Post-SMS Retirement Enforcement Scope

Alena Halenwood 5 Reputation points
2026-08-17T19:58:27.8766667+00:00

Post-Feb-1, for a user whose only method is SMS/voice (or who has zero methods), who signs in to a resource where no CA policy demands MFA — does the blocking passkey-registration requirement fire on that non-MFA sign-in, or only when an MFA demand is present?

The wording "Tenants with users enabled for SMS or voice, those users are auto-enabled and nudged for Passkey registration upon MFA sign-in." clearly explains it is for an MFA sign-in but the later wording could be interpreted as at any sign in: "Users whose only available MFA method is SMS or voice will be required to register a passkey during sign-in to continue accessing their account. This prompt will be blocking. Users must register a passkey before they can continue to sign in to their account.

There is no opt out from this February 1 behavior. It will be enforced for all tenants."

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-08-17T19:58:41.7+00:00

    The supported scope is this:

    • September 1, 2026 behavior is explicitly tied to MFA sign-in. Users enabled for SMS or voice are auto-enabled for passkeys and nudged to register upon MFA sign-in.
    • After February 1, 2027, the documented enforcement says users whose only available MFA method is SMS or voice are required to register a passkey during sign-in before they can continue accessing the account, and that the prompt is blocking with no opt out.
    • The same retirement guidance also states that if those users have not been moved to another phishing-resistant method and no customer-managed telecom provider is configured, they can no longer use SMS or voice to satisfy MFA requirements and continue signing in.

    The documentation in scope does not explicitly state whether the February 1, 2027 blocking passkey-registration prompt is triggered on every sign-in, including a sign-in where no MFA challenge is required, or only when an MFA-related sign-in event occurs.

    What is explicitly supported is:

    1. The pre-February nudge is tied to MFA sign-in.
    2. The post-February experience is a blocking sign-in-time registration requirement for users whose only MFA method is SMS or voice.
    3. There is no opt out of that February 1, 2027 enforcement.

    The context does not provide a definitive statement for the exact edge case of a non-MFA sign-in with no CA MFA requirement.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.