Act Before September 1: Microsoft Entra’s Passkey Auto-Migration

By: Michael C. Korting
|
08/21/2026
이미지

What tenant administrators need to know about the temporary opt-out, configuration changes, SMS and voice retirement, and the February 2027 enforcement date.

The immediate decision
Microsoft will begin changing eligible tenant configuration on September 1, 2026. If your organization is not ready for automatic passkey enablement and a Microsoft-managed Registration Campaign, use the temporary Microsoft Graph opt-out before the rollout reaches your tenant. The opt-out delays the September changes only. It does not change the February 1, 2027 enforcement.

Executive summary

  • On September 1, Microsoft begins auto-enabling passkeys for users enabled for SMS or voice in the Authentication Methods Policy or legacy MFA settings.
  • Microsoft will set the Registration Campaign to Microsoft Managed, target passkeys, and place in-scope users into a profile that allows all passkey types, including synced and device-bound passkeys.
  • A temporary Graph beta setting can defer those automatic September changes while an organization completes migration or configures a customer-managed telecom provider.
  • On February 1, 2027, Microsoft-provided SMS and voice delivery is retired across Entra, including self-service password reset. There is no opt-out from that enforcement.
  • The published timeline applies to public cloud. Sovereign and government clouds follow later schedules.

What Microsoft will change in your tenant

This is more than a retirement notice. For tenants with eligible users, Microsoft is changing authentication policy and registration-campaign behavior. Administrators should review current intent before the automatic rollout begins.

Area

September 1 change

Why it matters

Passkey policy

In-scope SMS or voice users are auto-enabled for passkeys in AMP.

Existing assignments are expanded without an administrator initiating the change.

Passkey profile

In-scope users are placed in a profile allowing all passkey types.

Synced passkeys, such as iCloud Keychain and Google Password Manager, may be allowed alongside device-bound methods.

Registration Campaign

Campaign settings move to Microsoft Managed and target passkeys.

A campaign currently aimed at another method can be repointed for in-scope users.

User prompt

After MFA sign-in, in-scope users are nudged to register a passkey.

The default allows unlimited snoozes until the February enforcement behavior.

Temporary opt-out: the action available now

Use deliberately
The temporary opt-out is intended to delay automatic passkey and Registration Campaign enablement while you complete transition work. It applies from September 1, 2026 through February 1, 2027. It is not a permanent exemption.

Who is actually in scope on September 1?

The September auto-enablement is narrower than “everyone using Microsoft Authenticator.” It targets users enabled for SMS or voice in AMP or legacy MFA settings.

Scenario
An Authenticator-only user who is not enabled for SMS or voice is not brought into scope by the September 1 SMS/voice migration. A user who uses Authenticator but is also enabled for SMS or voice can be in scope and may receive the passkey registration nudge.

User experience by scenario

Authenticator only, no SMS or voice enabled

No automatic September enrollment through this specific migration. Continue your planned passkey rollout separately.

Authenticator plus SMS or voice enabled

In scope. Passkeys can be auto-enabled and the user can be targeted by the Microsoft-managed campaign.

SMS or voice as the only available MFA method

In scope and highest risk. After February 1, 2027, native delivery is unavailable; the user receives a blocking passkey-registration experience unless a customer-managed telecom provider is configured.

Already using Windows Hello or a FIDO2/passkey method

The existing phishing-resistant method remains usable. Policy owners should still review whether the all-passkey-types profile matches organizational requirements.

SSPR is a separate operational workstream

The retirement of Microsoft-provided SMS and voice applies across Microsoft Entra, including self-service password reset. Do not limit discovery and communications to MFA sign-in. Review password-reset dependencies, recovery procedures, service-desk scripts, and user communications as part of the same program.

Timeline and decision points

Date

Milestone

Administrator action

Before Sep 1, 2026

Readiness decision

Confirm scope, review passkey-type restrictions and Registration Campaign intent, then migrate, accept the change, or apply the temporary opt-out.

Sep 1, 2026

Automatic rollout begins

Eligible users are auto-enabled for passkeys and brought into a Microsoft-managed passkey campaign. Rollout can be gradual.

Sep 18, 2026

Provider information

Review telecom provider options, terms, regional availability, and compliance fit in the Microsoft Security Store.

Oct 30, 2026

Provider configuration

Organizations with a continuing need for SMS or voice can begin selecting and configuring a provider.

Feb 1, 2027

Native delivery retired

Microsoft-provided SMS and voice are retired. The temporary opt-out no longer prevents enforcement.

After Feb 1, 2027

Blocking registration

Users whose only available MFA method is SMS or voice must register a passkey before continuing, unless an appropriate customer-managed provider path is in place.

Cost and scope caveats

  • Telecom is paid. Customer-managed telecom providers through the Security Store are paid and typically priced per message; pricing varies by provider, region, volume, and geographic distribution.
  • Passkey migration is free. Microsoft states that migrating Microsoft-provided SMS and voice users to passkeys incurs no additional cost.
  • Public cloud only. The published timeline applies to public cloud environments. Other cloud environments, including sovereign and government clouds, follow later schedules.
  • Azure AD B2C is out of scope. This announcement does not change Azure AD B2C.
  • External ID comes later. Microsoft states that the change comes to Microsoft Entra External ID next year under a separate announcement.
  • B2B and internal guests need special planning. Passkey support is planned by the end of calendar year 2026, while these users remain in scope for retirement of Microsoft-provided SMS and voice.

Administrator checklist

Identify users enabled for SMS or voice: Use Microsoft’s analyzer rather than relying only on registration reports or assumptions.

Review AMP and legacy MFA policy: Determine the exact population that Microsoft will treat as in scope.

Review passkey-type policy intent: Confirm whether allowing all passkey types, including synced passkeys, aligns with your security standards.

Review the Registration Campaign: Document its current state, target population, and authentication-method focus before September 1.

Make the opt-out decision: Apply it only if the automatic rollout conflicts with your migration or telecom-provider plan.

Include SSPR: Inventory SMS and voice use for password reset and recovery, not just MFA.

Plan guest and B2B continuity: Account for the timing gap between the September migration and planned passkey support by end of CY2026.

Prepare support communications: Explain why users are prompted, which passkey types are approved, how device replacement works, and that the nudge allows unlimited snoozes by default.

Set a February exit plan: Move users to phishing-resistant methods or configure a customer-managed telecom provider before native delivery ends.

The September deadline is about control
The most urgent question is not whether passkeys are a good destination. It is whether Microsoft’s automatic September policy changes match your tenant’s intended passkey types, Registration Campaign design, user scope, and migration sequence. Review that configuration now, and use the temporary opt-out only when you need additional control before February 1, 2027.

References

Microsoft Learn: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

Microsoft Learn: FAQ for Microsoft-provided SMS and voice retirement

Microsoft GitHub: Entra SMS and voice usage analyzer

About the Author

이미지

Michael C. Korting is a Senior Microsoft 365 Consultant at Sycomp with more than 15 years of experience helping organizations modernize their technology platforms through cloud adoption, security transformation, and digital workplace solutions. He specializes in Microsoft 365, Copilot, identity and access management, endpoint management, compliance, and Zero Trust security architectures, with extensive experience leading enterprise migrations, modernization initiatives, and governance programs

Throughout his career, Michael has partnered with organizations ranging from small businesses to enterprise clients, delivering solutions that improve security, collaboration, operational efficiency, and user experience. As a recognized Microsoft technology expert, he regularly shares practical insights on Microsoft 365, security, compliance, AI, and emerging cloud technologies through his professional blog and industry content