17 September 2026 · By Brett Casterton

Passkeys: what’s replacing your text-message login codes

Passkeys replacing SMS login codes before Microsoft’s February 2027 retirement deadline.
A texted code travels to you — and anything that travels can be intercepted. A passkey stays put.

Last week we covered fake websites and the one habit that defeats them. This week is about a login method that defeats them automatically — and a Microsoft deadline that makes it urgent rather than optional. If you set up multi-factor authentication a few years ago and haven’t revisited it since, this one is for you.

“Why is Microsoft asking me to register a passkey — is it genuine?”

A Greater Manchester law firm called us after a partner asked what should have been a simple question: why was Microsoft prompting her to register something called a passkey, and was it genuine?

It was. But nobody in the firm knew that, so the safest assumption — ignore it — was exactly the wrong one.

When we looked, eleven of their twenty-two staff had a mobile number as their only second factor. Two of those numbers belonged to people who had left. One was a shared handset kept in reception for out-of-hours calls.

None of that is unusual. Text-message codes were the easy option when multi-factor authentication was first rolled out, and nobody revisits a thing that works.

The problem is it stops working on a fixed date. We spent an afternoon registering passkeys, clearing out the stale numbers, and writing down who was responsible for the reception phone. The firm’s deadline pressure disappeared.

The Microsoft prompt is real. Ignoring it doesn’t make it go away — it just means you meet it later, under time pressure, when a login you needed has already stopped working.

Why this matters

Timeline of Microsoft's SMS and voice retirement: 1 September 2026 passkeys become the default, 18 September 2026 telecom provider options published, 30 October 2026 customer-managed provider configurable, and 1 February 2027 SMS and voice retired completely.
Four dates worth putting in the diary — and one deadline that isn’t moving.

The fix

The practical difference is where the secret lives. A texted code travels to you, and anything that travels can be redirected, read over your shoulder or phished. A passkey never leaves your device and only responds to the real web address. That’s why Microsoft’s stated reasoning for the change is that text and voice codes no longer withstand AI-assisted attacks.

If you’re not sure how your own Microsoft 365 tenant is set up, that’s the thing to check this month rather than in January. The NCSC’s guidance on this is consistent — secure your important online accounts with strong, phishing-resistant sign-in, and don’t rely on a single factor you can lose.

Three quick wins you can act on this week

🏠 At home

Register a passkey on your personal Microsoft, Google and Apple accounts. Each takes a couple of minutes and uses the fingerprint or face unlock you already use to open your phone. Keep one backup method registered until you’re confident.

🏢 At work

Run a report on who still has a phone number as their only second factor, then check that list for leavers and shared handsets. Register passkeys for those users now. If you genuinely need SMS after February, you’ll need a customer-managed telecom provider, which can be configured from 30 October.

🌍 For everyone

Don’t wait for the blocking prompt. Set passkeys up while everything still works, so your fallback is available if something goes wrong — rather than being the thing that’s broken.

How the sign-in methods compare

Honest comparison — the routes in most common use, and how they hold up after February.

Sign-in method Can it be phished? Works after 1 Feb 2027? Best for
Password alone ❌ Very exposed Yes, but weak Nothing
Password + SMS code ❌ Yes — the code can be typed into a fake site Not via Microsoft Being replaced
Password + authenticator app ⚠️ Reduced, still possible Yes A solid interim step
Passkey ✅ Resistant — bound to the real web address Yes, and it’s the default Everyone
Hardware security key ✅ Resistant Yes High-risk admin accounts

What this looks like locally

We’re working through this with law firms, accountancy practices and manufacturers across Denton (M34), Ashton-under-Lyne (OL6), Stockport (SK1) and Trafford (M33). The pattern is consistent: a tenant where multi-factor authentication was switched on years ago, a handful of staff still on text-message codes, and at least one phone number nobody can account for. Finding those takes minutes now. Finding them in February takes a bad morning.

If you’d like this built into how your Microsoft 365 tenant is looked after — phishing-resistant sign-in, cleaner leaver processes and a plan for the February deadline — it’s all part of a SecureState review.

Frequently asked

What is a passkey?

A login tied to your device and the genuine website, unlocked by your fingerprint, face or screen PIN. There’s no code to type and nothing extra to remember.

Is Microsoft really getting rid of text-message codes?

Yes. Microsoft-provided SMS and voice retire on 1 February 2027, including for self-service password reset. See Microsoft Learn (2026).

What happens if I do nothing?

Users whose only method is a phone number will meet a blocking passkey registration prompt they can’t dismiss or postpone.

Are passkeys safer than a texted code?

For phishing, yes. A code can be entered into a convincing fake site. A passkey is bound to the real web address and simply won’t work on a copy — which is the fake-website problem solved at the login screen.

What if I lose my phone?

Register a passkey on more than one device, or keep a second method available. Passkeys sync through your Apple, Google or Microsoft account depending on your setup.

Can we keep SMS for a few users?

Only through a customer-managed telecom provider, configurable from 30 October 2026. Microsoft stops providing the service itself.

“A code travels to you, and anything that travels can be intercepted. A passkey stays put — that’s the whole idea.” — Brett Casterton, Inology IT
Not sure who in your business still logs in with a text message?

Let’s clear the SMS list before February forces the issue.

I’m Brett at Inology IT. We’ll check your tenant, find the accounts still relying on SMS, register passkeys for them and clear out any stale numbers — well before February forces the issue. Drop your details below and I’ll come back to you the same day.

We’ll never sell your details. See our privacy policy.

Last reviewed by Brett Casterton, September 2026.

← Back to Weekly Tech Tips

Inology IT — managed IT support for businesses across Greater Manchester, headquartered in Tameside.