I'm trying to understand how the September 2026 passkey enrollment change relates to the retirement of SMS and voice MFA. Our Entra Authentication Methods policy currently allows SMS for all users, although only a small percentage appear to have SMS or voice registered in their authentication details. I initially assumed we wouldn't need to change anything, but Microsoft's FAQ says that users enabled for SMS or voice in the policy will be automatically enabled for passkeys on September 1, 2026.
Does "all users" mean everyone in the policy scope will receive the passkey nudge, even if they have never registered SMS or voice? What happens to someone whose only registered MFA method is Microsoft Authenticator?
3 Answers
We disabled the setting after finding users who had no usable authentication method other than SMS. It’s worth checking registration details and dependencies such as self-service password reset before turning SMS or voice off, because some users may still rely on them even if adoption looks low.
Yes. The important distinction is between being registered for SMS or voice and being eligible to use it under the Authentication Methods policy. If the policy is scoped to all users, everyone in that scope can be targeted for the passkey enrollment nudge, even if they currently use only Microsoft Authenticator. The nudge is based on eligibility, not on the methods already registered.
The passkey prompt can be postponed until February 2027, so you don’t necessarily have to accept a tenant-wide rollout immediately. If you want more control, opt out of the automatic nudge and run your own enrollment campaign using staged groups or deployment rings. If SMS and voice aren’t actually being used, including for password reset, disabling them after verification is another option.

This can be especially important for contingent or frontline workers who may not have a managed phone and may not want work apps on a personal device. Make sure the replacement method works for those users before removing SMS access.