A cloud-based identity and access management service for securing user authentication and resource access
For Microsoft Authenticator on mobile devices, the context supports these distinctions:
- Microsoft Authenticator phone sign-in is a push-based method with number matching and is not phishing-resistant.
- Microsoft Authenticator can also store device-bound passkeys on iOS 17+ and Android 14+, and those passkeys are phishing-resistant.
- On mobile platforms, passkey behavior depends on device state and app broker behavior.
- For Microsoft app support with an authentication broker, the supported brokers are:
- iOS: Microsoft Authenticator
- Android: Authenticator, Company Portal, or Link to Windows app
- Intune’s role is to deploy and manage the mobile app and device prerequisites, and to support the brokered sign-in experience across Microsoft apps.
The context does not provide a supported admin control to force Microsoft Authenticator to register specifically as a passkey instead of push/OTP, and it does not provide a complete matrix of MDM-enrollment or app-store distribution requirements beyond the platform and broker prerequisites above.
For users without smartphones or company devices, the supported direction after Microsoft-provided SMS/voice retirement is:
- Microsoft recommends moving users to passkeys as the primary path.
- Users can also continue using other phishing-resistant methods already in use, such as Windows Hello for Business or FIDO2.
- If an organization has a valid business, regulatory, or operational need to keep using SMS or voice, it can use a customer-managed telecom provider through the Microsoft Security Store.
Retirement timeline and impact:
- September 1, 2026
- Users enabled for SMS or voice are auto-enabled for passkeys in Authentication Methods Policy.
- Registration Campaign settings are set to Microsoft Managed targeting passkeys for in-scope users.
- When those users next sign in and complete MFA, they are nudged to register a passkey.
- February 1, 2027
- Microsoft-provided SMS and voice delivery is retired in Microsoft Entra ID.
- If users still rely on SMS or voice and no customer-managed telecom provider is configured, they can no longer use Microsoft-provided SMS/voice to complete MFA.
- Users whose only available MFA method is SMS or voice receive a blocking prompt to register a passkey during sign-in and must complete passkey registration before continuing.
- There is no opt out from this behavior.
For the customer-managed telecom provider option, the supported criteria and requirements in the context are:
- It is intended for user segments with a genuine regulatory or operational need for a telecom channel.
- Examples include:
- specific compliance regimes requiring out-of-band SMS
- scenarios where no other method is workable
- Recommended preparation steps:
- Identify the user segments that truly require telecom-based authentication.
- Document the requirement and the applicable regulation or scenario.
- Beginning September 18, 2026, review telecom providers and related information in the Microsoft Security Store.
- Beginning October 30, 2026, select and configure a telecom provider from the Microsoft Security Store.
- Stand up the carrier contract through the marketplace flow and test with a pilot group before broad rollout.
- Default all other users to passkeys.
A practical planning approach for the affected population is:
- Identify all users currently enabled for SMS or voice by using the published PowerShell script. This requires one of these roles: Global Reader, Authentication Policy Administrator, or Security Reader.
- Separate users into:
- users who can move to passkeys
- users who can use Windows Hello for Business or FIDO2
- users with a documented regulatory or operational need for telecom-based MFA
- Enable and plan passkey rollout for the first group.
- For the last group, evaluate and configure a customer-managed telecom provider before February 1, 2027.
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Frequently asked questions about SMS and voice retirement
- Passkey (FIDO2) authentication matrix with Microsoft Entra ID
- Passwordless authentication with Microsoft Intune