Our organization is suddenly seeing users prompted to register passkeys, even though we have SMS and voice authentication disabled. I also understand that Microsoft is moving away from SMS and voice authentication and may eventually enforce passkeys or require organizations to use a paid telecom provider for phone-based authentication. We apparently missed some of the earlier announcements and want to understand which settings control the registration campaign, what the current deadlines are, and how to prevent Microsoft-managed defaults from changing our authentication policy unexpectedly.
3 Answers
This has not really been sudden. The change has been announced for months, with repeated notices sent to tenant administrators. The timelines have also changed: some administrators and external users may receive an extension, while other users still face the earlier deadline. The safest approach is to follow the current administrator notices rather than relying on older dates, and plan for passkeys or another supported authentication method now.
You can disable or postpone the passkey registration campaign for now, but that does not remove the broader move away from SMS and voice authentication. Organizations should disable legacy authentication methods where appropriate, communicate the change to users, and test another method before the retirement deadlines arrive.
We disabled SMS and voice already, but users are still seeing the passkey prompts. The Microsoft-managed setting was the part we had missed, so explicitly disabling the registration campaign is worth checking.
Check your authentication methods policy and see whether passkeys or the registration campaign are set to Microsoft-managed. If you do not want Microsoft changing the behavior automatically, explicitly set the relevant option to Disabled rather than leaving it on the managed default. Also review the Entra admin center's Message center and service health notifications so these changes do not come as a surprise.

There may also be an option to keep phone-based authentication through a supported paid telecom provider after the built-in service is retired, but passkeys are clearly the direction Microsoft wants organizations to adopt.