Secure Access · Passwordless

SMS and voice MFA retire on February 1, 2027.

Anyone whose only method is a phone will be blocked at sign-in, with no fallback. Our experts find who is affected in your tenant, move every user to phishing-resistant methods and prove that it worked.

SMS and voice MFA retirement
–days
–hours
–minutes
–seconds
February 1, 2027
What changes and when

Two dates, one deadline

Knowing the dates is easy. Knowing who is affected in your own tenant is not.

01

Passkey by default

September 1, 2026 · already in effect

Users enabled for SMS or voice are enabled for passkeys as the rollout reaches the tenant, and are prompted to register one at their next MFA. Sign-in is not blocked.

02

Enforcement

February 1, 2027

SMS and voice are retired. Registration becomes mandatory for every user in scope, and users without a compliant method cannot sign in.

03

The new default

After enforcement

New users register a phishing-resistant method at onboarding, with no fallback to SMS or call-back at any point.

The passkey prompt is a registration campaign: your tenant can enable, scope or disable it at any time before enforcement, starting with a pilot group.

Today vs. after enforcement

What is accepted, what is at risk

Change management, user enrollment and configuration are the work between today and the new default.

Accepted today

Every method still works

  • Phishing-resistant: passkeys, FIDO2, Windows Hello, Authenticator
  • Phishable: SMS, voice call, email one-time code, password only
At risk

SMS and voice call

  • Business impact: users whose only method is a phone are locked out
  • No fallback: no help desk workaround once enforcement starts
From Feb 2027

What remains

  • Phishing-resistant: passkeys, FIDO2 keys, Windows Hello for Business
  • Authenticator: push with number matching and passwordless sign-in
Protection by method

Not every MFA resists phishing

SMS one-time codeRetires Feb 1, 2027Low
Voice callRetires Feb 1, 2027Low
Authenticator OTP codeLow
OATH hardware tokensLow
Authenticator push (approval only)Medium
Authenticator number matchingRecommended for transitionHigh
Certificate-based authenticationRecommendedVery high
Windows Hello for BusinessPreferredVery high
Passkeys (software / platform)PreferredVery high
FIDO2 security keys (hardware)PreferredMaximum

The weakest method sets the real security level of the account, and attackers always pick it. Temporary Access Pass is a bootstrap method for onboarding and recovery.

Passwordless E-xperiences

Four packages, one clear path

Start with a free review of your tenant and scale to a full rollout. Every package runs in your production tenant and maps to our E-xperiences journey.

FREE

Readiness Free

Establish the baseline at no cost

Read-only review
  • Microsoft Entra configuration discovery and review
  • Authentication methods best practices
  • Passwordless Readiness Report
  • Findings and recommendations session (up to 2 hours)
Up to 2 working sessions · no commercial commitment
E-VALUATION

Readiness Essentials

Remediate the critical gaps and start enrollment

Production evaluation · baseline scope
  • Configuration review and knowledge transfer for IT teams
  • Passwordless Readiness Agent deployment
  • Phishing-resistant registration for SMS and voice users
  • Cleanup of weak methods, Conditional Access and Identity Protection policies
Up to 6 working sessions · 2 weeks
E-VALUATION PLUS

Readiness Standard

Scale passwordless across the organization

Production evaluation · extended scope
  • Everything in Essentials
  • Onboarding waves, troubleshooting, recovery and reporting
  • Re-registration for incomplete profiles
  • Micro-Visor Passwordless for end-user adoption
Up to 12 working sessions · 3 weeks
E-VALUATION PLUS

Readiness Advanced

Complete the rollout with knowledge transfer

Production evaluation · maximum scope
  • Everything in Standard
  • Adoption agent and campaigns for every employee
  • Windows Hello, passkeys, Temporary Access Pass and FIDO2 keys
  • 6–8 hours of knowledge transfer, end-user and admin guides
Up to 16 working sessions · 4 weeks
Technology that accelerates adoption

Faster enrollment, fewer tickets

Our own E-Suite technology does the heavy lifting, so the change reaches every user at a lower cost.

Readiness Report

Analytics

A read-only view of your current state: users at risk, real SMS and voice usage and Conditional Access gaps, in HTML and PDF.

Score and roadmap

From insight to a funded plan

One readiness score and a sequenced roadmap of waves, with a business case that quantifies help desk and licensing savings.

Readiness and Adoption agents

Admin and end user

An admin agent that answers who loses access and what changed, and an agent in Teams that guides every employee until they finish.

Micro-Visor Passwordless

Adoption in the flow of work

In-Teams guidance and self-service management of authentication methods, with targeted campaigns for the users who still need to act.

Configured does not mean adopted. Adoption is a user behavior, and only reporting proves it.

FAQ

Frequently asked questions

We already have MFA. Is that not enough?

MFA proves a second factor, but it does not prove the site is real: push and code prompts can be relayed in real time. Phishing-resistant methods such as passkeys are bound to the domain and the device, so there is no secret left to steal or replay.

What if a user loses their phone?

Every user registers at least two methods, so a lost phone is a re-registration and not a lockout. A Temporary Access Pass restores access in minutes, time-limited and fully audited.

Can we control the passkey prompts users are already seeing?

Yes. The prompt is a registration campaign that your tenant can enable, scope to a pilot group or disable at any time before enforcement, so you can prepare communications and support first.

What about frontline or phone-less users?

FIDO2 security keys, Windows Hello for Business and certificates cover shared, frontline and phone-less users without depending on personal phones.

Why act now?

Weak methods are being retired on a published timeline, so the change happens with or without a plan. Most capabilities are already licensed; the value comes from activating and governing them before the deadline.

Talk to our experts

Get ready before Feb 1, 2027

Start with a free readiness review. A Synergy Advisors identity expert will confirm the scope with you.

01

Share your contextUsers, authentication methods, licensing and timeline.

02

Get a recommendationThe package or maturity step that fits, with scope and next steps.

03

Move before the deadlineIn English or Spanish, in person or remote.

We could not process your request. Please try again or write to us.
Thank you. A Synergy Advisors secure access expert will contact you shortly.

By submitting this form you agree that Synergy Advisors may contact you about your request. We use Brevo as our marketing platform; your data is processed in line with our Privacy Policy and Brevo's Privacy Policy.

Scroll to Top