If your business runs on Microsoft 365, there is a good chance some of your team still logs in by typing a password and then a six-digit code from a text message. That method is going away, on a schedule Microsoft has already published.
This is not a vendor nudge or a best-practice suggestion. It is a dated change to how sign-in works, with an enforcement date attached — and most small businesses have not heard about it yet, because the announcement lives in an identity-administration document nobody outside IT reads.
The two dates that matter
September 1, 2026 — passkeys become the default. Anyone currently set up for text or phone-call codes is automatically enabled for passkeys, and the next time they complete a sign-in they get prompted to register one. It is a nudge, not a wall: people can skip it, and by default they can keep skipping it. Nothing breaks. But every one of your employees starts seeing an unfamiliar security prompt, and if nobody has told them it is coming, your phone rings.
February 1, 2027 — Microsoft-provided text and voice codes are retired. After this date, anyone whose only second factor is a text message or phone call is required to register a passkey during sign-in before they can continue into their account. Microsoft describes this prompt as blocking, and states there is no opt-out from it for any tenant.
Nobody is permanently locked out of anything. But “my login is demanding something I have never seen and I have a client on the phone” is a bad morning for the employee and a worse one for whoever supports them — multiplied by however many people were still on text codes.
Why Microsoft is doing it
Because text-message codes were never actually strong, and attackers have gotten very good at collecting them. A convincing fake login page asks for the password and the code in the same breath, and relays both to the real site while the victim is still reading. SIM-swap fraud moves the phone number itself. Neither attack requires sophistication anymore — the toolkits are rented.
A passkey removes the thing being stolen. Instead of a secret you type, your device proves who you are with a key it never hands over, unlocked by your fingerprint, face, or PIN. There is nothing to phish, because there is nothing to type. That is the whole reason insurers and auditors started asking specifically about phishing-resistant authentication instead of just asking whether you have MFA.