How to set up passkeys for Microsoft 365

This guide is for a small business moving Microsoft 365 users from SMS or voice to passkeys without lockouts. It covers the right order: find affected users, choose methods, test recovery, pilot and register controlled groups.
Know the Microsoft timeline, then plan calmly
Microsoft begins rolling out passkeys as the default authentication experience in Microsoft Entra ID on 1 September 2026. When the rollout reaches your organisation, users enabled for SMS or voice are automatically enabled for passkeys and prompted to register a passkey the next time they perform MFA. Treat that as the start of the rollout, not a date when every user must have changed.
The hard date is 1 February 2027. Microsoft retires its own telecom delivery for SMS and voice authentication then. Users who use SMS or voice must register a passkey before they can sign in, automatic registration prompts are enforced for all users in all tenants, and Microsoft says there is no opt-out. This applies to Microsoft Entra ID in the public cloud.
Start with people and accounts that still use SMS or voice. For background before choosing a method, read what passkeys are and how they work.
Step 1: find who still relies on SMS or voice
Review the authentication method policy and identify users and groups enabled for SMS or voice. Record their role, devices and whether losing the usual device would stop work. Flag shared devices, staff without a smartphone, people who do not want a work credential on a personal device, and anyone about to replace a device. Any user can be locked out if their only method is unavailable.
You are deciding how each person can authenticate and recover access. It also supports the wider checks in our Microsoft 365 security guide.
Step 2: match the passkey type to the person
Microsoft Entra ID supports synced and device-bound passkeys. Synced passkeys, such as those in iCloud Keychain or Google Password Manager, sync across a user's devices. They are easier to recover but rely on the user's Apple or Google account. Microsoft Authenticator passkeys, Entra passkeys on Windows and FIDO2 security keys are device-bound, so need a replacement arrangement.
Do not force one method on everybody. A member of staff who is comfortable using their own device may suit a synced passkey. A Windows user may suit an Entra passkey on Windows. A person on shared equipment, without a smartphone or unwilling to use a personal device may be better served by a FIDO2 security key. Every choice needs a recovery route.
Microsoft does not state a licence requirement for passkeys. Check your tenant's licences before planning around a control. For the wider service picture, see TSS's Microsoft 365 support.
Step 3: sort recovery and break-glass access first
Device loss is the main operational risk with passkeys. Before a broad rollout, give every user a second method or documented recovery route. Decide who verifies a user asking for help, who restores access and where the process is recorded. A plan in one administrator's memory is not enough.
Keep emergency administrator access separate from day-to-day use and test recovery with the pilot group. Document how lost phones, keys and replacement devices are handled, and who is authorised to check identity and restore access.
Step 4: run a small, representative pilot
Choose a small group that covers a Windows user, a mobile user, a remote worker and, where relevant, a shared-device or security-key user. Enable suitable passkey types, then ask them to register during an MFA sign-in and sign out and back in normally.
Check that the passkey works on the genuine Microsoft sign-in route and that recovery works without the expected device. Record staff questions and applications that still need a password. Not every business application supports passkeys yet, so a password manager still has a job.
Step 5: run the registration campaign and explain it
Microsoft tells admins to use a registration campaign in Microsoft Entra ID to move users at scale. It prompts passkey registration during an MFA sign-in. Run manageable groups rather than relying on an automated prompt to explain the change.
Tell staff what is changing, when they may see the prompt and where to get help. Explain that the passkey is unlocked locally with device biometrics or PIN, and biometric data is not sent to Microsoft.
Passkeys are tied to the genuine site or app, so a false domain cannot trigger the real passkey. Staff should still report suspicious email. Share our staff phishing email guide with the rollout notice.
Step 6: make a defined plan if SMS or voice must remain
SMS and voice are not impossible after 1 February 2027, but Microsoft stops providing the telecom delivery. From 30 October 2026, admins can configure a supported third-party telecom provider through the Microsoft Security Store. Document the affected group, pilot the provider and have it ready before 1 February 2027. The customer pays its telecom costs.
Do not use this as a reason to delay the general rollout. Microsoft's guidance is to ensure every user has a phishing-resistant method, such as a passkey, an Entra passkey on Windows or a FIDO2 security key.
Step 7: verify and keep the record current
After each group moves, check that the users previously enabled for SMS or voice have a working phishing-resistant method and a recovery route. Update the policy, user instructions and the record of who owns recovery. Review the awkward cases again when a new starter joins, a key is lost or somebody replaces a phone.
Cyber Essentials does not require passkeys. From April 2026, MFA must be enabled on a cloud service when it is offered or the assessment cannot be passed. The update promotes passwordless authentication and passkeys. Keep this work in your cyber security plan, and share our MFA explainer with staff.
What to do next
Make the SMS and voice user list, choose the pilot group and agree recovery before the rollout reaches your organisation. TSS supports businesses in Bury, Greater Manchester and Lancashire. Arrange a free, no-obligation chat with TSS if you would like help turning the list into a practical plan.
Need a calm plan for Microsoft 365 passkeys?
Book a free, no-obligation chat and we will help you plan the rollout, recovery and staff support.