Team: Huntress Managed Identity Security Posture Management (ISPM)
Product: Microsoft Entra ID, Microsoft 365
Environment: Microsoft 365
Summary: Microsoft is changing the default authentication experience for some Microsoft Entra ID users beginning September 1, 2026, which is not a Huntress Managed ISPM change.
In this Article
Overview
What changes on September 1, 2026?
Important distinction: this is not a Managed ISPM change
What happens to SMS and voice authentication?
What should partners do?
Optional temporary migration delay
Frequently asked questions
Overview
Microsoft is beginning a rollout that makes passkeys the default authentication experience for users who currently use Microsoft-provided SMS or voice calls for multi-factor authentication (MFA).
This change applies to users who are enabled for SMS or voice in the Microsoft Entra Authentication Methods Policy or in legacy MFA settings. This is a Microsoft Entra ID change. Huntress Managed ISPM is not making this change, and partners should not interpret the new passkey registration prompt as an action by Managed ISPM.
For the latest details, review Microsoft’s Passkeys by default and retirement of Microsoft-provided SMS and voice authentication article.
What changes on September 1, 2026?
For users currently enabled for Microsoft-provided SMS or voice authentication:
Microsoft automatically enables passkeys for the affected users.
Microsoft places those users in a passkey profile that allows all passkey types.
Microsoft manages the passkey registration campaign for those users.
The next time an affected user signs in and completes MFA, Microsoft might prompt them to register a passkey on their device.
The registration prompt has unlimited snoozes by default, so users might not register a passkey immediately.
Users already using passkeys, Windows Hello for Business, FIDO2, or another phishing-resistant method can continue using those methods. However, users who remain enabled for SMS or voice might still receive a passkey registration prompt.
Microsoft might roll out the change gradually, so users in the same tenant might not see the prompt at exactly the same time.
Important distinction: this is not a Managed ISPM change
Huntress Managed ISPM is not responsible for the September 1 rollout.
Managed ISPM Managed Deployment does not enable secure authentication methods by default.
The related Managed ISPM security control is available for manual remediation only.
A passkey prompt that begins appearing on or after September 1, 2026, comes from Microsoft Entra ID, not from Huntress Managed ISPM.
What happens to SMS and voice authentication?
Microsoft has announced that Microsoft-provided SMS and voice authentication will retire on February 1, 2027.
After that date, users whose only available MFA method is SMS or voice must register a passkey at sign-in to continue accessing their account. This prompt blocks access, and Microsoft does not provide an opt-out, applying it to all tenants.
Microsoft also states that customer-managed telecom providers configured through the Microsoft Security Store are not affected by the retirement. Microsoft expects provider information to be available beginning September 18, 2026, and provider configuration to be available beginning October 30, 2026.
What should partners do?
Partners should prepare their users for the change and review their current authentication methods in Microsoft Entra ID.
Review Microsoft’s guidance for finding active SMS or voice users to identify affected users. Microsoft notes that this requires an appropriate directory role, such as Global Reader, Authentication Policy Administrator, or Security Reader.
Communicate that Microsoft might prompt affected users to register a passkey after September 1, 2026.
Encourage users to register a passkey or another supported phishing-resistant authentication method, such as Windows Hello for Business or FIDO2.
Before February 1, 2027, move affected users away from Microsoft-provided SMS and voice authentication to avoid being blocked when they retire.
Review Microsoft’s passkey migration guidance for the current configuration and registration recommendations.
Optional temporary migration delay
Microsoft documents a temporary opt-out from the automatic passkey enablement and registration campaign rollout from September 1, 2026, through February 1, 2027.
This option is intended to provide additional time for migration activities. It requires Microsoft Graph permissions and a policy change by a qualified Microsoft Entra administrator. It does not avoid the February 1, 2027, retirement or the blocking enforcement that follows. Review Microsoft’s temporary opt-out instructions before applying this setting, and be aware of its limitations.
Frequently asked questions
Did Managed ISPM enable passkeys for my users?
No. The passkey rollout is initiated by Microsoft through Microsoft Entra ID. Managed ISPM didn't automatically enable this change.
Why are my users seeing a new passkey registration prompt?
Microsoft prompts users who are enabled for Microsoft-provided SMS or voice authentication to register a passkey as part of its authentication-method rollout.
Could users who already use passkeys still see the prompt?
Yes. Microsoft says users who remain enabled for SMS or voice might still receive the registration prompt, even if they already use another phishing-resistant method.
Does having Huntress Managed ISPM change Microsoft’s rollout?
No. The Microsoft rollout occurs independently of Managed ISPM. The related ISPM security control is manual and is not automatically enabled through Managed Deployment.
Does this mean SMS and voice stop working immediately on September 1, 2026?
No. September 1, 2026, is the start of Microsoft’s passkey auto-enablement and registration-prompt rollout. Microsoft has announced February 1, 2027, as the retirement date for its native SMS and voice authentication.
What happens if a user still relies only on SMS or voice after February 1, 2027?
Microsoft requires users to register a passkey at sign-in before they can continue accessing their accounts. The prompt blocks access, and Microsoft does not provide an opt-out from this enforcement.
What should I tell a user who is concerned about the prompt?
Explain that the prompt is from Microsoft Entra ID and is part of Microsoft’s move toward phishing-resistant authentication. The user should follow their organization’s authentication policy and contact their Microsoft 365 administrator if they need help registering a passkey.