Skip to content
EJK Consultancy

Microsoft 365 Passkeys: What UK SMEs Should Do Before SMS MFA Retires

Microsoft retires SMS and voice MFA codes for Microsoft 365 on 1 February 2027. A practical passkey rollout plan for UK SMEs and IT managers.

9 min read
Microsoft 365SecurityIdentityMFA

Microsoft has started switching Entra ID to a passkey-first sign-in, and the method most UK small businesses still rely on is being retired. Microsoft-provided SMS and voice codes stop working as a second factor for standard users on 1 February 2027. Anyone whose only method is a text message will meet a blocking prompt at sign-in.

Entra ID sits behind every Microsoft 365 sign-in, so this is not an Azure-only change. It lands on business email, Teams, SharePoint and every app you have connected through single sign-on. Microsoft began the rollout on 1 September 2026, and it reaches tenants gradually rather than all at once.

We audit Business Premium tenants and the authentication methods report almost always tells the same story. SMS is the primary factor for most users because it was the easiest method to register on day one, and nobody has revisited it since.

The dates to put in your diary

Four dates shape the work. Three of them belong to Microsoft, and one is the deadline you should set for yourself.

DateWhat changesWho is affected
1 September 2026Passkeys become the default authentication experience and users enabled for SMS or voice are prompted to register oneEvery Entra ID tenant, rolled out gradually
30 October 2026Third-party telecom providers can be selected through the Microsoft Security StoreOnly relevant if a genuine reason exists to keep SMS or voice
1 February 2027Microsoft-provided SMS and voice delivery retiresStandard users, including internal guests
1 July 2027Microsoft-provided SMS and voice delivery retiresGlobal administrators and external users

Two entries in that table catch people out. Global administrators get an extra five months, which reads as generous until you remember that the emergency access account is the one an attacker wants most. Internal guest users get no extension at all, so contractors, agency staff and anyone from a sister company signing in with a guest account belongs in the February wave.

After the relevant date, a user with no other method meets a blocking passkey registration prompt at sign-in. There is no administrative opt-out for users in scope.

Why Microsoft is switching off text codes

Text codes were a reasonable compromise fifteen years ago. Two attacks have made them weak. Real-time phishing puts a proxy between the user and the genuine sign-in page, relays the password and the one-time code, then steals the session cookie in the same browser session. Number ownership is the second problem, because mobile numbers are recycled by operators and the person who ends up with a former employee's number can receive that person's codes. Microsoft sets out the reasoning in its retirement guidance and in the Entra ID security update.

Our position is blunt. If a business still relies on SMS as the main factor for people who approve payments, handle client data or administer systems, Microsoft has just handed it a deadline to clear a security debt it should have cleared already.

What your users will actually see

This is a registration campaign rather than a hard cutover. An administrator enables Passkey (FIDO2) in the authentication methods policy, points a registration campaign at the users to be reached, and those users are prompted to create a passkey the next time they complete MFA. Users enabled for SMS or voice join the Microsoft-managed campaign automatically, and the prompt can be snoozed at that stage.

Early steps matter more than perfect ones. Turning the campaign on tells you within days which users can register a passkey and which ones cannot, and that list decides what you have to buy.

Which passkey suits which person

Four options cover almost every UK SME. The choice is about the device each person carries and the risk attached to the account they hold. Match the method to the person, not the other way round.

MethodGood forWatch out for
Synced passkey in a phone or password managerOffice staff who already carry a modern smartphoneTenant policy can require device-bound passkeys instead, so settle that question before publishing guidance
Microsoft Authenticator passkeyStaff who already use Authenticator for approvalsIt is device-bound, so a lost or replaced phone needs a clear re-registration route
Windows Hello for BusinessDesk-based and site-based users on Windows devicesNeeds a supported Windows edition and suitable hardware so the credential is backed by the device
FIDO2 security keyWarehouse, field and shared-device users without a suitable phoneOne-off hardware cost per user, plus a process for lost keys

Give administrators and anyone with elevated access a security key or Windows Hello. A credential that syncs to a personal account is convenient, and that convenience works for the attacker as soon as the personal account is compromised.

The licence question, answered plainly

Registering and using a passkey does not require an extra Microsoft 365 licence. Passkeys work across Entra ID editions, including the free tier that comes with every tenant, and Microsoft confirms that position in its passkey FAQ.

Who needs which entitlement

Enforcement is where cost appears. Conditional Access and authentication strengths both need Entra ID P1, which Microsoft lists at around £5.40 per user per month ex VAT on an annual commitment. Treat that as an approximate list price, because it excludes VAT and it moves with Microsoft's UK pricing, so check your own quote.

Plenty of UK SMEs already own the entitlement. Microsoft 365 Business Premium includes Entra ID P1, so a tenant on that plan can enforce phishing-resistant methods without buying anything new. Teams on Business Standard or Basic face a real decision: add P1 for administrative and finance users, or accept that enforcement stays manual and rely on people following written guidance.

A migration sequence that fits around other work

The sequence below takes a 25 to 50 person business roughly three weeks of part-time effort. The order matters more than the pace.

  1. Run the authentication methods report in the Entra admin centre and export every user whose only method is SMS or voice.
  2. Choose the target method for each group, including the people who have no suitable phone.
  3. Enable Passkey (FIDO2) and any other method you are standardising on, then test with a small group that includes at least one administrator.
  4. Turn on the registration campaign for the rest of the business and give it a two-week completion window.
  5. Remove SMS and voice from the method policy once registration is done, then confirm every user still has a working fallback.

Keeping SMS alive by buying a third-party telecom provider is a waste of money for almost every SME we speak to. You would be paying a provider to keep the weakest available factor running for a handful of edge cases. Buy a few security keys instead.

Where rollouts go wrong

The technical change is small. The support load is where projects like this derail, and it lands in three predictable places.

Frontline and shared devices come first. A shop-floor PC or warehouse terminal that signs into one account is not a normal passkey candidate, and the answer is usually a shared-device mode or a managed security key, chosen before the campaign starts. Staff without smartphones come second, and that group is always bigger than the IT team expects, so each of them needs hardware. The emergency access account comes third. Exclude it from enforcement in a documented way, keep that exclusion under review, and remember that a break-glass account locked behind a lost device becomes an outage.

Recycled phone numbers deserve their own mention. We have cleared landline numbers off department accounts after an office move, and by then the number had already been reassigned. Numbers attached to former employees sit in the tenant the same way, and the new owner of that number can receive codes meant for the old account.

What it costs a typical 25-person business

Costs split into one-off hardware, a possible licence upgrade and internal time. Nothing on the list is a surprise once it is written down.

ItemTypical costNotes
Passkeys on phones staff already ownNothingNeeds a device with a screen lock and a reasonably current operating system
FIDO2 security keys for staff without a suitable phoneRoughly £50 to £80 each, one-offUK retail pricing including VAT varies by model and connector, so buy a spare per key user
Entra ID P1 for policy enforcementAround £5.40 per user per month ex VATAlready included with Microsoft 365 Business Premium, and list prices change, so check your own quote
Internal time to plan and support the rolloutTwo to three days of IT effortMost of it sits in user support during the first week of the campaign

The Cyber Essentials angle

Cyber Essentials v3.3 tightened the rules in April 2026. MFA is now expected on every cloud service that supports it, for every user who authenticates to that service, including ordinary staff. That leaves no room for a tenant where a third of the business signs in with a password and a text code. The official requirements are published by the NCSC, and passkeys make the evidence simpler to produce, because the authentication methods report shows who has registered a phishing-resistant method rather than who merely has MFA switched on.

Start with the report, not with a licence

The whole exercise starts with one export. The authentication methods report in the Entra admin centre takes ten minutes to pull and turns a vague worry about February 2027 into a list of names. That list then tells you whether the answer is hardware, a licence upgrade or nothing at all.

We would rather have this conversation in September 2026 than in the last week of January 2027, when the same problem turns up as a queue at the helpdesk. If your tenant is on Business Premium and the report shows SMS as the main factor, a short Microsoft 365 review will size the work properly.

Get your passkey rollout planned before February 2027

We audit your Entra ID authentication methods, identify every user who still relies on SMS or voice, and put together a method-by-method rollout your helpdesk can actually support.

Book a Microsoft 365 assessment
Dan Kennedy

Written by Dan Kennedy

Managing Consultant at EJK Consultancy

Dan is a Microsoft Certified consultant with over 25 years of hands-on IT experience, specialising in Microsoft 365 migrations, SharePoint architecture, Power Automate automation and Microsoft Copilot readiness. He works directly with UK businesses to solve real workplace technology problems.