Starting September 1, 2026, Microsoft Entra ID will begin automatically nudging every user still on SMS or voice-based multi-factor authentication to register a passkey instead, according to Microsoft's own security blog. This isn't a minor settings tweak — it's the beginning of Microsoft formally retiring phishable authentication methods across its identity platform.

The full timeline runs through early 2027: auto-enrollment nudges begin September 1, 2026; pricing and provider details for organizations that still need SMS or voice for regulatory reasons arrive September 18; those organizations must configure a third-party telecom provider by October 30, 2026 and cover the cost themselves going forward; and Microsoft-provided SMS/voice delivery ends entirely on February 1, 2027, after which passkey registration becomes mandatory with no opt-out.

The reasoning is straightforward — Microsoft's own Digital Defense Report found phishing-resistant MFA blocks more than 99% of identity-based attacks even when an attacker already has a valid username and password, and identity-based attacks specifically surged 32% in the first half of 2025. SMS and voice codes remain vulnerable to SIM-swapping and real-time phishing kits in a way passkeys, which never leave the user's device, aren't.

For IT teams, the useful move now is proactive rather than reactive: audit which users and groups are still on SMS or voice MFA, and start the passkey rollout on your own schedule before Microsoft starts pushing prompts on theirs. Organizations that wait until September will be managing this as an emergency instead of a planned rollout.