Passkeys: what’s replacing your text-message login codes
Last week we covered fake websites and the one habit that defeats them. This week is about a login method that defeats them automatically — and a Microsoft deadline that makes it urgent rather than optional. If you set up multi-factor authentication a few years ago and haven’t revisited it since, this one is for you.
“Why is Microsoft asking me to register a passkey — is it genuine?”
A Greater Manchester law firm called us after a partner asked what should have been a simple question: why was Microsoft prompting her to register something called a passkey, and was it genuine?
It was. But nobody in the firm knew that, so the safest assumption — ignore it — was exactly the wrong one.
When we looked, eleven of their twenty-two staff had a mobile number as their only second factor. Two of those numbers belonged to people who had left. One was a shared handset kept in reception for out-of-hours calls.
None of that is unusual. Text-message codes were the easy option when multi-factor authentication was first rolled out, and nobody revisits a thing that works.
The problem is it stops working on a fixed date. We spent an afternoon registering passkeys, clearing out the stale numbers, and writing down who was responsible for the reception phone. The firm’s deadline pressure disappeared.
The Microsoft prompt is real. Ignoring it doesn’t make it go away — it just means you meet it later, under time pressure, when a login you needed has already stopped working.
Why this matters
- Microsoft made passkeys the default authentication experience on 1 September 2026, automatically enabling them for anyone still using SMS or voice — so personal account holders are being moved whether they act or not. Microsoft Learn (2026): Retirement of SMS and voice methods.
- From 1 February 2027, Microsoft-provided SMS and voice retire completely, including self-service password reset, and affected users receive a blocking passkey registration prompt with no opt-out. Microsoft Learn (2026): SMS and voice retirement FAQ.
The fix
The practical difference is where the secret lives. A texted code travels to you, and anything that travels can be redirected, read over your shoulder or phished. A passkey never leaves your device and only responds to the real web address. That’s why Microsoft’s stated reasoning for the change is that text and voice codes no longer withstand AI-assisted attacks.
If you’re not sure how your own Microsoft 365 tenant is set up, that’s the thing to check this month rather than in January. The NCSC’s guidance on this is consistent — secure your important online accounts with strong, phishing-resistant sign-in, and don’t rely on a single factor you can lose.
Three quick wins you can act on this week
🏠 At home
Register a passkey on your personal Microsoft, Google and Apple accounts. Each takes a couple of minutes and uses the fingerprint or face unlock you already use to open your phone. Keep one backup method registered until you’re confident.
🏢 At work
Run a report on who still has a phone number as their only second factor, then check that list for leavers and shared handsets. Register passkeys for those users now. If you genuinely need SMS after February, you’ll need a customer-managed telecom provider, which can be configured from 30 October.
🌍 For everyone
Don’t wait for the blocking prompt. Set passkeys up while everything still works, so your fallback is available if something goes wrong — rather than being the thing that’s broken.
How the sign-in methods compare
Honest comparison — the routes in most common use, and how they hold up after February.
| Sign-in method | Can it be phished? | Works after 1 Feb 2027? | Best for |
|---|---|---|---|
| Password alone | ❌ Very exposed | Yes, but weak | Nothing |
| Password + SMS code | ❌ Yes — the code can be typed into a fake site | Not via Microsoft | Being replaced |
| Password + authenticator app | ⚠️ Reduced, still possible | Yes | A solid interim step |
| Passkey | ✅ Resistant — bound to the real web address | Yes, and it’s the default | Everyone |
| Hardware security key | ✅ Resistant | Yes | High-risk admin accounts |
What this looks like locally
We’re working through this with law firms, accountancy practices and manufacturers across Denton (M34), Ashton-under-Lyne (OL6), Stockport (SK1) and Trafford (M33). The pattern is consistent: a tenant where multi-factor authentication was switched on years ago, a handful of staff still on text-message codes, and at least one phone number nobody can account for. Finding those takes minutes now. Finding them in February takes a bad morning.
If you’d like this built into how your Microsoft 365 tenant is looked after — phishing-resistant sign-in, cleaner leaver processes and a plan for the February deadline — it’s all part of a SecureState review.
Frequently asked
What is a passkey?
A login tied to your device and the genuine website, unlocked by your fingerprint, face or screen PIN. There’s no code to type and nothing extra to remember.
Is Microsoft really getting rid of text-message codes?
Yes. Microsoft-provided SMS and voice retire on 1 February 2027, including for self-service password reset. See Microsoft Learn (2026).
What happens if I do nothing?
Users whose only method is a phone number will meet a blocking passkey registration prompt they can’t dismiss or postpone.
Are passkeys safer than a texted code?
For phishing, yes. A code can be entered into a convincing fake site. A passkey is bound to the real web address and simply won’t work on a copy — which is the fake-website problem solved at the login screen.
What if I lose my phone?
Register a passkey on more than one device, or keep a second method available. Passkeys sync through your Apple, Google or Microsoft account depending on your setup.
Can we keep SMS for a few users?
Only through a customer-managed telecom provider, configurable from 30 October 2026. Microsoft stops providing the service itself.
“A code travels to you, and anything that travels can be intercepted. A passkey stays put — that’s the whole idea.” — Brett Casterton, Inology IT
Let’s clear the SMS list before February forces the issue.
I’m Brett at Inology IT. We’ll check your tenant, find the accounts still relying on SMS, register passkeys for them and clear out any stale numbers — well before February forces the issue. Drop your details below and I’ll come back to you the same day.
Last reviewed by Brett Casterton, September 2026.