# Microsoft Entra ID authentication method transition

> Live situation record from CLSTR: https://clstr.news/situations/microsoft-entra-id-authentication-method-transition
> Updated: 2026-08-31T18:03:52.000Z. Sources: 14. Developments: 3.

Microsoft is transitioning its Entra ID identity platform toward passwordless authentication by phasing out SMS and voice call-based multi-factor authentication (MFA). This shift is driven by the rise of AI-enabled cyber threats, including increased effectiveness in phishing, social engineering, and SIM-swapping attacks.

Starting September 1, 2026, passkeys will become the default sign-in method for Microsoft Entra ID tenants. During this phase, users currently relying on SMS or voice credentials will be prompted to register a passkey during the sign-in process as part of an automatic enablement and registration campaign. Organizations have a temporary window between September 2026 and February 1, 2027, to use the Microsoft Graph API to delay automatic registration and coordinate migrations.

Passkeys utilize a cryptographic key pair where the private key remains securely on the user's device—often leveraging TPM 2.0 hardware—while the public key is stored on the service server. Authentication is typically completed via biometrics, such as facial recognition or fingerprints, or through a PIN via Windows Hello. Supported storage methods include Microsoft Authenticator, password managers, mobile devices, or physical security keys. For Windows 11 users, the implementation integrates with the operating system and Edge browser to provide a phishing-resistant experience.

As part of this broader strategic push, Microsoft is testing a feature in the Edge browser Canary build designed to automatically detect and replace weak passwords with stronger ones. By February 1, 2027, Microsoft will permanently terminate native SMS and voice verification for all Entra ID accounts. After this deadline, no opt-out option will be available, and any users exclusively using the discontinued methods will be required to register a passkey to sign in.

## Timeline

### 2026-08-31: Microsoft advances passwordless security via passkeys and Edge updates

Microsoft is moving toward passwordless security by making passkeys the primary authentication method for Entra ID by September 2026 and testing automated password updates in the Edge browser.

4 sources. https://clstr.news/cluster/microsoft-to-implement-passkeys-as-default-sign-in-method

### 2026-08-18: Microsoft to phase out SMS and voice authentication for Entra ID

Microsoft will phase out SMS and voice call authentication for Entra ID, moving toward automatic passkey enablement by September 2026 and ending legacy SMS/voice services by February 2027.

3 sources. https://clstr.news/cluster/microsoft-entra-id-to-automate-passkey-migration-by-2026

### 2026-08-14: Microsoft to end Entra ID SMS and voice authentication by 2027

Microsoft will end SMS and voice authentication for Entra ID by February 2027, pushing users toward phishing-resistant passkeys to combat AI-driven cyberattacks and SIM-swapping.

8 sources. https://clstr.news/cluster/microsoft-to-end-sms-and-voice-authentication-for-entra-id-by-2027

---
Cite as: Microsoft Entra ID authentication method transition. CLSTR, https://clstr.news/situations/microsoft-entra-id-authentication-method-transition
