The Deadline Nobody Asked For
Starting 1 September 2026, Microsoft Entra ID will make PasskeyA WebAuthn credential — a public/private key pair generated and stored on a user's device, used to sign in without ever transmitting a shared secret a phishing site could steal.s the default authentication experience for users currently enabled for SMS or voice — automatically enabling them for passkey registration and prompting them during sign-in, not forcing an instant switch. Microsoft says more information on customer-managed telecom providers will be available for review from 18 September, and beginning 30 October, organizations that genuinely need to keep SMS or voice will be able to select and configure one of those providers through Microsoft's Security Store. Then, on 1 February 2027, Microsoft's own SMS and voice authentication stops working entirely. There is no opt-out from that February enforcement itself — anyone still relying on it alone gets a blocking prompt demanding a passkey before they can sign in again.
Why a Text Message Was Never That Safe
None of this is really about text messages suddenly becoming dangerous — they always were. SIM swapping lets an attacker convince a carrier to move a victim's number onto a new SIM, silently rerouting every code meant for them. The SS7 protocol that routes phone traffic globally has known interception weaknesses that don't require touching the victim's phone at all. And plenty of "MFAMulti-Factor Authentication — requiring proof from more than one category of factor (something you know, have, or are) before granting access.-protected" accounts have fallen to nothing more sophisticated than a fake login page that asks for the code the moment the real one arrives, then relays it before it expires. None of this needed artificial intelligence. It just needed patience, and there was always someone willing to supply it.
What Actually Changed Is the Economics
Passwords and SMS codes aren't disappearing because they're outdated — they're disappearing because humans have always been the weak point, and attackers finally have the tooling to exploit that at scale. AI has made voice phishing more convincing, more scalable, and cheaper to operate — cloning a voice now takes a few seconds of public audio, enough to hold a real-time conversation convincing enough to talk someone through reading out a code they were never supposed to share. Session-hijacking phishing kits do the same thing to login pages: sit invisibly between a victim and the real site, forward the traffic in both directions, and simply wait for a human to finish authenticating on the attacker's behalf. Microsoft's own justification for retiring SMS and voice is unusually blunt about this — it isn't that these methods are old, it's that they can't stop an attacker who's automated the one job a human used to be needed for: getting fooled.
What a Passkey Actually Changes
A passkey replaces "a secret you type" with a cryptographic key pair your device generates and never lets leave it. Signing in means your device proves it holds the private half of that pair — it never transmits anything a phishing site could steal or a human could be tricked into reading aloud. The part that actually matters here is narrower and more mechanical than most explanations make it sound: a passkey is bound to the exact origin it was created for, and the browser enforces that binding, not the user. A cloned voice can talk someone into reading out a code. It cannot talk a browser into handing a credential to a domain that doesn't match. That's not a bigger password — it's a different category of thing to attack.
The Catch Nobody's Advertising
Here's what gets left out of most of the celebration: passwords had an ugly but real safety net — forget one, and a reset link fixes it. Lose every device holding your passkeys, and there's no equivalent. A passkey's private key genuinely never leaves the hardware it was generated on, which is exactly what makes it unphishable and exactly what makes losing that hardware a real problem. The practical fix — Apple's iCloud Keychain, Google's Password Manager, Microsoft's own sync — backs passkeys up to the cloud so a lost phone doesn't mean a lost identity. But that fix works by making your access to everything depend on staying logged into one company's account. A suspended Google account, an Apple ID under review, a Microsoft account flagged by an automated system — any of those stops being an inconvenience and starts being the single point of failure for every account tied to it. Critics have been blunt about what this actually is: not just a security upgrade, but a deeper coupling of your digital identity to whichever platform you happened to pick.
So Is This Actually Progress?
Genuinely, yes — and the numbers back it up better than the marketing does. The FIDO Alliance puts active passkeys at roughly five billion worldwide in 2026, with three in four consumers having enabled one somewhere and nearly half using them regularly. Closer to home, Visa launched its Payment Passkey in India in July 2026 with IDFC FIRST Bank as its first issuing partner — built on the same FIDO standards, and aligned with the RBI's own September 2025 framework pushing Indian digital payments past OTPs entirely. This isn't a vendor experiment being forced on a reluctant public; it's a shift that was already happening, and Microsoft's deadline mostly just formalizes where the puck already went.
The Part Worth Remembering Before You Migrate
"Passwordless" was never the same promise as "risk-free," and it's worth being honest about which risk actually got traded for which. The old failure mode was a memory an attacker could extract from a person. The new one is a device — and the account that resurrects it when the device is gone — that now has to be protected instead. That's a smaller, better-shaped problem than the one it replaces. It just isn't a solved one, and anyone migrating this year deserves to hear that part too, not just the deadline.
Sources
The factual claims and data points in this article are traceable to the sources below. They are linked here rather than woven inline, so the argument reads clean and the underlying information stays checkable.
- Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID — Microsoft Security Blog, 13 July 2026
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication — Microsoft Learn, official rollout timeline
- Microsoft admits SMS and voice MFA can't stop AI attacks, mandates passkeys in Entra by February 2027 — Windows Latest, 22 July 2026
- What is SIM Swapping? How to Prevent It — Trend Micro
- How attackers are bypassing MFA using AI in 2026 — WorkOS
- State of Passkeys 2026 — FIDO Alliance, based on a Sapio Research study of 11,000 consumers and 1,400 enterprise decision-makers
- Visa Launches Payment Passkey in India, Reducing Friction in Digital Payments — Visa India newsroom, July 2026
- Visa passkeys go live in India as IDFC First Bank becomes first issuer — Business Standard, 3 July 2026
