Skip to main content
Skip to main content

This is an announcement bar or top menu bar. Additional content can go here.

More Microsoft 365 users are beginning to see prompts encouraging them to set up a passkey for faster, more secure sign-in.

Some click through. Many dismiss it. And many users do not fully understand what the prompt means.

That is becoming increasingly important.

Microsoft is actively moving organizations toward phishing-resistant authentication, and businesses that still rely on SMS or voice for multi-factor authentication now have a timeline to work against.

Why Businesses Need to Pay Attention Now

Starting September 1, 2026, Microsoft says users who are enabled for SMS or voice authentication in Microsoft Entra ID will also be automatically enabled for passkeys and brought into Microsoft’s passkey registration campaign.

When those users sign in and complete MFA, Microsoft may prompt them to register a passkey.

Then, beginning February 1, 2027, Microsoft-provided SMS and voice authentication delivery will be retired in Microsoft Entra ID.

Organizations that still have a legitimate business, regulatory or technical need for SMS or voice will be able to use a customer-managed telecom provider. Otherwise, users whose only available MFA method is SMS or voice will be required to register a passkey before they can continue signing in.

That means this is no longer just about whether passkeys are more convenient.

Businesses using Microsoft 365 should be reviewing their authentication environment now, identifying who still depends on SMS or voice, and planning a move toward phishing-resistant authentication before the retirement takes effect.

Passkeys are one of the primary methods Microsoft is encouraging organizations to adopt.

Here is what they are, how they work, and what your organization needs to think through before rolling them out.

What Are Passkeys?

A passkey lets you sign in without entering a password. Your device verifies you using a fingerprint, facial recognition, device PIN, or physical security key. Your password is not entered or transmitted as part of the authentication process.

Registering a passkey does not automatically delete your existing password. Many accounts continue to support passwords and other authentication methods during the transition to passwordless sign-in.

The underlying technology is based on the FIDO2, or Fast Identity Online, authentication standards.

When you create a passkey, two cryptographic keys are involved:

  • A private key used by your device or passkey provider
  • A public key registered with Microsoft

When you sign in, Microsoft sends a challenge that can only be answered using the corresponding private key. Microsoft verifies the response using the public key associated with your account.

The private key is never sent to Microsoft during authentication.

How Is a Passkey Different from a Password?

With a device-bound passkey, the private key remains on the device where it was created. With a synced passkey, an encrypted version of the private key can be securely stored by an approved passkey provider, allowing it to be used across the user’s authorized devices.

This is the key difference from a password.

A password is a shared secret that you submit to a service. Secure systems should store a cryptographic representation of the password rather than the password itself, but passwords can still be phished or exposed through a breach.

A passkey does not transmit a reusable secret that can be captured through a fraudulent sign-in page.

Your fingerprint or facial scan is only used to unlock the passkey locally. Microsoft does not receive or store your biometric data. It only receives confirmation that the local verification was completed successfully.

Based on Microsoft’s experience with consumer accounts, synced passkey sign-ins can be approximately 14 times faster than signing in with a password and traditional MFA, taking about three seconds instead of 69 seconds.

Microsoft’s 2024 Digital Defense Report also found that more than 99% of the identity attacks observed at the time were password-based.

Passkeys vs. Passwords vs. MFA: What Is Actually Different?

These methods are not always separate layers. A passkey can itself satisfy multifactor authentication requirements because it combines possession of the passkey with a local biometric or PIN verification.

The important difference is whether the authentication method is vulnerable to phishing.

Method What It Helps Stop What It Can Still Miss
Password only Basic unauthorized access when the password remains secret Phishing, credential stuffing, password spraying, password reuse and stolen credentials
Password plus traditional MFA Many password-only attacks and unauthorized sign-ins Real-time phishing against phishable MFA methods, stolen verification codes, push-notification fatigue, and SIM swapping when SMS is used
Passkey Phishing, credential stuffing, password replay and intercepted verification codes Compromised or unlocked devices, insecure fallback methods and weaknesses in account-recovery processes

Passkeys are considered phishing-resistant because they are tied to the legitimate website or application. A passkey created for Microsoft cannot be used to authenticate a fraudulent website pretending to be Microsoft.

That does not make passkeys invulnerable. Attackers can still target devices, active sessions, recovery processes and weaker authentication methods that remain available on the account.

How Do You Set Up a Microsoft Passkey?

The setup process depends on whether you are using a personal Microsoft account or an account managed by your organization.

For a Personal Microsoft Account

  1. Sign in to your Microsoft account.
  2. Go to Security.
  3. Open Advanced Security Options.
  4. Select Add a new way to sign in or verify.
  5. Choose the passkey option.
  6. Follow the prompts to save the passkey to your device, security key or supported passkey provider.

For a Microsoft 365 Work or School Account

  1. Sign in to your work or school account’s Security Info page.
  2. Select Add sign-in method.
  3. Choose the available passkey option.
  4. Follow the prompts to register the passkey using your device, Microsoft Authenticator, security key or another passkey provider approved by your organization.

The options users see depend on how their Microsoft Entra ID administrator has configured passkey authentication.

An organization may support synced passkeys, device-bound Microsoft Authenticator passkeys, Windows-based passkeys, physical FIDO2 security keys or a combination of these methods.

What Should Businesses Plan for Before Rolling Out Passkeys?

This is where many organizations underestimate the work involved.

Passkeys are genuinely stronger authentication, but enabling them without preparation can create confusion, inconsistent access and unnecessary helpdesk calls.

And with Microsoft’s September 2026 passkey changes approaching, businesses that still use SMS or voice authentication should be doing this work before users begin encountering new registration prompts.

Identify Who Still Uses SMS or Voice

This should now be one of the first steps.

Determine which users are still enabled for or actively relying on SMS or voice authentication.

Those are the users most directly affected by Microsoft’s upcoming changes and should be prioritized in your migration plan.

The goal should be to move users toward phishing-resistant authentication before Microsoft-provided SMS and voice authentication retires, rather than waiting for a blocking registration prompt to force the change.

Decide Which Type of Passkey You Will Support

Not all passkeys work in exactly the same way.

Synced passkeys can be stored by providers such as Apple iCloud Keychain, Google Password Manager and supported third-party credential managers. They are generally convenient for employees because they can be available across multiple authorized devices.

Device-bound passkeys remain tied to a particular device. These include passkeys stored in Microsoft Authenticator and physical FIDO2 security keys.

Windows-based passkey options are also evolving as Microsoft expands passkey support across Windows and Microsoft Entra ID.

Microsoft recommends considering synced passkeys for many general users while using device-bound passkeys for administrators, regulated workers and people accessing highly sensitive resources.

Check Device Compatibility First

Most current Windows, iOS and Android devices support some form of passkey authentication, but compatibility depends on the type of passkey being used.

Operating-system versions, browsers, hardware security features, mobile-device policies and credential providers can all affect the user experience.

Microsoft Authenticator passkeys require Android 14 or later, and device compatibility may vary based on the available security hardware and platform configuration.

Test the actual device types used by your employees before expanding the rollout across the organization.

Audit Your Applications

Passkeys work through modern Microsoft Entra authentication.

Older applications and protocols that depend directly on usernames and passwords may not support a complete passwordless experience. These applications may need to be upgraded, reconfigured or replaced before passwords can be meaningfully removed from everyday use.

Identify legacy authentication activity and business-critical applications before changing sign-in requirements.

Review Conditional Access Policies

If your organization uses Microsoft Entra Conditional Access, those policies need to be reviewed before deployment.

Conditional Access authentication strengths can be used to require passwordless or phishing-resistant authentication for selected users, applications or resources.

Incorrectly configured policies can block passkey registration, create sign-in loops or allow users to fall back to weaker authentication methods when that was not the intention.

Set Up Recovery Before It Becomes an Emergency

Recovery depends on the type of passkey.

Synced passkeys may remain available through the user’s approved passkey provider after a device is replaced.

Microsoft Authenticator passkeys are device-bound and do not transfer as usable passkeys to a replacement phone. After moving to a new device, the user must register a new passkey.

Microsoft Authenticator can transfer or restore certain account information to a new phone, but work or school accounts still require additional setup, and the passkey itself must be registered for the replacement device.

If necessary, Microsoft Entra administrators can issue a Temporary Access Pass that allows the user to regain access and register a new passkey. The old passkey should then be removed once the replacement authentication method is working.

Your IT team should define this process before the first lost-device call comes in.

“We see businesses becoming much more interested in passkeys as Microsoft moves toward phishing-resistant authentication. The technology is strong, but organizations still need to review Conditional Access, application compatibility and recovery before rolling it out,” says Andriy Marchyshyn at Sirkit.

“Passkeys are a meaningful security upgrade. Deployment needs a real plan.”

Microsoft Passkey Deployment Checklist

Before enabling passkeys across your organization:

  • Identify users who still depend on SMS or voice authentication.
  • Plan to move those users to phishing-resistant authentication before February 1, 2027.
  • Decide whether users need synced passkeys, device-bound passkeys or both.
  • Consider device-bound passkeys for administrators and other higher-risk accounts.
  • Confirm operating-system, browser, hardware and credential-provider compatibility.
  • Enable passkeys for a small pilot group before expanding the rollout.
  • Review Microsoft Entra Conditional Access and authentication-strength policies.
  • Identify legacy applications and sign-ins that still depend on passwords.
  • Configure Temporary Access Pass and account-recovery procedures.
  • Ensure users have an approved backup authentication or recovery method.
  • Define a helpdesk process for lost, stolen or replaced devices.
  • Communicate the upcoming Microsoft changes before users are prompted to register.
  • Review sign-in logs and helpdesk feedback during the rollout.

Common Questions About Microsoft Passkeys

Why Is Microsoft Moving Away from SMS and Voice Authentication?

The primary reason is security.

SMS and voice authentication are more vulnerable to phishing and account compromise than phishing-resistant methods such as passkeys and FIDO2 security keys.

Microsoft is therefore changing the default authentication experience in Microsoft Entra ID.

Beginning September 1, 2026, users enabled for SMS or voice will also be enabled for passkeys and may be prompted to register one.

Beginning February 1, 2027, Microsoft-provided SMS and voice authentication delivery will retire. Organizations that still require these methods will need to configure a supported customer-managed telecom provider.

Do Passkeys Replace Passwords Entirely?

Not automatically.

Registering a passkey does not usually delete the password already associated with the account. Passwords and other authentication methods may continue to exist during the transition.

Organizations can use Microsoft Entra authentication policies and Conditional Access authentication strengths to require passkeys or other phishing-resistant methods when accessing selected resources.

That reduces reliance on passwords, but it does not necessarily remove the underlying password from every user account.

What Happens if I Lose My Device?

Your account is not necessarily lost with it, but the recovery process depends on where the passkey is stored.

A synced passkey may be available on another authorized device connected to the same passkey provider.

Microsoft Authenticator passkeys are device-bound. When moving to a replacement phone, some Authenticator account information can be transferred or restored, but the passkey itself must be registered again on the new device.

The user can regain access using another approved authentication method or a Temporary Access Pass issued by IT.

This recovery path works, but it needs to be planned and documented before the device is lost.

Can Passkeys Be Phished?

Passkeys are designed to be phishing-resistant.

The private key is not shared with the website, and authentication is tied to the legitimate website or application. A fraudulent login page cannot capture a reusable password, MFA code or private key through the normal authentication flow.

Passkeys do not eliminate every identity risk. Attackers may still target compromised devices, active browser sessions, weaker fallback authentication methods or poorly controlled account-recovery processes.

This is why organizations should treat passkeys as part of a broader identity-security strategy rather than a single setting that solves every access risk.

Are Passkeys Only for Personal Accounts?

No.

Microsoft supports passkeys for personal Microsoft accounts and enterprise environments managed through Microsoft Entra ID.

Business users can authenticate using synced passkeys, Microsoft Authenticator passkeys, Windows-based passkeys and supported FIDO2 security keys, depending on the policies configured by their organization.

Does Microsoft Store My Biometric Data?

No.

Your fingerprint or facial recognition data is processed by your device. It is used locally to verify that you are authorized to use the passkey.

Microsoft receives confirmation that the verification was successful, but your fingerprint, facial scan or biometric template does not leave the device.

What Should Your Business Do Next?

For organizations using Microsoft 365, the immediate question is no longer simply whether passkeys are worth adopting.

It is whether your organization is ready for Microsoft’s move away from Microsoft-provided SMS and voice authentication.

September 1, 2026: Users enabled for SMS or voice begin being automatically enabled for passkeys and brought into Microsoft’s registration campaign.

February 1, 2027: Microsoft-provided SMS and voice authentication delivery retires.

Businesses should use the time between those dates to identify affected users, review authentication methods, test passkeys, evaluate Conditional Access policies and establish recovery procedures.

Do not wait until users encounter a blocking registration prompt.

“The businesses that benefit most from passkeys are not the ones treating it as a nice-to-have. They are the ones that recognize credential-based attacks as a significant real-world exposure and approach passkeys as the architectural shift they actually are,” says Andriy.

If your organization is working through passkey deployment or preparing for Microsoft’s SMS and voice authentication changes, Sirkit’s team is glad to help review your Microsoft 365 and Entra ID configuration.

Reach out to start the conversation.

Tags: