Passkey and Voice / SMS retirement.

passione 120 Reputation points
2026-09-08T16:00:52.3233333+00:00

Hello Microsoft Community,

I am looking for guidance on configuring Microsoft Authenticator deployment and preparing for the upcoming Microsoft Entra ID native SMS/Voice retirement.

Microsoft Authenticator: Passkey vs. Push/OTP

  • Is there a way for an admin to determine or enforce whether Microsoft Authenticator registers as a FIDO2 passkey versus a traditional push/OTP method, when deployed via Intune to managed mobile devices?

Are there known OS-version, MDM-enrollment, or app-store distribution requirements that affect whether Authenticator can register in passkey mode on a mobile device?

Users Without Smartphones or Company Devices

  • For users who have neither a company-managed laptop nor a smartphone capable of running an authenticator app, what authentication methods will remain supported by Microsoft Entra ID after the native SMS/Voice retirement?
  • What are the eligibility criteria and configuration requirements for the customer-managed telecom provider option that becomes available after Microsoft's native SMS/Voice MFA retirement?

Thank you for your insights.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-09-08T16:01:16.35+00:00

    For Microsoft Authenticator on mobile devices, the context supports these distinctions:

    • Microsoft Authenticator phone sign-in is a push-based method with number matching and is not phishing-resistant.
    • Microsoft Authenticator can also store device-bound passkeys on iOS 17+ and Android 14+, and those passkeys are phishing-resistant.
    • On mobile platforms, passkey behavior depends on device state and app broker behavior.
    • For Microsoft app support with an authentication broker, the supported brokers are:
      • iOS: Microsoft Authenticator
      • Android: Authenticator, Company Portal, or Link to Windows app
    • Intune’s role is to deploy and manage the mobile app and device prerequisites, and to support the brokered sign-in experience across Microsoft apps.

    The context does not provide a supported admin control to force Microsoft Authenticator to register specifically as a passkey instead of push/OTP, and it does not provide a complete matrix of MDM-enrollment or app-store distribution requirements beyond the platform and broker prerequisites above.

    For users without smartphones or company devices, the supported direction after Microsoft-provided SMS/voice retirement is:

    • Microsoft recommends moving users to passkeys as the primary path.
    • Users can also continue using other phishing-resistant methods already in use, such as Windows Hello for Business or FIDO2.
    • If an organization has a valid business, regulatory, or operational need to keep using SMS or voice, it can use a customer-managed telecom provider through the Microsoft Security Store.

    Retirement timeline and impact:

    1. September 1, 2026
      • Users enabled for SMS or voice are auto-enabled for passkeys in Authentication Methods Policy.
      • Registration Campaign settings are set to Microsoft Managed targeting passkeys for in-scope users.
      • When those users next sign in and complete MFA, they are nudged to register a passkey.
    2. February 1, 2027
      • Microsoft-provided SMS and voice delivery is retired in Microsoft Entra ID.
      • If users still rely on SMS or voice and no customer-managed telecom provider is configured, they can no longer use Microsoft-provided SMS/voice to complete MFA.
      • Users whose only available MFA method is SMS or voice receive a blocking prompt to register a passkey during sign-in and must complete passkey registration before continuing.
      • There is no opt out from this behavior.

    For the customer-managed telecom provider option, the supported criteria and requirements in the context are:

    • It is intended for user segments with a genuine regulatory or operational need for a telecom channel.
    • Examples include:
      • specific compliance regimes requiring out-of-band SMS
      • scenarios where no other method is workable
    • Recommended preparation steps:
      1. Identify the user segments that truly require telecom-based authentication.
      2. Document the requirement and the applicable regulation or scenario.
      3. Beginning September 18, 2026, review telecom providers and related information in the Microsoft Security Store.
      4. Beginning October 30, 2026, select and configure a telecom provider from the Microsoft Security Store.
      5. Stand up the carrier contract through the marketplace flow and test with a pilot group before broad rollout.
      6. Default all other users to passkeys.

    A practical planning approach for the affected population is:

    1. Identify all users currently enabled for SMS or voice by using the published PowerShell script. This requires one of these roles: Global Reader, Authentication Policy Administrator, or Security Reader.
    2. Separate users into:
      • users who can move to passkeys
      • users who can use Windows Hello for Business or FIDO2
      • users with a documented regulatory or operational need for telecom-based MFA
    3. Enable and plan passkey rollout for the first group.
    4. For the last group, evaluate and configure a customer-managed telecom provider before February 1, 2027.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.