I ran Get-SmsVoicePolicyUsers.ps1 against my tenant and got results below: Registration campaign: disabled SMS state: disabled Voice state: disabled ===== IMPACT SUMMARY ===== SMS/Voice disabled - no action required. At the same time, we have a lot of users subject to MFA who have only a voice call MFA method registered on their behalf by an admin. What will happen for these users? --- EDIT ---- I found out that the migration for "As of September 30th, 2025, legacy multifactor authentication (MFA) and self-service password reset (SSPR) policies have been deprecated" was never completed for this tenant. This adds an interesting level of complexity to this upcoming MSFT change ...
Users using only WHfB or PSSO on their assigned devices that were onboarded via a TAP still get prompts to "let's keep your account secure" - they can click through and access docs, but will MS ever treat these methods on that machine as a registered passkey (stopping unnecessary prompts)?
If you decide to use the new 3rd party SMS / voice option mentioned in the article, are these users still required to register a passkey for their account?
This is a great question I hadn't thought of. If we pay for SMS for our frontline workers, will they still be nagged endlessly about passkeys?
Does the nudge is specific to passkey configuration or including all authentication methods available for the user (even non phishing resistant method such as Authenticator OTP, Authenticator Number matching, Software OATH) ? Does the nudge hit also users with SMS and also another non phishing method such as Authenticator OTP, Authenticator Number matching, Software OATH ? What about the SMS/Voice method for Admin SSPR policy ?
+1 In my case, we want to opt-out some users from receiving the "nudge" to register passkeys. MS recommends we remove the users from having SMS/Voice as an auth method. Does that mean these users can't use SMS/Voice for SSPR too?
How does this affect guest B2B users? Will passkeys be enforced on guest accounts as well?
Yes, guest users (B2B, internal, B2C) should need a passkey too.
Does it mean anyone with authenticator as their default method would have passkeys as their default on Sept 1st?
When will Guest users (B2B and Internal) support Passkeys? Will the forced passkey enablement be done for these users even though enrollment is broken for them? Will there be an extension for these deadlines for these users since the proposed alternative literally does not work for them?
Will Microsoft change Self Service Password Reset (SSPR) to allow additional authentication methods, eg Passkeys as a separate authentication method from Authenticator (notification, OTP)?
Are users going to be nudged (or forced) to register a passkey if they aren’t currently using one? Can we opt out of the nudge as a tenant? Currently we’re about 97-98% on the auth app w number matching but aren’t able to make the hop to passkeys just yet. I want to ensure users are given the option to use the auth app still.
Agree it should be clarified auth app will continue to work, even if passkey isn't configured in the app. FAQ on the article talks about you can opt out of the nudge, more info coming Aug 1 on that opt out. https://learn.microsoft.com/en-us/entra/identity/authenticat…
There's no mention on how this affects External MFA methods-- will they get tagged too? We currently use Duo Security with some SMS users (also being phased out), is Duo reporting that they are performing SMS for MFA, even though it's outside of Microsoft? Will we have control over who gets tagged and who doesn't?
The FAQ needs expanding, lower level of detail. Big risk I can see right now (on paper). User has only SMS as MFA, ignores pressure to move to passkey as they have CA trusted IP location excludes for MFA prompt. Deadline comes in Feb and goes. User signs in to Entra on new mobile device which would normally prompt for SMS. No SMS is sent, but instead a registration prompt to enrol to passkeys appear. If this is the case, in effect some form of MFA was actually removed as protection. Hacker know the userid and pass - as such they could not register passkey instead! Slight mitigation if CA policy set to restrict registration, but 95% people do not have thus CA.
How does Microsoft envision organizations handling the transition for users who aren't issued corporate phones and refuse to use their personal devices for authentication? Furthermore, for frontline or restricted-environment workers who physically cannot carry a phone, FIDO2 security keys become the only viable option. Are there any upcoming plans to improve the lifecycle management and at-scale provisioning of FIDO2 keys in Entra to better support these mandatory use cases as SMS and Voice retire?
Will/when will Microsoft provide a way for tenants to estimate costs associated with current SMS/Voice MFA usage? We have hundreds of users using SMS+Hello or SMS+PSSO but we assume they're almost never prompted for SMS.
1. What sort of due diligence should customers be performing on passkey providers? For synced passkeys most users will likely use Apple or Google password manager, but should businesses be performing deeper assessments on other password managers users may use? 2. To help customers assess the effectiveness of registration campaigns will Microsoft be providing any audit log events to indicate when a user sees but skips a passkey registration nudge?
A third-party password manager like Enpass or heylogin is recommended for passkeys to avoid vendor lock-in. An additional hardware security key like Nitrokey or YubiKey is prefered too.
Does the passkey registration campaign only targets user accounts with SMS/voice auth methods registered? Or instead, is it any user account targeted by the authentication methods policy for SMS or Voice call?
Also what about users who have SMS/voice registered but also have other (more secure) methods. Will they get nagged?
@Ben Seaba Its for all users who are enabled for SMS or voice call (users doesn't need to be registered for them) Source - MS Learn page: https://learn.microsoft.com/en-us/entra/identity/authenticat…
Will the SMS retirement include External ID, which already provides so few options? Removal of SMS from External ID would leave only email OTP and passkeys which is particularly restrictive for customers
For customers who have already committed to and prepaid a 2–3 year Enterprise Agreement, should they not be allowed to continue using SMS services until their current EA term expires?
How would you expect companies to handle frontline workers without any company device ?
You may give them a pre-configured Nitrokey or YubiKey.
Not sure enterprise will be happy to pay extra cost in this economy
Not really, but a Nitrokey is way cheaper than a breach. 😜
Should synced passkeys be the default recommendation? (given their reliance on the security of a 3rd party mobile/byod ecosystem)?
When will attestation for windows hello authenticator passkeys be supported (seems overdue if attestation and passkeys are mainstream best practice)?
Why was the timeline of February 21, 2027 chosen as the enforcement date? For large companies with large user bases impacted, this timeline is very aggressive and the has risk of causing major disruption in the business.
With Microsoft making passkey the default for MFA registrations, what about companies that have MS Authenticator configured for passwordless as the default. Why can’t companies continue to use a default like this that does meet the requirement to move away from SMS/Voice factors for their MFA instead of forcing them to a passkey default that doesn’t meet their requirements.
Are the accounts that has a utilize Microsoft Authenticator without passkey affected by this change?
1. What does MSFT Entra telemetry show for passkey adoption? 2. Timeline for them to be superseded by Verifiable Credentials 3. Is MSFT seeing uptake in FLW scenarios -Questions from Darren Robinson
Can tools like Microsoft 365 Lighthouse or CIPP help MSPs with the adoption?