IronSights
All insights

microsoft 365

Microsoft is asking your staff to register a passkey. What to tell them.

From 1 September, staff still on SMS codes get a passkey prompt at sign-in. It can be snoozed, which is exactly why most people will. What to say, and what to check first.

Ryan BallootBy Ryan Balloot, Managing Director24 August 20265 min read
ByRyan Balloot24 August 20265 min read

On 1 September, staff who still receive their verification code by text message start seeing something new at sign-in. Microsoft asks them to set up a . Most of them will not know what that word means, and the ones who do will wonder whether they are allowed to say no.

They are, for now. That is the part worth understanding before your help desk hears about it second-hand.

What the prompt actually is

From 1 September every user still enabled for SMS or voice in Entra is switched on for automatically, and the registration campaign becomes Microsoft-managed. The next time one of them completes , they are asked to register a passkey rather than being waved straight through.

Nobody is locked out by this. The prompt can be snoozed, and by default there is no limit on how many times. A staff member can decline it every morning between September and February and nothing happens to them.

That is the whole problem with it. A prompt that can always be postponed generally is. The nudge does not fix your exposure, it makes it visible, and the date it stops being optional is 1 February 2027. The two dates and what sits behind them are worth reading once if you have not already.

What to tell your staff

Send something before the prompts start rather than after. Four points cover it.

First, the prompt is genuine. Staff have been trained for years to distrust anything that appears at sign-in asking them to set up a new security thing, which is the right instinct and, this once, the wrong conclusion. Tell them it is coming, from you, before Microsoft tells them.

Second, a passkey is not a new app or another password. On a company phone it lives in the Microsoft Authenticator app they already have. On a laptop it can be the fingerprint or face unlock they already use. There is nothing to buy and nothing to memorise.

Third, doing it now takes about two minutes, and doing it in February will take longer because everyone else will be doing it at the same time. That is a scheduling argument rather than a security one, and it is the one that actually moves people.

Fourth, tell them who to ask. A rollout with no named person to call produces a queue at the busiest desk in the building.

Microsoft publishes end-user communication templates at aka.ms/mfatemplates. They are a reasonable starting point if you would rather edit than write.

Find out who is actually affected

The list is usually shorter than people fear. Most organisations moved the bulk of their staff to the Authenticator app years ago. The ones still on text messages tend to be a specific group: long-serving staff, people who joined before the app was standard, and, more often than is comfortable, executives who asked to be left alone.

There are two ways to get the list. The authentication methods report in Entra shows what every user has registered, and the sign-in logs show what they actually use, which is not always the same thing. Microsoft has also published a PowerShell analyser, entra-sms-voice-usage-analyzer, that reports SMS and voice usage across the tenant and needs only a read-only role to run.

Check one more thing while you are in there: who has SMS as their only registered method. Those are the people who meet a wall in February, and they are what the plan is actually about.

Can you defer it?

Yes, and only until February. An administrator can opt the tenant out of the September migration through the authentication methods policy, which hands the registration campaign back to you. That defers the nudge. It does not defer the retirement.

Microsoft has been unusually direct about the February behaviour: it is enforced for all tenants and there is no opt-out. Deferring the September prompt is sensible if you already have a rollout scheduled and do not want two sets of instructions in flight at once. It is not sensible if the plan is to think about it later.

The case for enforcing it yourself

There is a version of the next five months where nothing much happens, the snooze button does its work, and a queue forms on the first Monday of February. There is another version where you pick the date.

Enforcing it yourself means a Conditional Access policy requiring -resistant authentication, applied first to the accounts that matter. Administrators, finance, anyone who can move money or approve access. The rest of the business follows on a schedule that avoids your month end and your busy season.

It also means every person registers a second method at enrolment. That is the step most rollouts skip, and every account recovery conversation afterwards depends on it.

Can staff just ignore the prompt?

Until 1 February 2027, yes. The snooze is unlimited by default, so a user can decline it indefinitely without losing access. From 1 February the same prompt becomes blocking for anyone whose only registered method is SMS or voice, and there is no opt-out from that one.

Is Microsoft Authenticator affected?

No. Push notifications, app codes and passkeys in the app all continue as they are. The retirement covers codes delivered over the phone network only, so a tenant where everyone already uses the app has nothing to fix.

Do we have to buy hardware keys?

Not for most people. A passkey in Microsoft Authenticator meets the new default and costs nothing. Hardware keys earn their place on privileged accounts, and for staff who cannot reasonably be asked to use a personal phone, such as shared-device and frontline workers.

Does this affect password resets too?

Yes. Self-service password reset by SMS or voice call retires on the same February date, so anyone relying on a text to get back into their account needs another way in before then.

Where to from here

If you would rather the exposure list, the cohort design and the policy were handled than added to someone's Friday, that is work we do. Either way, the useful thing to do this week is find out who is still on a text message. Everything else is a decision you can only make once you have that list.

Keep reading

More from the IronSights team.