Phishing, recovery and stronger sign-in
Microsoft Entra Defaults to Passkeys on Sept 1, 2026
Starting September 1, 2026, Microsoft Entra turns on passkeys for SMS and voice MFA users and prompts them to register one. Here is what changes, what stays the same, and whether your email verification codes are affected.
If a work or school Microsoft sign-in has started nudging you to set up a passkey this month, that is a real, scheduled change, not a glitch or a phishing attempt. Starting September 1, 2026, Microsoft Entra ID automatically enables passkeys for anyone currently using SMS or voice for multifactor authentication, and prompts them to register one at their next sign-in — this applies to work and school (Entra ID) accounts specifically, and Microsoft's own documentation does not list email verification codes as affected.
This is an enterprise identity change, not a consumer Outlook.com change, and it is worth being precise about scope before reacting to a prompt you did not expect.
What changes on September 1, and what does not?
Work and school accounts that use SMS or voice MFA are enabled for passkeys and prompted to register one; SMS and voice keep working until February 1, 2027, and email codes from other services do not change.
| Item | Status after Sept 1, 2026 | Source |
|---|---|---|
| SMS-based MFA on a work/school (Entra ID) account | Passkeys enabled for the user; user is nudged to register one at next sign-in and can snooze the prompt | Microsoft Entra ID security blog |
| Voice-call-based MFA on a work/school account | Same as SMS: passkeys enabled and a registration nudge | Microsoft Entra ID security blog |
| Microsoft-provided SMS/voice delivery itself | Continues until February 1, 2027, then retires unless a tenant configures a third-party telecom provider | Microsoft Learn: SMS and voice retirement |
| Passkeys already in use, or Windows Hello / FIDO2 | No change; these methods continue working as before | Microsoft Learn: SMS and voice retirement |
| Email-delivered verification codes for other services | Not mentioned as affected by this change; this rollout is specific to Entra ID's own MFA methods | Microsoft Learn: SMS and voice retirement |
| Personal Outlook.com accounts | Not the subject of this announcement, which is scoped to Entra ID (organizational accounts) | Microsoft Entra ID security blog |
- I confirmed the prompt is on a work or school account, not a personal one.
- I understand this is a registration nudge, not an immediate lockout.
- I know SMS/voice still works until February 1, 2027, if I'm not ready to switch yet.
- I did not assume this changes how any other service emails me a verification code.
- If I manage a tenant, I know an admin-level, time-boxed opt-out exists via a Microsoft Graph policy setting.
Why is Microsoft making this change?
Microsoft's own Entra ID security blog post, published July 13, 2026, frames the change plainly: SMS and voice are no longer positioned as secure authentication methods, and Microsoft is making passkeys the default sign-in experience so organizations get phishing-resistant protection without having to opt in. Microsoft's Learn documentation adds the mechanical detail: users currently enabled for SMS or voice in a tenant's Authentication Methods Policy are auto-enabled for passkeys starting September 1, 2026, and the next time they complete multifactor authentication, a registration campaign nudges them to set one up. By default, that nudge can be snoozed indefinitely — it is not a hard block on that date.
What happens on February 1, 2027?
September 1, 2026 starts the nudging. The enforcement date is different: Microsoft's documentation states that from February 1, 2027, Microsoft-provided SMS and voice delivery is retired in Entra ID, and any user whose only remaining MFA method is SMS or voice will be required to register a passkey during sign-in to continue — a blocking prompt with, in Microsoft's own words, no opt-out. Organizations with a genuine regulatory or operational need for SMS can configure a customer-managed telecom provider through the Microsoft Security Store, with more provider detail due September 18, 2026, and configuration available from October 30, 2026, per Microsoft's published timeline.
Does this affect email verification codes?
This change is specific to Microsoft Entra ID's own multifactor authentication methods for organizational accounts. Microsoft's documentation does not describe any effect on email-delivered one-time codes that other services, including non-Microsoft ones, send you at login — those continue to work exactly as they did before. If your day-to-day frustration is with verification codes arriving late, getting filed as spam, or piling up across services, that is a separate, ongoing problem this passkey rollout does not solve or worsen. See OTP email not arriving: a checklist before you request another code or, if the account in question is a work email specifically, work email verification code not arriving: check aliases, filters, and admin rules.
Should you register the passkey when prompted?
For most people on an Entra ID (work/school) account, yes — passkeys are phishing-resistant in a way SMS and voice codes are not, which is the entire rationale Microsoft's blog post gives for the change. If you are not ready, Microsoft's documentation confirms SMS and voice keep working until the February 2027 retirement date, so there is no need to rush a specific device setup today. If you want a broader comparison of authenticator methods, including how app-based codes compare to email-based ones, switching to an authenticator app: what to set up first covers the backup-method precautions worth taking with any authentication-method migration, passkeys included.

Where does MagicLess fit?
This rollout is about how Microsoft Entra ID authenticates people into work and school accounts — it has nothing to do with how MagicLess works. None of this changes how MagicLess works: it still reads whatever email verification codes a connected Gmail inbox receives, for the accounts that keep using them after this rollout. If an account you use MagicLess for eventually moves entirely to a passkey with no email-code fallback, there simply will not be a code left for MagicLess to surface for that specific account — which is the correct, expected outcome of a more phishing-resistant setup.
FAQ
Why is my work Microsoft account suddenly asking me to set up a passkey?
Starting September 1, 2026, Microsoft Entra ID automatically enrolled accounts using SMS or voice MFA into passkeys and began nudging them to register one at their next sign-in, per Microsoft's own documentation.
Do I have to set up a passkey right now?
Not immediately. Microsoft's documentation states SMS and voice continue working until Microsoft-provided delivery retires on February 1, 2027; after that date, an account with no other MFA method will be required to register a passkey to sign in.
Does this affect my personal Outlook.com or Hotmail account?
No. This announcement and the linked Microsoft Learn documentation describe an Entra ID (organizational, work/school) change, not a personal Microsoft account change.
Does this mean I no longer need email verification codes for other websites?
No. This change is specific to Microsoft Entra ID's own MFA methods. Microsoft's documentation does not describe any effect on how other services deliver email-based verification codes.
Can my company opt out of this for now?
Microsoft's documentation describes a temporary, admin-configured opt-out through a Microsoft Graph authentication-methods policy setting, available through February 1, 2027, after which standard migration and enforcement timelines apply regardless.
Claim ledger
| Claim | Source | Last checked | Confidence |
|---|---|---|---|
| Starting September 1, 2026, Microsoft Entra ID auto-enables passkeys for users on SMS or voice MFA and nudges them to register one at next sign-in. | Microsoft Security Blog: Microsoft Entra ID security updates — passkeys are the default authentication method | 2026-09-16 | High |
| Microsoft-provided SMS and voice delivery for Entra ID MFA retires February 1, 2027, after which users with no other MFA method must register a passkey to sign in, with no opt-out. | Microsoft Learn: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication | 2026-09-16 | High |
| A temporary, tenant-level opt-out from automatic passkey enablement is available via a Microsoft Graph policy setting through the February 1, 2027 deadline. | Microsoft Learn: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication | 2026-09-16 | High |
| This rollout is scoped to Microsoft Entra ID (organizational accounts); Microsoft's documentation does not describe an effect on email-delivered one-time codes from other services. | Microsoft Learn: Frequently asked questions about SMS and voice retirement | 2026-09-16 | Medium |