Published:

Every owner-managed business in Sussex or Kent with 10–25 staff that uses Microsoft 365 is facing a quiet change to how your team signs in. If anyone on your team still verifies their identity by text message or phone call, something is about to shift without warning.
Microsoft is making passkeys/default sign-in the norm — the Microsoft 365 passkey migration is real, and it applies to you whether you've noticed or not. There is no opt-out. No extension window exists beyond the deadlines Microsoft has published. This is what changes, when it changes, and what you need to resolve with your IT provider before September 2026.
What's Happening and Why It Matters
The two dates you need to track:
1 September 2026 — Microsoft begins automatic activation of passkeys by default for users still on SMS or voice identity verification. Staff receive prompts to set up a passkey but may experience confusion or brief access gaps during registration.
1 February 2027 — full retirement of Microsoft-provided SMS and voice sign-in MFA methods. After this date, users whose only identity method is text message or phone call will face blocked sign-in attempts with no workaround available.
A passkey is a modern sign-in method that uses your phone or computer instead of a text message — the same technology behind Apple Face ID or Windows Hello, built directly into Microsoft 365 at no extra cost. If your organisation already relies on passkeys, this change does not affect you.
If SMS MFA has been enabled as a catch-all solution across your Microsoft 365 tenant in recent years, understanding the passkey adoption timeline becomes essential to avoid disruption.
The Governance Rationale Behind This Push
SMS and voice MFA are among the weakest identity verification methods still in common use within the UK tech landscape. Someone can trick a mobile provider into redirecting your phone number to a device they control through SIM-swapping attacks. Users also routinely paste one-time codes directly into fake login pages without question.
Passkeys address these gaps through asymmetric cryptography tied to the user's own device. The attack vectors that make SMS MFA weak become essentially irrelevant when authentication is cryptographically bound to hardware. Microsoft frames this as part of a broader security posture update — identity verification methods need to evolve alongside how attackers operate.
This is not a product update or a feature request. It is policy enforcement applied globally across every Entra ID tenant worldwide. For SMEs who have invested in Microsoft 365 passkey adoption or explored SMS MFA retirement planning, this means the timeline is no longer optional — it is fixed.
What This Means for Your Business Operations
There are two angles worth keeping separate: compliance posture, and whether your team will actually be able to log in when they need to.
Compliance and Cyber Essentials Readiness
SMS-based MFA does not meet the requirements expected under Cyber Essentials Plus alignment in the most defensible interpretations used by auditors. Passkeys represent a significantly stronger identity control aligned with defensible security standards for SMEs — directly supporting CE/CE+ readiness without requiring additional purchased tools or services.
Insurance providers and business suppliers are increasingly demanding documented, phishing-resistant identity governance as a baseline condition. Positioning your organisation for these expectations regardless of when the next audit lands is what forward-looking MSP support delivers.
Day-to-Day Staff Impact
When the transition happens, anyone without a passkey set up may be locked out without warning or opt-out permission. Blocked sign-ins mean missed deadlines, confused clients, and work that simply does not get done because someone cannot reach their inbox.
Staff already using modern phones or computers with biometric authentication (Face ID, Touch ID, Windows Hello) may actually find their sign-in experience improves. No more waiting for text messages to arrive or calling in codes from memory.
What Remains Available
Customer-managed telecom providers configured through the Microsoft Security Store remain an option from October 2026 for specific regulatory scenarios. It is a narrow path that most SMEs will not need, but it exists for organisations bound by legacy telephony compliance requirements.
Questions You Should Answer Before September 2026
There are two decisions every SME owner needs clarity on before the auto-activation window closes:
How many of your users are currently on SMS or voice MFA? This is a tenant-level policy view in Entra ID settings. Most organisations have more affected users than they realise because SMS was enabled years ago as a fallback option for accounts unable to use authenticator apps — and never reviewed. The number might be one person. It might be half the company. You would not know without looking at your tenant configuration directly.
Do you have a migration plan covering every user, every device, and every signing scenario before September 2026? Acting before Microsoft decides your timeline removes the possibility of unplanned business disruption from identity verification changes. The difference between proactive planning and reactive intervention is the gap that good managed IT support fills.
How This Fits into a Broader Security Baseline
Passkey migration addresses one security control. Identity alone does not create a defensible setup across your entire environment — but it is often the first control that gets noticed during audits and compliance reviews.
The same approach that gets passkeys deployed cleanly extends across every core security control in your Microsoft 365 tenant: a clear baseline understanding of every security setting currently configured, standardised policies applied consistently at scale rather than managed by whoever remembers how to open the admin portal, and verified compliance woven into routine operations instead of requiring last-minute preparation before an audit.
For owner-managed SMEs, what matters about this is predictability. Security controls deployed, maintained, and reviewed without per-ticket billing or scope ambiguity. Every control gets consistent attention so nothing falls between the gaps while you focus on running your business.
What to Do Next
If you do not know whether passkey migration affects your organisation right now, start with that question. It is a quick, zero-commitment review — and one that positions you ahead of the timeline most businesses are currently missing.
Book a Security Triage Call. If you are an owner-managed SME in Sussex, Kent, or East Sussex and want to understand whether the Microsoft 365 passkey changes affect your tenant — and what this means for your broader IT security baseline — we will review your current Entra ID configuration, identify exactly how many users are on SMS MFA today, and confirm what needs action before deadlines arrive.
Or review our IT Security Baseline Checklist. See how every core security control fits together into one defensible starting point for your organisation.

Cyber Security
Passkeys Are Becoming Default for Microsoft 365 — Here Is What SME Owners Need to Know

Managed IT Services
Make IT boring (in the best way): 9 standards that stop the same issues coming back

Managed IT Services
Maintained or muddling through? 12 checks your SME IT should pass every month

Managed IT Services
Ownership. Scope. Evidence: A practical way to review your current IT arrangement

Managed IT Services