You know the routine. You type your password. Your phone buzzes. You squint at six digits, race to type them in, and hope the code hasn’t expired.
That routine is on its way out. Microsoft is replacing text-message and phone-call login codes with something called a passkey. If you sign in to Microsoft 365 at work, you’ll see the change soon.
The good news is that passkeys are easier than what they replace. Most people sign in faster with one. Here’s what they are and what to expect.
What is changing, and when
Microsoft has set two dates for its work and school sign-in system, called Microsoft Entra ID.
- September 1, 2026: Passkeys become the default. If you now get login codes by text or phone call, Microsoft turns on passkeys for you. The next time you sign in, it asks you to set one up.
- February 1, 2027: Microsoft stops sending login codes by text and phone call. If that was your only backup method, you must set up a passkey before you can sign in.
Two groups get extra time. Global administrators and outside guest users have until July 1, 2027.
This applies to work and school accounts. Microsoft’s announcement covers Entra ID, not personal accounts like Outlook.com.
So, what is a passkey?
Think of a passkey as a house key that only works on your own front door. And nobody can copy it by looking over your shoulder.
Here’s how it works. When you create a passkey, your device makes two matching pieces. One is a lock, and the website keeps it. The other is the key, and it stays on your device.
When you sign in, the website asks your device to prove it holds the key. You approve with your face, fingerprint, or PIN. That’s it. The key never travels over the internet, and nobody can talk you into reading it aloud.
A password is something you know. A text code is something you’re sent. A passkey is something your device already has, tied to something only you can do.
Where does the Authenticator app fit?
You may already use Microsoft Authenticator. It’s the app that asks you to approve a sign-in or shows a six-digit code that keeps changing.
The app now has a second job. It can create and hold a passkey for your work account. Think of it as a key ring on your phone.
Passkeys in the app work a little differently. They stay on the phone where you made them. They don’t sync to other devices. The app holds one passkey per work account, and it needs an internet connection.
Microsoft says the app supports iPhone (iOS 17 or later) and Android (version 14 or later). If your phone is older, check with IT first.
You have other choices too. A passkey can also live in Windows Hello on your PC or on a physical security key. Or it can sit in iCloud Keychain or Google Password Manager. Those synced options follow you to a new device.
Microsoft recommends phone-locked passkeys for administrators and other highly privileged users. For everyone else, it recommends synced passkeys.
What about the approval prompts and rotating codes? Microsoft still lists them today. The February 2027 change targets text and phone-call codes only. Microsoft’s documentation doesn’t say how long approvals and codes will last, so plan on passkeys.
Why text codes are being retired
Text codes were a big step up from passwords alone. But they have a weakness. A person can trick you into handing one over.
Here’s a common trick. A fake login page asks for your password and your code. You type both. The attacker types them into the real site a moment later, and they’re in.
Microsoft says text and phone codes rely on “shared secrets or channels that attackers increasingly intercept, phish, or manipulate.” It also reports that AI-written phishing campaigns reach click-through rates as high as 54%. Traditional campaigns reach about 12%.
A passkey blocks that trick. It only works on the real website. A fake page has nothing to steal, because you never type or read out a secret.
What signing in feels like
You open the sign-in page and enter your email. Your phone or computer asks for your fingerprint, face, or PIN. You approve, and you’re in.
No six-digit code. No waiting for a text. No “I never got the message.”
If you already open your phone with your face, you already know the skill.
Is anyone else using passkeys?
Yes, and the number is big. The FIDO Alliance is the industry group behind the technology. It estimated 5 billion passkeys were in use worldwide in May 2026.
Its survey of 11,000 consumers found 75% had turned on a passkey for at least one account. Among companies, 68% had deployed passkeys for employee sign-ins or were actively rolling them out.
Google, Apple, and Microsoft all support them. You’ve likely been offered one already.
Your questions, answered
What if I lose my phone?
Set up a backup before you need it. An Authenticator passkey can’t move to a new phone. A new phone means a new passkey. Register a second method on another device, such as your work laptop. If you’re locked out, call your IT team.
Is it safe to use my face or fingerprint?
Your face or fingerprint only approves the key on your own device. It isn’t sent to the website. If you’d rather not use biometrics, a device PIN works too.
Do I have to do this?
For most work accounts, yes, by February 1, 2027. Your company can delay the switch until then. It can’t skip the passkey requirement for users who only have text or phone codes.
Can my company keep text codes?
Possibly. Microsoft says companies with a real business or regulatory need can use a third-party phone provider. Those options open October 30, 2026, and the company pays the phone costs.
How it works
- Watch for the passkey prompt the next time you sign in to Microsoft 365.
- Skipping works today but stops on February 1, 2027.
- Set up a passkey on the device you use every day, or in the Authenticator app.
- Add a second method on another device, such as your laptop, so you have a backup.
- Tell your team the prompt is real. Attackers copy new features, so confirm with IT if a message looks odd.
- Ask your IT team what happens to your account on February 1, 2027.
What if you skip the prompt?
Nothing bad happens at first. Until February 1, 2027, you can skip it. Microsoft says users get unlimited snoozes by default. The prompt comes back the next time you go through a multifactor sign-in.
That changes on February 1. If a text or phone call is your only backup method, the prompt becomes a blocking one. There’s no skip button. You must register a passkey before you can finish signing in.
You won’t be locked out for good. But you can’t get into your account until you register.
Skip it until January, and you may hit that wall on a travel day. Registering now is a one-time setup, and it spares you the surprise.
The blocking prompt targets people whose only method is a text or phone call. If you already use a passkey, Windows Hello, or a security key, it doesn’t force anything on you.
A note for business owners and managers
Don’t leave this to the last week. Some employees will be traveling, on leave, or using an older phone in January. Each one is a potential lockout on day one.
Start now. Tell staff what’s coming, run a small pilot group, and give people a clear place to ask for help. A quiet February 1 is the goal.
Your IT provider can check which users still rely on text codes today. That list is your to-do list.
Need a hand with the rollout? Call ADNET. We’ll help your team make the switch without the panic.
ADNET Technologies | Engagement@thinkadnet.com
Rocky Hill, CT 860.409.1700 | Albany, NY 518.458.9300