Why Microsoft 365 keeps asking your staff to set up a passkey

You may have noticed a new prompt when signing in to Microsoft 365 lately, asking you to set up a passkey. It is not random, and it is not optional for much longer.

What a passkey actually is

If passkeys are new to you: a passkey is a sign-in credential that lives on something you already have - your phone, your work laptop, or a security key on a keyring - and is unlocked with your fingerprint, your face, or a PIN. There is no code arriving by text and nothing to copy across from one place to another. Where you do enter a PIN, it unlocks the device in your hand and goes no further - the website never sees it. Most people have used a passkey already without hearing it called that, because it is the same technology behind the fingerprint prompt on a banking app.

Why that is safer than a text message, rather than just more convenient, is worth its own post. The short version is that nothing you type travels anywhere, so there is nothing for anyone to intercept, talk you into reading out, or capture on a convincing copy of a login page.

What is changing, and when

Since 1 September, Microsoft has been nudging anyone who signs in with a text message towards registering a passkey. The nudge is skippable for now, but from 1 February 2027 it becomes mandatory.

From that date, Microsoft will retire its own SMS and voice authentication. Anyone who currently signs in by typing a code sent to their phone, and has nothing else set up, will be blocked at the sign-in screen until they register a passkey. Microsoft's own documentation is blunt: there is no opt-out for enforcement.

If you already use the Microsoft Authenticator app

A word on the authenticator app. If your staff approve a prompt in Microsoft Authenticator, or read a six-digit code out of it, they will not be locked out in February - this change is only about codes sent by text or read out over a phone call. But the app is not the same thing as a passkey either. A code can still be read out to someone who rings up claiming to be from IT, and an approval can still be tapped by someone who assumes the request is genuine. The National Cyber Security Centre ranks both below passkeys for exactly those reasons. The useful part is that the same app can hold a passkey, so for most businesses this is a setting to change rather than something new to buy.

If you want to read Microsoft's announcement yourself, it is in your Microsoft 365 admin centre under Health > Message centre, reference MC1426371 - or ask whoever looks after your IT to forward it to you.

Four things that are easily missed

  • Text messages are not actually banned - you can keep them by contracting a telephony provider through the Microsoft Security Store, which opens for configuration on 30 October. What changes is that you will no longer be able to use SMS or phone call verification without a paid-for 3rd-party provider.

  • Password resets are also affected. If your staff reset their own forgotten passwords by receiving a text, that route closes on the same date.

  • Order matters more than the date. Take the old method away before the new one is set up, and the account is left with no second step at all, which is worse than where it started. Passkeys on first, phone numbers off second.

  • The administrators get longer, which is not the good news it sounds like. Accounts with full administrative rights have until 1 July 2027 - five months more than everyone else. It means the person who would have to fix a lockout is the last one to be locked out. Do those accounts first regardless, and give each of them two ways in rather than one.

What to actually do

None of this is difficult. It is a sequence, and the sequence matters more than the deadline does.

  1. Count two numbers. How many people can only sign in with a code sent to a phone - those are the ones locked out in February. And how many have a phone number as a sign-in option at all, even alongside something stronger - they will not be locked out, but an account is only as safe as the easiest way into it. The first number is the deadline. The second is the real problem, and it is usually the bigger one.

  2. Start with the administrators. These are the few accounts that can change settings for everyone - normally you, whoever looks after your IT, or both. Ignore their later date. They are the people who would have to fix a lockout, and they are the ones Microsoft locks out last.

  3. Give everyone two ways in, not one. A passkey on the phone and Windows Hello on the work laptop, or a security key kept as a spare. One method means one lost phone is a member of staff who cannot work.

  4. Set up the new before removing the old. Get passkeys registered, confirm people can actually sign in with them, and only then take the phone numbers out of the settings. Not the other way round.

  5. Check what else sends a code to a phone. Password resets are the obvious one. Anything else in the business that texts a code is better found now than discovered in February.

  6. Decide whether you need to pay for text messages at all. Most businesses will not. If you have people who genuinely cannot use a passkey, the Microsoft Security Store route opens on 30 October - but it is a contract and a cost, so it deserves a decision rather than drifting into it.

For whoever does the checking: both numbers in step 1 come from the Authentication methods activity report in Microsoft Entra, not from the phone numbers held on staff profiles. Those are address book entries, and most of them are not sign-in methods at all.

If the prompts are already confusing your staff: they can be paused until 1 February 2027, which buys time to plan rather than react. It does not move the deadline.

If you hold Cyber Essentials, there is a second reason the order matters. The scheme requires multi-factor authentication on cloud services, so a window in which accounts have no second step at all is a problem for the certificate as well as for the account. Worth adding that a text message still satisfies the scheme - passkeys are preferred rather than mandated - so this is about not leaving a gap rather than about the method itself.

The work itself is not hard. It is that it has to happen to everyone, and the people who will find it hardest are the ones who tell you last.

Next
Next

What Are Passkeys, and Should Your Business Use Them?