The sign-in prompt your staff are about to start seeing

If your business runs on Microsoft 365, your staff are about to be asked to set up something called a passkey. Most of them will not know what it is, whether it is genuine, or whether they are allowed to ignore it. The short answers are that it is genuine, they can ignore it for now, and from 1 February 2027 they will not be able to.

Microsoft has begun making passkeys the default way of signing in across Microsoft Entra ID, the identity service sitting behind every Microsoft 365 account. From 1 September 2026, anyone still set up to receive a text message or an automated phone call to prove who they are is being enabled for passkeys automatically and prompted to register one the next time they complete multi-factor authentication, or MFA, which is the second step you do after typing your password.

The prompt can be dismissed as often as a user likes, and that is where businesses will come unstuck. Nothing appears to break, so nothing gets done, and the date arrives with most of the company untouched.

What a passkey actually is

A passkey replaces the password rather than adding another step to it. When someone registers one, their device creates a matched pair of cryptographic keys. The private half never leaves the device and is unlocked by the same face, fingerprint or PIN they already use to open the phone or the laptop. The public half is handed to Microsoft. Signing in means the device proving it holds the private key, so there is nothing to type and nothing an attacker can talk somebody into reading out.

That is the whole point of them. Passkeys exist to defeat phishing, which is the convincing email or the fake sign-in page that persuades somebody to hand over their details. A passkey is tied to the exact web address it was created for, so a copied Microsoft login sitting on a lookalike domain has no key to ask for and gets nothing.

Microsoft's own threat intelligence reports AI-assisted phishing campaigns reaching click-through rates as high as 54 per cent, against roughly 12 per cent for more traditional ones. A six-digit code sent by text does not stop any of that, because the person still types it into whatever page asked for it.

The NCSC, the government's cyber security body, puts the case for passkeys plainly.

Passkeys are resistant to phishing, as they can't be intercepted, reused or stolen like passwords.

It now recommends people choose passkeys over passwords wherever they are offered, and its published technical comparison concluded that passkeys are always as secure or more secure than two-step verification using the strongest password. Microsoft, drawing on hundreds of millions of consumer accounts already using them, reports that 99 per cent of users successfully register a synced passkey, that signing in takes about 3 seconds rather than 69, and that sign-ins succeed 95 per cent of the time against 30 per cent for older methods.

The dates that decide your February

Microsoft has published the timetable in full. Some of these dates you can work around, and the last one you cannot.

  • 1 September 2026 Anyone in your organisation still set up for text message or voice call verification is automatically enabled for passkeys and nudged to register one at their next sign-in. By default those nudges can be snoozed as many times as the user likes.
  • 18 September 2026 Microsoft publishes details of the outside telephone providers that can carry text and voice codes for organisations that genuinely need them.
  • 30 October 2026 Those providers can be chosen and configured, at your own cost, through the Microsoft Security Store.
  • 1 February 2027 Microsoft stops delivering text message and voice codes itself. Anyone whose only remaining method is a text or a call is stopped at sign-in and must register a passkey before they can continue. Microsoft states that there is no opt-out from this and that it is enforced for every customer.

There is a temporary opt-out covering the months in between, applied by an administrator. It buys you time to do the work in your own order, and it expires on 1 February 2027 along with everything else.

Synced or device-bound: which kind you hand out

Microsoft supports two kinds of passkey, and the difference matters more in a business than it does at home.

  • Synced passkeys Created on the device and copied, encrypted, into the user's own credential store, such as Apple Passwords or Google Password Manager, so the same passkey works across their phone, tablet and laptop. Microsoft's own guidance is that these are the sensible default for most staff. A lost or broken device does not lose the passkey.
  • Device-bound passkeys Created and kept on one device and never copied anywhere else. In practice that means a physical security key or the Microsoft Authenticator app. Microsoft recommends these for administrators, directors and anyone with access to sensitive systems, and they are the only kind whose make and model can be checked at the moment of registration.

Both are a serious upgrade on a text message, and neither adds to your bill. Passkeys are available in every edition of Microsoft Entra ID, including the free one, with no extra licence required. What this project costs you is time and communication, not software.

The device requirements are modest but not nothing. Windows gives the best experience on Windows 10 version 1903 or later, Apple's built-in credential store needs macOS 13 or iOS 16 or later, and Google's needs Android 9 or later. Anything too old for that was already a problem you were going to have to deal with.

What passkeys do not fix

Passkeys are the strongest everyday sign-in most businesses will ever put in place, and they are not the end of the story. The NCSC has been unusually candid about the gaps, and these are the ones that catch out a smaller business rather than a bank.

  • Account recovery becomes the target The NCSC warns that attackers are now more likely to focus on finding weaknesses in account recovery and reset requests, whether by email, phone or chat. If somebody can talk your help desk into a reset, you have moved the problem rather than solved it.
  • Shared logins still do not work The whole model assumes one person has exclusive, private access to the account and the device. The generic login that four people in the office share cannot be fixed with a passkey, and it was never safe to begin with.
  • Guests are excluded Microsoft does not support passkey registration for guest accounts, including the external people you have invited into Teams or SharePoint. They will still need another method.
  • Moving between providers is awkward The NCSC notes that shifting passkeys from one credential store to another is currently difficult, although the industry is working on it. Decide where your staff keep theirs before you start registering people.
  • Changing a sign-in name breaks the passkey If somebody's Microsoft sign-in address changes, after a marriage or a rebrand for instance, the existing passkey cannot be edited to match. They delete it and register a new one.

Where this leaves Cyber Essentials

If you hold Cyber Essentials, or your customers and insurers ask you for it, this change works in your favour. Multi-factor authentication on cloud services has been a requirement of the scheme for years, and the April 2026 update sharpened the marking. IASME, which runs the scheme on behalf of the government, says the updated requirements apply to assessment accounts created after 27 April 2026, and that failing to have it in place across the whole of your scope now fails the assessment outright rather than costing you a few marks.

Passkeys satisfy that requirement comfortably. The scheme's guidance treats FIDO2 authenticators, which is the open standard passkeys are built on, as multi-factor authentication in their own right, because the person has to prove who they are to the device before the key will work at all. The work you do to beat Microsoft's February date is the same work that protects a certificate you probably already hold.

What to do between now and February

None of this needs a project team. It needs one person to own it and a few months of steady follow-up, because the difficult part is people rather than technology.

This month

  • Find out who is still on text messages Microsoft publishes a script that lists exactly which of your users are set up for text or voice. Until you have that list, every estimate of the work is a guess.
  • Tell people the prompt is real The biggest cause of help desk calls in a change like this is staff assuming an unfamiliar sign-in screen is an attack. Send that message before the prompts start, not after the first person has rung you about it.

Before Christmas

  • Start with the people who would hurt most Directors, finance, and anyone who can move money or change payroll details. Give them a security key or the Authenticator app rather than a synced passkey.
  • Register everybody else during ordinary sign-in A registration campaign prompts people at the moment they are already proving who they are, which works far better than asking them to visit a settings page in their own time. A user has to have completed multi-factor authentication in the previous five minutes before they can add a passkey.
  • Deal with the shared logins now Give the people using them their own named accounts. A shared account can hold a passkey on only one person's device, so everybody else loses their way in.

Before 1 February 2027

  • Check nobody is left on a text message alone Anyone still in that position on the day is stopped until they register a passkey, and that happens at whatever moment they next try to sign in.
  • Be honest about the exceptions If you have a genuine regulatory reason to keep text codes, you can buy delivery from an outside provider through Microsoft. If the real reason is that a few people find the new screen unfamiliar, that is a training job rather than a purchase.
  • Tighten the way you reset accounts Write down what proof somebody has to give before an account gets reset, and who is allowed to do it. That is where the attackers go next.

The deadline does some of the work for you

Most security improvements are a hard sell internally because nothing visible changes afterwards. This one comes with a date and a consequence attached, which makes it an easier case to put to the people who have to pay for it, and it removes a running cost and a real risk at the same time.

The businesses that have a bad February will be the ones that let everyone snooze the prompt until snoozing stopped being an option. The ones that never notice February at all will be the ones that spend an hour this month finding out who is affected, and then tell their staff what is coming. That hour, and one clear email, is most of the job.