Microsoft 365 Security Change 2026
Microsoft Is Making An Important Security Change To The Way Users Securely Access Microsoft 365 And Other Services Protected By Microsoft Entra ID Find out moreGet in touchMicrosoft Security is Changing with Passkeys: What Your Business Needs to Know
From 1 September 2026, Microsoft will begin moving users away from SMS and voice-based authentication and towards passkeys, a more secure and phishing-resistant way to verify identity.
For businesses, this is more than another Microsoft update. It is a good opportunity to review how employees access business systems, how credentials are managed and whether your current approach provides the right level of protection against modern cyber threats.
What is Microsoft changing?
Many businesses currently use SMS codes or telephone calls as part of Multi-Factor Authentication (MFA). While these methods provide considerably more protection than relying on a password alone, they can still be vulnerable to attacks such as phishing and SIM swapping.
Microsoft is therefore moving towards stronger, phishing-resistant authentication, with passkeys becoming an increasingly important part of its authentication experience.
From 1 September 2026, users currently enabled for SMS or voice authentication will automatically be enabled for passkeys. When affected users sign in and complete MFA, Microsoft may prompt them to register a passkey.
This is the first stage of a wider transition. From 1 February 2027, Microsoft-provided SMS and voice authentication will be retired from Microsoft Entra ID.
Businesses should use the time available to identify affected users, review their current authentication setup and prepare employees for the change.
What is a passkey?
A passkey uses cryptographic authentication rather than relying on a traditional password or one-time security code.
Users can authenticate through trusted methods such as Windows Hello, Microsoft Authenticator or a FIDO2 security key.
The key security benefit is that there isn’t a reusable password or authentication code that an attacker can simply trick a user into handing over. Microsoft states that passkeys are resistant to phishing, SIM-swap and replay attacks, providing much stronger protection against common methods used to compromise business accounts.
For users, passkeys can also make signing in easier by reducing the need to remember passwords or manually enter security codes.
Does SMS MFA stop working in September?
1 September 2026 marks the beginning of Microsoft’s transition, rather than the immediate retirement of SMS and voice authentication.
Microsoft-provided SMS and voice authentication is scheduled to be fully retired on 1 February 2027.
This gives organisations time to prepare, but businesses should avoid leaving the transition until the final deadline. Users who currently depend on SMS or voice MFA should be identified and moved to an appropriate alternative authentication method.
What about your other business accounts?
Microsoft’s move towards passkeys is an important security improvement, but Microsoft 365 is only one of the many systems employees access every day.
Employees may also need passwords for cloud applications, supplier portals, industry-specific software and other online services. Managing an increasing number of credentials can lead to password reuse, weak passwords or credentials being stored and shared insecurely.
This is where Keeper Enterprise Password Manager, provided and managed by AMJ IT, can help.
Keeper gives employees a secure, encrypted vault for their business credentials and makes accessing accounts easier by automatically filling passwords, passkeys and two-factor authentication codes.
It can generate strong, unique passwords for individual services, helping to reduce password reuse without requiring employees to remember multiple complex credentials. Keeper also provides a controlled way to share business credentials between authorised employees, avoiding insecure practices such as sending passwords through email or Teams or storing them in spreadsheets.
Keeper can integrate with Microsoft 365 and Microsoft Entra ID, allowing businesses to complement Microsoft’s move towards stronger authentication with secure credential management across the other applications their employees use.
What should businesses do now and how can AMJ Help?
With Microsoft’s first changes arriving on 1 September 2026, businesses should start preparing now.
Organisations should identify employees who currently depend on SMS or voice MFA, review their Microsoft Entra authentication configuration and establish how those users will transition to passkeys or another appropriate authentication method.
It is also a good opportunity to review credential security across the wider business. Consider how employees currently create, store and share passwords for other systems.
AMJ IT can help you review your Microsoft 365 and Entra ID authentication configuration, identify users affected by Microsoft’s upcoming changes and prepare your organisation for the move towards passkeys.
We can also help you implement Keeper Enterprise Password Manager, providing employees with a straightforward and secure way to manage the passwords and credentials they still need across other business systems.
Unsure how Microsoft's authentication changes will affect your organisation?
BOOK A FREE REVIEWLook no further and get in touch with our team!
Whether you are looking for a new IT company to support your business, advise on a specific IT requirement or project or assistance or a specific area of your IT, our team will be happy to help.
Pleast fill in our available form or get in touch with our team by email or phone

