Microsoft is moving away from SMS and voice-based MFA in favor of passkeys and other phishing-resistant authentication methods. All of my users currently use Microsoft Authenticator push notifications with number matching. Is this sign-in method expected to remain supported, or should we begin migrating everyone to passkeys?
2 Answers
Yes, Microsoft Authenticator push notifications with number matching are still supported. The changes are aimed primarily at reducing reliance on SMS and voice MFA, so your current setup should continue working for the foreseeable future.
You should be fine, but it’s still worth planning for passkeys over time. Passkeys may become the default recommendation for newly onboarded users, and some existing users may already have one through Windows Hello or another supported method. Whether the passkey option appears depends on your tenant’s configuration and Microsoft’s rollout status.
That option may not appear until passkeys are enabled for the organization and the relevant users. Check the authentication-method policies and rollout settings in the Microsoft Entra admin center.

Are passkeys available for users already? I checked the available sign-in methods in the Microsoft security-info page, but Passkey wasn’t listed as an option.