The landscape of business security is undergoing its most significant shift in a decade. For Small and Medium Enterprises (SMEs) relying on Microsoft 365, the clock is now ticking on traditional Multi-Factor Authentication (MFA).
Microsoft has officially announced two critical deadlines that will redefine how your team accesses company data. By September 1, 2026, Microsoft will begin auto-enabling passkeys for all users currently using SMS or voice authentication. Following this, on February 1, 2027, Microsoft-provided SMS and voice delivery for MFA will be fully retired.
At Anantek Solutions, we believe in "Invisible Infrastructure": tech that works so reliably in the background that you forget it’s even there. However, moving from legacy SMS codes to phishing-resistant passkeys requires a deliberate strategy to avoid user lockout and operational downtime.
The End of the SMS Era: Why Now?
For years, SMS-based MFA was the gold standard for SME security. It was easy to deploy and familiar to users. However, in an era of sophisticated "Man-in-the-Middle" (MitM) attacks and SIM swapping, SMS is no longer considered secure by modern standards.
Passkeys, based on FIDO2 standards, are fundamentally different. They are phishing-resistant because they use public-key cryptography. Unlike a six-digit code that can be intercepted or tricked out of an employee, a passkey requires a physical device or biometric verification (like FaceID or Windows Hello) that is mathematically tied to the specific service being accessed.
Key Deadlines for Your Calendar:
- September 1, 2026: Microsoft Entra ID will auto-enable passkeys as the default experience. Users relying on SMS/Voice will be prompted to register a passkey during their next sign-in.
- February 1, 2027: The retirement of Microsoft-managed SMS/Voice delivery. If your team hasn’t migrated by this date, they risk being blocked from accessing Microsoft 365 entirely.
Strategic Benefits for the Modern SME
Transitioning to passkeys isn't just about compliance; it's about building "Tech That Lasts."
- Eliminating Phishing Risks: Passkeys effectively neutralise the most common cause of data breaches: stolen credentials.
- Improved User Experience: No more hunting for phones to find a text code. A quick touch of a finger or a glance at a camera is all it takes.
- Longevity of Investment: By adopting phishing-resistant methods now, you are future-proofing your cyber security infrastructure against upcoming regulatory requirements.

Step-by-Step Guide: Preparing Your Entra ID Environment
Preparation should not be left until the summer of 2026. To ensure a seamless transition, IT Directors and Operations leads should follow this structured deployment roadmap.
1. Audit Your Current Usage
Before changing policies, you must understand your baseline. Navigate to the Microsoft Entra admin center and review your Authentication Methods policies. Identify which groups are most dependent on SMS and voice. These users are your priority for communication and training.
2. Enable Passkeys (FIDO2) in Entra ID
You don't need to wait for Microsoft to auto-enable this for you.
- Go to Protection > Authentication methods > Policies.
- Select Passkeys (FIDO2) and set the status to Enabled.
- Pro Tip: Start by targeting a "Pilot Group" of technical staff or early adopters rather than the whole company at once.
3. Define Your Passkey Profiles
Microsoft introduces two types of passkeys: Device-bound (e.g., a physical YubiKey) and Synced (e.g., passkeys stored in an iCloud Keychain or Google Password Manager).
- For most SMEs, a Balanced approach that allows both is ideal for flexibility.
- For high-security environments, such as those handling sensitive financial data, you may choose to restrict access to device-bound passkeys only.

4. Launch a Registration Campaign
Microsoft provides a built-in "Registration Campaign" tool. This allows you to "nudge" users to set up their passkeys without blocking their work immediately. From late 2026, these nudges will become more frequent, but starting now allows your helpdesk and support team to manage queries at a manageable pace.
5. Update Conditional Access Policies
To truly secure your environment, update your Conditional Access policies to "Require phishing-resistant MFA" for sensitive applications. This ensures that even if a password is leaked, the attacker cannot bypass the passkey requirement.
Handling Device Loss and Recovery
A common concern for SME owners is: "What happens if an employee loses their phone or security key?"
Robust IT infrastructure requires a fallback plan. Ensure your recovery processes are documented:
- Temporary Access Passes (TAP): Admins can issue a time-limited code that allows a user to sign in and register a new passkey.
- Multiple Registrations: Encourage users to register at least two passkeys: for example, Windows Hello on their laptop and a passkey on their mobile device.
- Alternative MFA: While Microsoft is retiring their SMS service, you can still maintain the Microsoft Authenticator app as a reliable backup method.
The Foundation: Why Infrastructure Matters
At Anantek, we often work with high-end retail and commercial fit-outs, providing the structured cabling and Wi-Fi installs that power modern businesses. We've delivered these mission-critical environments for world-renowned brands like Audemars Piguet (AP) and A. Lange & Söhne (ALS).
Why does this matter for your Microsoft 365 security? Because software-level security is only as good as the hardware and connectivity it sits on. A passkey system relies on stable, high-speed Wi-Fi and robust network architecture. If your physical infrastructure is outdated, even the most advanced security protocols will feel clunky and slow.
Whether we are optimising a school's network or a luxury retail showroom, we focus on the same goal: Improved Longevity.

Managing the Human Element
The technical shift to passkeys is often easier than the cultural one. SMEs should communicate the "Why" behind the change:
- Frame it as a benefit: "We are making your login faster and more secure."
- Provide simple guides: Use screenshots showing the FaceID or fingerprint prompt so users know what to expect.
- Phased Rollout: Don't flip the switch for everyone on a Monday morning. Use your pilot group feedback to refine your internal documentation.
Should You Keep SMS?
If your business has a specific edge case: such as employees using legacy "dumb" phones without biometric capabilities: you can technically keep SMS/Voice after February 2027. However, you will need to purchase and configure a third-party telecom provider via the Microsoft Security Store. For 95% of SMEs, moving fully to passkeys and the Authenticator app is the more cost-effective and secure route.
Partnering for a Secure Future
Transitioning your entire organization to a passwordless environment can feel daunting. As your trusted partner, Anantek Solutions is here to ensure your transition is seamless. From auditing your current Entra ID setup to deploying the underlying connectivity needed for a modern office, we handle the complexity so you can focus on growth.
Our expert customer support responds in an average of one minute, ensuring that if your team does encounter a registration hiccup, they aren't left waiting.

Ready to secure your infrastructure?
Don't wait for the September 2026 deadline to catch you off guard. Contact Anantek today for a comprehensive Security and Infrastructure Audit. We’ll help you build a roadmap for passkey adoption that protects your data and empowers your team.