Passkeys vs. Passwords: Why Microsoft Is Phasing Out SMS Codes in 2026
- Nico Dudli

- 2 hours ago
- 6 min read
For years, a password plus a text-message code was treated as a practical way to make account sign-ins safer. In 2026, Microsoft is accelerating the shift toward phishing-resistant authentication: Microsoft Entra ID will begin making passkeys the default authentication experience for users who still rely on SMS or voice, while personal Microsoft accounts are also gradually moving away from SMS for sign-in and account recovery.
The wider industry is moving in the same direction. In May 2026, the FIDO Alliance estimated that around five billion passkeys were already in use worldwide.
This guide explains why SMS authentication is being phased down, how passkeys work, what Microsoft's actual timeline says, and what users should do before the transition reaches their accounts.

Why SMS codes are losing their role in secure authentication
SMS codes are better than relying on a password alone, but they are not phishing-resistant.
An attacker can create a convincing fake login page and relay a one-time code to the real service while the victim enters it. SMS authentication also depends on control of a phone number, which creates additional risks such as SIM swapping and number reassignment.
NIST's current Digital Identity Guidelines classify authentication secrets delivered through the public telephone network, including SMS and voice, as a restricted authenticator. NIST also explicitly states that out-of-band authentication of this type is not phishing-resistant.
CISA similarly recommends moving toward phishing-resistant authentication based on FIDO/WebAuthn where possible. Its guidance still makes an important distinction: weaker MFA such as SMS is generally better than having no MFA at all, but organizations should move toward stronger methods when they are available.
That is the security context behind Microsoft's transition. The goal is not simply to replace one type of code with another, but to move authentication away from credentials that can be entered into a phishing page.
Microsoft's roadmap is the wake-up call for 2026
Microsoft is making the transition visible across both personal and business accounts.
For personal Microsoft accounts, Microsoft says it is gradually phasing out SMS as a method for authentication and account recovery. Users are being directed toward passkeys and verified email instead. Microsoft has not published the same fixed retirement timeline for personal accounts that it has for Microsoft Entra ID.
For Microsoft Entra ID, the enterprise timeline is much more specific:
September 1, 2026: Users who are still enabled for SMS or voice authentication will also be automatically enabled for passkeys. Microsoft's registration campaign will begin prompting eligible users to create one after an MFA sign-in. This does not mean a passkey is automatically created for the user, and the registration prompt can initially be snoozed indefinitely.
September 18, 2026: Microsoft plans to make information about customer-managed telecom providers available through the Microsoft Security Store for organizations that still have a legitimate operational or regulatory need for SMS or voice.
October 30, 2026: Organizations will be able to select and configure those telecom providers.
February 1, 2027: Microsoft-provided SMS and voice delivery is retired in Microsoft Entra ID.
After February 1, 2027, users whose only available MFA method is Microsoft-provided SMS or voice, and whose organization has not configured an alternative telecom provider, will need to register a passkey during sign-in before they can continue. Users already using another supported phishing-resistant method are not automatically blocked simply because they have not created a passkey.
What the numbers say
The FIDO Alliance published its State of Passkeys 2026 report on May 7, 2026. Its consumer research covered 11,000 adults across ten countries, while the workforce study surveyed 1,400 enterprise decision-makers.
FIDO reported:
Around 5 billion passkeys in use worldwide.
90% of consumers were familiar with passkeys.
75% had enabled a passkey on at least one account.
49% said they use passkeys regularly when they are available.
68% of surveyed organizations had deployed, were deploying, or were piloting passkeys for employee authentication.
Availability and regular use are therefore still different measures. Three quarters of respondents had enabled at least one passkey, while roughly half said they used passkeys regularly when available.
Passkey availability on major websites has also grown substantially. In separate research published by FIDO in 2025, passkey support had reached 48% of the world's top 100 websites, compared with 20% reported by FIDO in 2024.
How a passkey actually works
A passkey uses public-key cryptography instead of a shared password.
The service stores a public key, while the corresponding private credential remains under the user's control on a device, security key, or supported credential manager. When you sign in, the service sends a cryptographic challenge that can be answered only with the matching private key.
A fingerprint, face scan, or device PIN can be used locally to unlock that credential. The biometric itself is not sent to the website.
Most importantly, the authentication is bound to the legitimate website or application. A fake phishing site cannot simply ask you to type the passkey into a form the way it can capture a password or one-time SMS code. This is why FIDO/WebAuthn authentication is considered phishing-resistant.
How to get ready
Enable passkeys on important accounts when they are offered. Email, cloud storage, and your primary identity accounts are sensible places to start.
Check where your passkeys are stored. Depending on your setup, they may be tied to a device, synchronized through a platform credential manager, or stored in a compatible password manager.
Review your recovery options. Do not remove an existing recovery method until you know how you would regain access after losing a phone or computer.
If your workplace uses Microsoft Entra ID, follow your IT team's migration plan. Passkeys are Microsoft's preferred path, but Windows Hello for Business, FIDO2 security keys, and other supported phishing-resistant authentication methods may also be part of the transition.
If an organization genuinely needs SMS or voice, administrators should evaluate the customer-managed telecom options Microsoft is making available through the Microsoft Security Store rather than assuming native Microsoft SMS will continue after February 2027.
Where SMS still hangs on
SMS authentication won't vanish entirely in 2026. Organizations with a genuine regulatory or operational need can configure a customer-managed telecom provider through the Microsoft Security Store instead of Microsoft's free built-in SMS delivery. Outside the Microsoft ecosystem, plenty of smaller services, government portals, and apps without passkey support will keep SMS as their only available second factor for a while yet.
FAQ
What is a passkey?
A passkey is a phishing-resistant authentication credential based on public-key cryptography. It can replace a password and one-time code, while local device authentication such as a fingerprint, face scan, or PIN unlocks the credential.
Why is Microsoft moving away from SMS authentication?
Microsoft says SMS and voice provide substantially weaker protection against phishing and account compromise than phishing-resistant methods such as passkeys.
What happens on September 1, 2026 in Microsoft Entra ID?
Users who are enabled for SMS or voice will also be enabled for passkeys, and Microsoft's registration campaign will begin prompting eligible users to register one. A passkey is not automatically created for them.
When does Microsoft-provided SMS and voice authentication end in Entra ID?
Microsoft plans to retire its own SMS and voice delivery on February 1, 2027. Organizations with a legitimate need for these channels can instead configure a customer-managed telecom provider.
Will everyone without a passkey be blocked on February 1, 2027?
No. The blocking registration requirement applies to users whose only available MFA method is Microsoft-provided SMS or voice and who do not have an alternative configured. Other supported phishing-resistant authentication methods can continue to be used.
Are passkeys more resistant to phishing than SMS codes?
Yes. FIDO/WebAuthn authentication is designed so that credentials are bound to the legitimate service and cannot simply be entered into a fake phishing page like a password or one-time code.
Summary
Starting September 1, 2026, Microsoft Entra ID will automatically enable passkeys for users who are still enabled for SMS or voice and begin prompting eligible users to register them.
Microsoft-provided SMS and voice delivery in Entra ID is scheduled to end on February 1, 2027.
Personal Microsoft accounts are also gradually moving away from SMS authentication and recovery, but Microsoft has not published the same fixed retirement timeline for them.
The FIDO Alliance estimated around 5 billion passkeys were in use worldwide in May 2026; 90% of surveyed consumers knew about passkeys, 75% had enabled at least one, and 49% used them regularly when available.
NIST classifies SMS and voice authentication over the public telephone network as restricted and not phishing-resistant.
Passkeys use public-key cryptography and are designed to resist phishing because authentication is bound to the legitimate service.
Organizations that still require SMS or voice after Microsoft's Entra retirement can use customer-managed telecom providers through the Microsoft Security Store.
Users should adopt phishing-resistant authentication where available and make sure they have reliable account-recovery options before removing existing methods.
Sources (for fact-checking, not necessarily all linked in the article):
Microsoft Learn, "Passkeys by default and retirement of Microsoft-provided SMS and voice authentication" (primary source, updated Aug 3, 2026)
FIDO Alliance, "State of Passkeys 2026" (May 2026) and 2025 World Passkey Day report (48% top-100-website figure)
NIST SP 800-63B-4, Digital Identity Guidelines — Authenticators (restricted authenticator classification)


Comments