As phones move onto the internet, your broadband connection becomes a single point of failure. Lose it and you lose calls, card payments, Teams and files at the same time. Here is what a backup connection looks like and when satellite makes sense.
Are you ready for Microsoft’s new sign in changes?

If your team signs in to Microsoft 365 with a code sent by text message or a phone call, that is about to stop working. Microsoft announced on 13 July that it is retiring SMS and voice as authentication methods in Entra ID, and passkeys have taken over as the default sign in experience from 1 September 2026.
This is not a suggestion or a nudge towards best practice. Microsoft has confirmed that the final cut off on 1 February 2027 applies to every tenant with no opt out. For a lot of North East businesses, the first sign anything has changed will be a member of staff standing at a laptop unable to get into their email.
What is actually changing
There are two separate changes bundled into one announcement, and it helps to keep them apart.
The first is that passkeys are now the default. From 1 September, any user who was enabled for SMS or voice in the authentication methods policy has been automatically enabled for passkeys, and the registration campaign has been switched to Microsoft managed state. The next time those users sign in and complete MFA, they get prompted to register a passkey. By default that prompt can be snoozed as many times as the user likes, so plenty of people will click past it and forget about it.
The second change is the retirement itself. From 1 February 2027, Microsoft stops delivering SMS and voice codes natively. Anyone left with a phone number as their only MFA option will be forced to set up a passkey before they can get in, and Microsoft has been explicit that there is no way to opt out of that.
If your staff already use the Microsoft Authenticator app, Windows Hello or a hardware key, very little changes for them. The people who will feel this are the ones still receiving six digit codes by text.
The dates that matter
There are four to put in the diary.
1 September 2026 is done. Passkeys are the default and the registration nudges have started.
18 September 2026 is when Microsoft publishes details of the customer managed telecom providers available through the Microsoft Security Store.
30 October 2026 is when you can actually select and configure one of those providers. This is worth being precise about, because it is being reported in places as a deadline. It is not. It is the date the option opens up for organisations with a genuine regulatory or operational need to keep a telephony channel.
1 February 2027 is the only hard deadline. After that, Microsoft provided SMS and voice are gone.
There is a temporary opt out for the September to February window, applied through Microsoft Graph, which buys time while you migrate. It does nothing at all for the February enforcement. If you want the full detail, Microsoft’s passkeys by default and SMS retirement guidance and the accompanying frequently asked questions are the authoritative sources.
Why Microsoft is doing this
None of this should be a surprise. Text message codes have been the weakest form of MFA for years. SIM swapping is straightforward, phone numbers get recycled and codes can be intercepted in real time by a convincing enough fake login page.
The NCSC reached the same conclusion some time ago. Its multi-factor authentication guidance is clear that not all MFA is equal, and that methods relying on a one time passcode are vulnerable to interception because the user can be tricked into typing the code straight into an attacker’s site. Passkeys are not vulnerable to this, because the credential is cryptographically tied to the real domain. A fake login page cannot use it.
We have written before about how businesses can protect themselves from phishing attacks. What has changed since is that the defence is no longer optional or something you configure yourself. Microsoft has made the decision for you.
What this means in practice
Three things tend to catch businesses out.
The first is Cyber Essentials. MFA sits at the heart of the user access control requirements, and if your documented method disappears in February your certification evidence goes with it. We covered the common stumbling blocks in our piece on what is catching people out with Cyber Essentials, and this is going to become one of them.
The second is client due diligence. Which MFA method you use is now a standard line on security questionnaires, and “SMS codes” is an answer that increasingly loses work. If you are already fielding those questions, our guidance on what to do when customers ask about your IT security is a useful starting point.
The third is the helpdesk load. Passkey registration is genuinely simple for someone with a modern phone or a laptop with Windows Hello. It is much less simple for shared machines, for sites where phones are not permitted on the floor and for staff who do not have a suitable device. Those cases need FIDO2 hardware keys, and hardware keys need budgeting, ordering and distributing. That takes weeks, not days.
Where it bites hardest
Some sectors cannot absorb a blocked sign in.
For legal firms, a fee earner locked out of a case management system on a completion day is a client problem within the hour. For social care providers, rostering and care records are needed at handover, and staff turnover means a constant stream of new users who need enrolling correctly from day one.
In both cases the risk is not the technology. It is doing this reactively in late January with no plan, no hardware and no communications to staff.
What to do now
Start by finding out who is actually affected. Microsoft publishes a PowerShell script that lists every user in your tenant still enabled for SMS or voice. In most small and medium businesses the number is lower than people expect, which makes the whole thing far less daunting.
From there it is a straightforward sequence. Enable passkeys properly in your tenant, run a controlled registration campaign rather than letting the automatic nudges do the work, identify the handful of users who need a hardware key and order them, then communicate the change to staff before they meet it at a login screen.
This is exactly the kind of change that belongs in a managed service rather than on someone’s to do list. Our IT service management team handles tenant changes like this as routine work, with the user communications and the helpdesk cover that go with them. If you want to look at it in the wider context of how your systems are set up, our business IT solutions page covers the broader picture.
February will arrive quickly, and the businesses that deal with this in the autumn will barely notice it happening.
Get a quote or give the team a call, and we will tell you where your tenant stands.
