Microsoft is making passkeys the default sign-in method across Microsoft Entra, and is retiring Microsoft-provided SMS and voice-call verification. Passkeys become the default on September 1, 2026. Microsoft-provided SMS and voice are fully retired on February 1, 2027.
This is a platform change from Microsoft that applies to every Microsoft 365 tenant — it is not specific to your organization, and it is not something Fuse elected to do. What Fuse controls is the pace.
Fuse has applied Microsoft's temporary opt-out to the environments we manage. Your users will not be swept into the automatic September 1 change or start seeing unexpected passkey prompts that week. Instead, Fuse begins a coordinated rollout for your organization on Thursday, October 1, 2026 — announced, supported, and sequenced by department rather than sprung on your team mid-morning.
This article explains what is changing, what your users will see and when, how to register a passkey, and the one budget decision this creates.

Two related changes are on the way, on two different dates:
Between those two dates the change is gentle by design. Existing sign-in methods keep working, and a user who is not ready can dismiss the prompt. That grace period ends on February 1.
Microsoft provides a documented, temporary opt-out from the September 1 automatic enablement, intended for organizations that want to complete their transition on a controlled schedule. Fuse has applied it to the environments we manage.
The practical effect: your users are not auto-enrolled on September 1 and will not receive unscheduled prompts. Fuse turns passkeys on for your organization from October 1, with your team told in advance what to expect. The opt-out is temporary and expires on February 1, 2027 — Microsoft has been explicit that the February enforcement applies to every tenant regardless of this setting. It buys a controlled rollout, not an exemption.
The February 1 prompt is blocking, and there is no opt-out
After February 1, 2027, a user whose only remaining method is SMS or voice must register a passkey during sign-in before they can continue into their account. Microsoft has stated this is enforced for all tenants with no opt-out. A user who has registered a passkey in advance never sees it.
A passkey is a phishing-resistant credential that lives on the device and unlocks with a fingerprint, face, or PIN. There is no one-time code to steal, forward, or phish, and the credential never leaves the device. Microsoft has pointed to the sharp rise in AI-assisted phishing as the reason for the shift.
A code delivered by text message or voice call travels across the public telephone network, which was never designed as a security channel. SIM swapping, number porting, and message interception all capture those codes without ever touching the account itself.
This is the part worth reading twice, because most teams already use the Microsoft Authenticator app and reasonably assume they are already covered. Approving a push notification is genuine multi-factor authentication, but it is not the same protection as a passkey.

| Authenticator push prompt (today) | Passkey (the new default) |
|---|---|
| Microsoft sends a prompt to your phone and you tap Approve, sometimes after matching a number. | You approve with your fingerprint, face, or device PIN. There is no code and no prompt to relay. |
| It confirms it is probably you — but not which site is asking. | It is tied cryptographically to the real Microsoft sign-in page and checks the site's identity before responding. |
| An attacker running a look-alike login page can relay the prompt to your phone, and a moment of inattention approves their sign-in. | A passkey physically cannot be used on a fake or look-alike site. |
In short: a push prompt confirms it is probably you; a passkey confirms you are on the real Microsoft site and that it is you. That is what phishing-resistant means in practice.
For most people the passkey lives inside the Microsoft Authenticator app that is already installed — there is no new app to download. Registration takes about five minutes.

You can also register ahead of any prompt at aka.ms/mysecurityinfo by signing in with the work account and choosing Add sign-in method.
Passkeys are also supported on Windows Hello for Business and on FIDO2 hardware security keys, for roles that prefer those over a phone. If your role requires a specific type, Fuse will tell you as part of the rollout.
Today Microsoft absorbs the cost of delivering SMS and voice codes. After February 1, 2027, an organization that still needs phone-based codes has to bring its own telecom provider through the Microsoft Security Store — turning a previously included feature into a metered, per-message charge.
Passkeys carry no such fee. They are included in every Microsoft Entra plan at no additional cost. Moving to passkeys ahead of the retirement date is both the more secure option and the one that keeps a new line item off your bill.
If you have a genuine need to keep SMS, plan it now
Some regulated scenarios genuinely require an out-of-band text message. Microsoft opens telecom provider details on September 18, 2026, and configuration from October 30, 2026. If that applies to you, tell us which regulation or scenario drives it and we will scope the provider decision with you well before February.
| Date | Milestone |
|---|---|
| September 1, 2026 | Microsoft's automatic enablement begins tenant-wide. Fuse-managed environments are opted out, so your users see no change and no prompts. |
| October 1, 2026 | Fuse begins your managed rollout. Passkeys are enabled for your organization and enrollment starts, sequenced by department with Service Desk support. |
| October 30, 2026 | Telecom providers become selectable through the Microsoft Security Store, for the rare cases that genuinely require SMS. |
| February 1, 2027 | Microsoft-provided SMS and voice are fully retired and the opt-out expires. Users without a phishing-resistant method face a blocking registration prompt. |
| Question | Answer |
|---|---|
| Do we have to do anything on September 1? | No, and your users will not see anything either. Fuse has opted your environment out of the automatic September 1 enablement. Your rollout begins October 1 on a schedule we set together. |
| Why not just let the September 1 change happen? | Because it arrives unannounced, mid-workday, with no support scheduled around it. A controlled October start lets us brief your team first and sequence enrollment by department. |
| Will anyone be locked out of their account? | No one loses their account. After February 1, a user whose only method is SMS or voice must register a passkey before continuing into a sign-in. Registering in advance avoids it entirely. |
| Is the Authenticator app still needed? | Yes. For most users the passkey lives inside the Authenticator app they already have. It is the method that changes, not the app. |
| What if a user gets a new phone? | Contact the Fuse Service Desk. We verify identity and reset the registration so the user can set up a passkey on the new device. |
| What about users with no suitable phone? | A FIDO2 hardware security key or Windows Hello for Business on a managed workstation covers them. Tell us who they are and we will plan for it. |
| Does this cost anything? | Passkeys are included in every Entra plan at no additional cost, and enrollment support is part of your Fuse Advantage coverage. Only keeping SMS after February 1 introduces a new cost. |
Partner with Fuse Networks and we will handle the passkey rollout, the user communication, and enrollment for your team, so this transition stays calm and predictable. If you would like the list of your users still on SMS or voice, contact us and we will pull it.
Fuse Networks Service Desk
| (888) 676-3873 | (855) GET-FUSE
Source: Microsoft 365 Message Center reference MC1426371, and Microsoft Entra documentation, Passkeys by default and retirement of Microsoft-provided SMS and voice authentication. Search MC1426371 in your Microsoft 365 admin center for the complete official guidance.
Fuse Networks is a Tukwila-based managed services provider and a CRN MSP 500 company. Focus on your Business, not your Technology.
Small businesses miss out on lucrative enterprise contracts every day for reasons unrelated to their core services. The deal usually stalls when the big prospect hands over a vendor security questionnaire, and the SMB blinks.
Let’s talk about how we can better prepare you to close these deals, and make you less likely to choke.
Small business leadership teams frequently address digital threats by purchasing separate software applications over time to defend different office terminals. This piecemeal strategy generates a fragmented environment where the antivirus app, mail filter, and network barrier do not share event data.
Cybercriminals deliberately exploit these disconnected zones, launching quiet intrusions that easily slide past individual security tools undetected.
When you examine modern corporate data breaches, the entry point is rarely a complex system hack. Most attacks succeed because they target busy schedules rather than a lack of intelligence.
Business owners know how to manage operations, but cybercriminals look for moments when your attention is stretched thin. Modern phishing schemes do not rely on complex software alone. They focus on taking advantage of your daily cognitive workload.
Summer vacations are essential for employee well-being, but they also introduce a critical operational risk: when leaders, executives, and internal IT personnel take time off, your standard business defenses naturally soften.
Cybercriminals do not take summer vacations. In fact, the threat actor's strategy is built entirely around exploiting these seasonal staffing gaps. Hackers know that standard verification processes break down when an office is operating with a skeleton crew. When the usual decision-makers are offline, employees left behind are more likely to make quick, unverified choices under pressure.
Phishing remains the most common method cybercriminals use to infiltrate small and medium-sized business networks. These attacks involve fraudulent emails manipulated to look like legitimate messages from banks, vendors, or even your own managers. If an employee falls for the trick, they may inadvertently hand over corporate passwords or download dangerous malware.
Protecting your company requires teaching your team how to recognize the signs of a fraudulent message before clicking any links.
One of the most challenging parts of implementing multi-factor authentication is getting your staff on board without having to twist their arms too much. The pushback is real, and it’s largely because employees see MFA as an inconvenience rather than a mechanism for security. You can change the culture around cybersecurity at your business and get your staff on board with MFA—and it’s easier than you might think.
There is a quiet tug-of-war happening in almost every small business right now, and it usually centers around the smartphone sitting on your employee's desk. On the one hand, business owners are quietly terrified of data security. They know that company emails, client databases, and internal chats are floating around on devices they don't own.
On the other hand, many employees are deeply uncomfortable with the idea of installing work apps if it means their boss can peek into their personal lives. They worry that an IT administrator will be able to read their private text messages, track their location over the weekend, or accidentally wipe their family vacation photos.
Honestly? I side with the employees on this one.
Every technology provider has a list of core values plastered on their website. They love using words like efficiency, innovation, and speed. While we use these outcomes as much as anyone, I want to be completely candid about the real boundary line in modern IT. Right now, there is a constant conflict happening between security and convenience.
Convenience demands fewer clicks, shorter passwords, bypassed logins, and instant access to everything from any device. Security requires verification, data encryption, strict access parameters, and deliberate authentication checks. When these two forces collide, our engineering team operates under a strict rule: security wins over convenience every single time. This core mindset guides every decision we make when we work with our clients.
When a growing company hires its first internal IT Director, it marks a significant organizational milestone. The business finally reaches a size where it requires dedicated technology leadership rather than relying on a tech-savvy office manager to reboot the network router. However, a single technology leader quickly faces a severe operational bottleneck.
A typical day often gets consumed by manually troubleshooting tasks like configuring legacy shipping printers, resetting user passwords, and setting up dual-monitor workstations. While these immediate tasks are necessary to keep employees working, they prevent the IT Director from addressing critical backend infrastructure needs. When an internal manager is occupied with daily hardware adjustments, nobody is reviewing firewall logs, running phishing simulations to train staff, or auditing the company compliance posture.
Buying new smartphones and tablets for an entire team represents a significant upfront expense. To reduce these equipment costs, many small business owners choose a simpler path. They implement a Bring Your Own Device policy that allows employees to check company emails, access client records, and use the corporate chat tool directly from their personal mobile phones.
This setup is highly convenient, but it introduces major data liabilities to your organization.
The average small business now relies on dozens of different software-as-a-service web platforms to handle daily operations, including billing, customer tracking, and team communication. For your staff, this digital growth has created severe password fatigue. Employees are forced to remember dozens of complex logins, which leads to a constant loop of locked accounts, broken workflows, and lost productivity that stalls your business day.
Small businesses invest thousands of dollars into sophisticated firewalls, email filters, and software protection to keep hackers out of their networks. However, many of those same organizations leave their physical server closets completely unlocked, or they locate their main network hardware in shared spaces like copy rooms.
Chances are you’ve seen the update window out of the corner of your eye while you’re going about your day-to-day tasks. For most employees, the choice is easy. They can click “Remind me later” to make today’s problem tomorrow’s. This creates a patch gap, which inadvertently becomes a major security hole for your small business.
Many technology policies are outdated documents filled with legal prohibitions. Employees often sign these forms during their first day of work and never look at them again. This approach is ineffective because overly restrictive rules lead staff to use unapproved software just to complete their tasks. This behavior creates security risks that are difficult to monitor or manage.
Cybersecurity has gotten more complex than ever, with many of the old standbys being rendered obsolete in comparison to the threats they are meant to prevent. Pairing that with the fact that many attacks are waged against small and medium-sized businesses, which often lack proper protections, makes the risk clear.
That said, you don’t have to accept these risks. Instead, you can implement tools like endpoint detection and response.