Entra ID Authentication Deadlines
| 1 July 2026 (passed) | 1 September 2026 | 1 February 2027 |
|---|---|---|
| Phase 2 MFA postponement deadline closes | Passkeys become default | SMS/voice retire, blocking prompt |
If you've not kept your finger on the pulse regarding Entra ID and the upcoming updates to it's authentication methods, now is probably a solid time to act. Back in 2024 Microsoft began enforcing mandatory Multi-factor Authentication (MFA) for all related sign-in attempts, the full scope was outlined within the Mandatory multifactor authenticatiion for Azure and admin portals Microsoft Learn documentation, which includes certain deadline dates for the enforcement mechanisms. We've now passed the 1 July, 2026 deadline relating to the Phase 2 MFA postponement, any customer had the opportunity to request postponement until this date.
Now that this is past, the actual enforcement mechanisms have been slowly rolling out since late last year (October 2025) and there's not a lot of time left before the full cutover is upon us! Especially important is if you're needing to further delay the inevitable to appropriately plan for the retirement of both SMS and Voice as outlined within Passkeys by default and retirement of Microsoft-provided SMS and voice authentication then you've only a few days until that extension is available to request. It's not a permanent solution, but it does give you extra time to ensure you've planned accordingly, the Microsoft Learn document above provides helpful instructions on what is required to prepare your transition to Passkey authentication.
A temporary opt-out will be available for the September 1, 2026 through February 1, 2027 changes. This allows you to delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providers or migrating to other authentication methods. API support and information for opting out will be available starting August 1, 2026.
Come 1 September, 2026 (just over 1 month away from the writing of this post) Passkey authentication methods will become the default, if you've still got employees with SMS or Voice, they'll start getting nudged towards passkey registration when they process an MFA sign-in, which is a good start. It is worth noting though, that if users are already using Windows Hello for Business, another phishing-resistant method or have already registered a passkey they will be unaffected. But ultimately, as a business, this needs to be appropriately planned and managed to ensure seamless transition.
That September deadline above is a nudge, a warning. But come 1 February, 2027 if you've not got your ducks in a row and ensured you've worked to retire SMS and Voice authentication from your users, you're likely to be in for a pretty nasty surprise as the Microsoft provided SMS and Voice is goneski. Fin. Adiós. And the outcome to those who have not uplifted their authentication methods is going to be blocking.
Users whose only available MFA method is SMS or voice will be required to register a passkey during sign-in to continue accessing their account. This prompt will be blocking. Users must register a passkey before they can continue to sign in to their account. There is no opt out from this February 1 behavior. It will be enforced for all tenants.
Now, one slight caveat that's worth calling out. Just because Microsoft is removing their provision of SMS and Voice authentication services for obvious security reasons, as a business you do still have the facility to utilise these authentication methods should you wish (you really shouldn't... But there's always outlying requirements) by ensuring you've organised and configured a customer-managed telecom provider via the Microsoft Security Store. Note though, this is not available just yet, 18 September, 2026 is when provider options will be published and they cannot be configured until 30 October, 2026.
It may feel like a bit to digest, but the primary take away should be to ensure you're actively working on getting improved modern authentication methods deployed throughout your organisation. To make things handy, Microsoft has provided a PowerShell script for running an audit against your tenancy to determine the scope of remediation required: Entra SMS / Voice Usage Analyser
And hey, if you need a hand there's a handy little contact email, signal@korthcore.com where we here at Korthcore can help you out! Don't be shy <3