Why Businesses Should Start Moving Away From SMS Authentication
For years, SMS has been one of the most common ways businesses have implemented multi-factor authentication (MFA).
It was a significant improvement over using passwords alone. But the security landscape has changed, and SMS is no longer considered a strong enough defence against increasingly sophisticated account takeover attacks.
Microsoft is now pushing organisations towards a more secure alternative: passkeys.
And for businesses using Microsoft 365 and Microsoft Entra ID, this isn’t simply a technology trend to keep an eye on. The move away from SMS authentication is already underway.
Microsoft is making passkeys the default
Microsoft is continuing its move towards phishing-resistant authentication, with passkeys becoming increasingly central to Microsoft Entra ID.
From 1 September 2026, Microsoft says users who are enabled for SMS or voice authentication in the Entra Authentication Methods Policy will be automatically enabled for passkeys, with registration campaign settings also being updated to bring those users into scope.
For businesses still relying heavily on SMS codes, this is an important opportunity to review how users authenticate to Microsoft 365 and other business systems.
Rather than waiting for Microsoft to make changes to your environment, now is a good time to plan the transition.
Why is SMS authentication being replaced?
SMS-based MFA is better than having no MFA at all, but it has well-known weaknesses.
An SMS verification code can potentially be intercepted or obtained through:
- Phishing attacks
- SIM-swapping
- Social engineering
- Mobile number compromise
- Fake login pages
- Man-in-the-middle attacks
An attacker doesn’t necessarily need to break into your Microsoft 365 environment directly. They may simply need to convince an employee to provide the six-digit code they’ve just received.
This is why modern phishing campaigns increasingly target the authentication process itself.
Passkeys take a fundamentally different approach.
What exactly is a passkey?
A passkey is a modern, passwordless authentication credential based on public-key cryptography and FIDO standards.
Instead of typing a password and then entering an SMS code, the user authenticates using something already built into their device.
That might be:
- Windows Hello
- A fingerprint
- Face recognition
- A device PIN
- A smartphone
- A FIDO2 security key
The important difference is that the authentication credential is cryptographically tied to the service it was created for.
A passkey created for your Microsoft 365 environment cannot simply be entered into a fake Microsoft login page.
Microsoft describes passkeys as phishing-resistant because they use origin-bound public-key cryptography, meaning the credential is associated with the legitimate service it was registered with.
In simple terms:
SMS asks:
“Can you enter the code we just sent to your phone?”
A passkey asks:
“Can your trusted device cryptographically prove that you’re really you?”
That’s a significant security improvement.
Passkeys aren’t just more secure — they’re easier
Security improvements often come with additional complexity.
Passkeys are one of the rare cases where the opposite can be true.
Instead of:
- Enter username
- Enter password
- Wait for SMS
- Find phone
- Read code
- Type code
- Get the inevitable “code expired” message
A user can often simply:
- Enter their username
- Select their passkey
- Use their fingerprint, face or PIN
Microsoft’s own Entra documentation reports that synced passkeys have been significantly faster than traditional password plus MFA combinations, with Microsoft reporting an average of around 3 seconds compared with 69 seconds in its analysis.
For businesses with dozens or hundreds of employees, that reduction in friction can add up quickly.
But rolling out passkeys isn’t as simple as pressing a button
This is where having the right IT partner becomes important.
A business shouldn’t simply enable passkeys for everyone overnight and hope for the best.
A successful passkey rollout needs to consider:
Which users should move first?
We would typically recommend starting with a controlled group of users.
This allows the organisation to:
- Test the registration process
- Identify compatibility issues
- Understand user behaviour
- Check account recovery procedures
- Confirm Conditional Access policies
- Monitor authentication logs
- Resolve problems before a company-wide rollout
Once the process has been proven, the rollout can be expanded.
Not every user needs the same type of passkey
One of the advantages of Microsoft Entra ID is that organisations can take a more sophisticated approach to authentication.
For many standard users, synced passkeys can provide a convenient and highly secure option.
For administrators and highly privileged accounts, a device-bound passkey or FIDO2 security key may be more appropriate.
Microsoft specifically recommends device-bound passkeys for administrators and highly privileged users, while synced passkeys are recommended for most other users.
This means your IT team should consider your users based on their risk profile rather than deploying exactly the same authentication method to everyone.
For example:
Standard employee
→ Synced passkey
Finance/HR user
→ Stronger authentication policy
Microsoft 365 administrator
→ Device-bound passkey or FIDO2 security key
This approach gives businesses stronger protection where it matters most without unnecessarily increasing costs or complexity for everyone.
What happens to SMS?
This is perhaps the most important part of the conversation.
Adding passkeys isn’t enough.
If a user has a highly secure passkey but still has SMS authentication enabled as a fallback, the weaker authentication method may remain an avenue for attack.
This is sometimes referred to as the fallback problem.
Imagine fitting an extremely strong lock to your front door but leaving a spare key underneath the doormat.
The lock is excellent.
The problem is the fallback.
Microsoft has highlighted this issue itself, pointing out that organisations need to consider dormant passwords and SMS methods even after stronger authentication has been deployed.
That’s why a proper migration should ultimately look at:
Passkey deployment → User adoption → Recovery → Removal of weaker authentication methods
rather than simply:
Passkey deployment → Done
What about users who lose their phone or device?
This is one of the most common concerns we hear when discussing passwordless authentication.
“What happens if someone loses their phone?”
This is exactly why recovery planning needs to form part of the project.
Synced passkeys can help because the credential can be available across a user’s trusted devices, reducing the impact of losing a single device.
For higher-risk users using device-bound credentials or physical security keys, organisations need a clear recovery and replacement process.
That might include:
- Registering an additional authentication method
- Having a second security key
- Defining an identity verification process
- Establishing an emergency administrator process
- Documenting account recovery procedures
- Ensuring the helpdesk cannot simply bypass security after a convincing phone call
That last point is particularly important.
The strongest authentication system in the world can be undermined by a weak helpdesk recovery process.
How we can help your business move away from SMS
As an MSP, we can manage the transition from start to finish.
Rather than simply enabling a Microsoft feature and leaving your staff to work it out, we can take a structured approach.
1. Review your current authentication setup
We start by understanding how your organisation currently authenticates users.
This can include reviewing:
- Microsoft Entra ID
- Microsoft 365
- MFA configuration
- SMS authentication
- Microsoft Authenticator
- Conditional Access
- Administrator accounts
- Guest accounts
- Authentication methods
- Existing security policies
This gives us a clear picture of where the risks are.
2. Identify high-risk accounts
Not every account represents the same level of risk.
We can identify accounts that deserve additional protection, particularly:
- Global Administrators
- Microsoft 365 Administrators
- Finance users
- Senior management
- HR users
- Users with access to sensitive information
- Users with access to critical business systems
These accounts can then be prioritised for phishing-resistant authentication.
3. Design the passkey rollout
We’ll create a staged rollout rather than switching everything on at once.
For example:
Phase 1 — IT team
Test the configuration internally.
Phase 2 — Pilot users
Introduce passkeys to a small group of users.
Phase 3 — Wider rollout
Gradually introduce passkeys across the organisation.
Phase 4 — Remove SMS
Once users have successfully registered and recovery procedures have been tested, remove weaker authentication methods where appropriate.
4. Configure Microsoft Entra ID
We can configure the relevant Microsoft Entra authentication policies and Conditional Access controls to support the rollout.
This can include configuring passkey profiles, registration campaigns and appropriate authentication strengths.
Microsoft Entra supports both synced and device-bound passkeys, allowing policies to be tailored to different user groups.
5. Help your staff through the change
Technology projects often fail because the technology works but the people don’t understand it.
That’s why user communication is an important part of the process.
We can provide straightforward guidance explaining:
- What passkeys are
- Why SMS is being phased out
- How to register a passkey
- How to use it
- What happens if a device is lost
- How account recovery works
- What users should do if they receive an unexpected authentication request
The goal is to make the transition feel like an improvement rather than another IT headache.
Passkeys are part of a bigger security strategy
Moving away from SMS shouldn’t happen in isolation.
It is a good opportunity to review your wider Microsoft 365 security environment.
For example:
Identity
→ Passkeys and phishing-resistant MFA
Access
→ Conditional Access policies
Devices
→ Microsoft Intune and device compliance
→ Anti-phishing and email security
Accounts
→ Least privilege and administrator protection
Monitoring
→ Sign-in and security alerts
Recovery
→ Secure account recovery procedures
Together, these controls create a much stronger security foundation than relying on passwords and SMS codes.
The future of business authentication is passwordless
Passwords aren’t disappearing overnight.
But the direction of travel is clear.
Microsoft, Google, Apple and other major technology companies are investing heavily in passkeys and passwordless authentication.
For businesses, this represents an opportunity to move away from authentication methods that are increasingly vulnerable to phishing and social engineering.
Passkeys offer a combination that traditional MFA has struggled to deliver:
Better security + less user friction.
And with Microsoft actively moving customers towards passkeys, businesses using Microsoft 365 should start planning their transition now rather than waiting for the changes to arrive.
Ready to move away from SMS authentication?
As your MSP, we can assess your current Microsoft 365 authentication setup, identify where your biggest risks are and create a phased plan to introduce passkeys across your organisation.
From the initial assessment and Microsoft Entra configuration through to user rollout, training and the eventual removal of weaker authentication methods, we can manage the process for you.
Want to find out how ready your business is for passwordless authentication? Get in touch with us today for a Microsoft 365 security and authentication review.