How to Migrate Users from SMS and Voice MFA to Passkeys in Microsoft Entra ID

Migrating users from SMS and voice MFA to passkeys in Microsoft Entra ID

Short answer: to move users from SMS and voice MFA to passkeys in Microsoft Entra ID, find everyone who still depends on SMS or voice, enable Passkey (FIDO2) with passkey profiles, get users registered with a registration campaign and Temporary Access Pass, close device gaps, communicate early and then require phishing-resistant MFA in waves with Conditional Access. Microsoft-provided SMS and voice are retired on February 1, 2027 for most users and on July 1, 2027 for Global Administrators and external users. After those dates, users whose only method is SMS or voice must register a passkey before they can continue signing in.

What is changing and when

Microsoft is retiring the SMS and voice authentication it delivers on behalf of Microsoft Entra ID tenants and is making passkeys the default sign-in method. The change applies across Microsoft Entra, including self-service password reset (SSPR). Only the Microsoft-provided channel goes away: organizations with a real regulatory or operational need can keep SMS or voice through a customer-managed telephony provider.

Timeline of the Microsoft Entra ID SMS and voice MFA retirement: September 1, 2026, October 30, 2026, February 1, 2027 and July 1, 2027
Key dates of the retirement. Feb 1, 2027 is the deadline for most users; Jul 1, 2027 applies to Global Administrators and external users.
WhoMicrosoft-provided SMS and voice endWhat happens after that date
Members and internal guest usersFebruary 1, 2027Users whose only MFA method is SMS or voice must register a passkey during sign-in. The prompt is blocking.
Global AdministratorsJuly 1, 2027Same blocking passkey registration if SMS or voice is their only method.
External users (B2B)July 1, 2027Same blocking behavior. Passkey support for B2B guests is planned by the end of 2026.
Users moved to a customer-managed telephony providerNot affected by the retirementThey keep SMS or voice through the provider, at the provider’s pricing.
Azure AD B2C tenantsOut of scopeNo change from this retirement.

No opt-out from enforcement. Between September 1, 2026 and February 1, 2027 you can delay the automatic passkey enablement through Microsoft Graph, but the retirement dates and the blocking prompt apply regardless.

What already changed on September 1, 2026

If your tenant had users enabled for SMS or voice, three things changed automatically on September 1, 2026:

  • Those users were enabled for passkeys in the Authentication methods policy, in a passkey profile that allows all passkey types.
  • The registration campaign moved to the Microsoft managed state, so users are nudged to register a passkey after their next MFA sign-in.
  • By default the nudge allows unlimited snoozes. Until February 1, 2027 users can postpone it; after that date the prompt can no longer be skipped for users who only have SMS or voice.

In other words, your users are already seeing passkey prompts. The question is whether you steer the migration or let the deadline do it.

A six-part migration plan

Six-part plan to migrate users from SMS and voice MFA to passkeys in Microsoft Entra ID
The plan moves from visibility to enforcement. Each part reduces risk before the next one starts.

1. Discover who still depends on SMS or voice

Start with data, not assumptions. Microsoft publishes a PowerShell script, the SMS and voice usage analyzer, that lists users enabled for SMS or voice and shows whether they actually use it. It runs with the Global Reader, Authentication Policy Administrator or Security Reader role. Any non-zero result means you are in scope.

Complement it with the Authentication methods activity report in the Microsoft Entra admin center (Entra ID > Authentication methods > Activity) or query registration details directly from Microsoft Graph:

GET https://graph.microsoft.com/v1.0/reports/authenticationMethods/userRegistrationDetails
    ?$select=userPrincipalName,methodsRegistered,isMfaCapable,isPasswordlessCapable

Split the result into three groups: users who only have SMS or voice (highest priority), users who have SMS plus another method, and users who are already passwordless capable.

2. Enable passkeys with the right profile for each group

Open Entra ID > Authentication methods > Policies > Passkey (FIDO2) with the Authentication Policy Administrator role. Passkey profiles let you apply different rules to different groups; up to three profiles are supported, including the default one. Each profile defines:

SettingWhat it controlsTypical choice
Passkey typesDevice-bound, synced or bothBoth for most employees; device-bound only for administrators
Enforce attestationAccept only authenticators that prove their make and modelYes for administrators; synced passkeys do not support attestation
Key restrictions (AAGUID)Allow or block specific authenticator modelsAllow-list Microsoft Authenticator and your approved security keys for privileged roles

Keep Allow self-service set up on, so users can register at Security info without opening a ticket. If you need the full comparison between the two passkey types, see Passkeys vs passwords and SMS codes.

3. Get every user registered

The registration campaign (Entra ID > Authentication methods > Registration campaign) is the main lever. You can leave it in Microsoft managed or switch it to Enabled to control it yourself: target Passkey (FIDO2), choose how many days a user can snooze (0 to 14) and limit snoozes to three, after which registration is required. Target the group of SMS and voice users first.

Users who have no other method, new hires and anyone who lost their phone need a secure way in. Issue a Temporary Access Pass (TAP): a time-limited passcode, configurable from 10 minutes to 30 days (default one hour), that can be one-time use. With a one-time TAP the user must complete the passkey registration within 10 minutes of signing in.

Passkeys cannot be registered from the Conditional Access registration interrupt. Users must register them beforehand through Security info, Microsoft Authenticator or the registration campaign. That is why registration has to come before enforcement.

4. Close device gaps before they become tickets

  • Phones: passkeys in Microsoft Authenticator require iOS 17 or later and Android 14 or later (Android 15 is recommended). For both synced and device-bound support, Authenticator 6.8.37 on iOS and 6.2507.4749 on Android or later.
  • Cross-device sign-in: registering or signing in from a computer with a phone needs internet and Bluetooth on both devices.
  • Network: allow, without TLS inspection, cable.ua5v.com for Android and cable.auth.com, app-site-association.cdn-apple.com and app-site-association.networking.apple for iOS.
  • Computers: Windows Hello for Business on managed Windows devices removes the phone from the daily sign-in altogether.
  • No phone: FIDO2 security keys for frontline staff, shared workstations and users who cannot or will not use a personal phone.

5. Communicate before you enforce

Most migration friction is a communication problem. Microsoft provides end-user templates for email, Teams and intranet posts at aka.ms/mfatemplates. A simple cadence works well: an announcement four weeks before enforcement, a reminder with a two-minute guide one week before, and a message on the day with the help desk path. Explain the why in one line: passkeys are faster than codes and they cannot be phished.

6. Enforce phishing-resistant MFA in waves

Once registration is high, require phishing-resistant MFA with a Conditional Access authentication strength. Run the policy in report-only mode, then turn it on for administrators, pilot groups and finally everyone. Exclude two emergency access accounts that use their own phishing-resistant method and alert on every use. The full policy design is in Conditional Access authentication strengths: how to require phishing-resistant MFA.

What about users who really need SMS or voice?

Some users have a legitimate need for an out-of-band telephone channel, for example because of regulation or because they work where no other method is viable. For them, Microsoft is opening customer-managed telephony providers in Microsoft Security Store, configurable from October 30, 2026. The first providers are Soprano and Telesign, and pricing varies by provider and region.

If you configure a provider and move those users before their retirement date, they will not receive the blocking passkey prompt. Keep this list short and reviewed: every user you leave on SMS is a user who can still be phished.

Common mistakes to avoid

  • Enforcing before registering. Users without a passkey are blocked by the policy and cannot register one from the interrupt.
  • Forgetting SSPR. The retirement also affects password reset by SMS or voice. Review your SSPR methods at the same time.
  • One profile for everyone. Administrators deserve device-bound passkeys with attestation; most employees are better served by synced passkeys.
  • Ignoring guests. External users follow July 1, 2027 and depend on your cross-tenant trust settings.
  • Leaving the help desk out. Recovery with Temporary Access Pass needs a documented identity-verification script before day one.

How Synergy Advisors helps

Our security experts run this migration end to end: we measure who depends on SMS and voice, design passkey profiles and Conditional Access, prepare communications and recovery, and enforce in waves without locking anyone out. Learn more about our Secure Access services and our Passwordless offering, or check your starting point with the passwordless readiness checklist.

Sources

Frequently asked questions

When do SMS and voice MFA stop working in Microsoft Entra ID?

Microsoft-provided SMS and voice are retired on February 1, 2027 for all users except Global Administrators and external users, who follow on July 1, 2027. Internal guest users follow the February date.

What happens to users who only have SMS or voice?

They are not locked out. After their retirement date they must register a passkey during sign-in before they can continue. The prompt is blocking and there is no opt-out from that enforcement.

Does the retirement affect self-service password reset?

Yes. The retirement of Microsoft-provided SMS and voice applies across Microsoft Entra, including SSPR, unless you use a customer-managed telephony provider.

Do passkeys cost extra?

No. Migrating users from Microsoft-provided SMS and voice to passkeys has no additional cost. Customer-managed telephony providers are paid services.

Can we keep SMS for some users?

Yes, through a customer-managed telephony provider in Microsoft Security Store, available from October 30, 2026. Move those users before their retirement date to avoid the blocking prompt.

Talk to our experts

Ready to take the next step?

A Synergy Advisors expert can help you assess where you are today and plan what comes next in your Microsoft security journey.

Scroll to Top