Microsoft appears to be moving organizations toward passkeys while also phasing out SMS and voice authentication in Entra ID. We have SMS and voice disabled already, but users are still being affected by the passkey registration campaign. Is this controlled by the Microsoft-managed default in the authentication methods policy, and what settings should administrators review to prevent unexpected changes?
4 Answers
You can opt out of the registration campaign for now, but that only delays the user experience changes. Microsoft is still planning to retire its built-in SMS and voice authentication service for many users, so organizations should move users to stronger methods such as passkeys or authenticator-based authentication. The dates have been revised for some groups, so check the latest tenant Message Center notice.
Check whether your authentication methods policy is using the Microsoft-managed default for passkeys. If you want control over when this changes, explicitly set the passkey registration campaign and related methods to Disabled instead of leaving them managed by Microsoft.
If your organization must keep using SMS or voice after Microsoft stops providing the service, the updated guidance indicates that you may need to choose and pay for a supported telecom provider through Microsoft’s security marketplace. That is separate from disabling the passkey registration campaign, so both areas need to be checked.
Review the tenant health dashboard and Message Center regularly, and make sure the right administrators receive notifications. Microsoft has been warning about this for months, including through admin emails, so the safest approach is to monitor those notices and test the authentication policy before the deadline.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures