Your text message security code may soon become a thing of the past, and for small businesses using Microsoft 365, this is a change worth preparing for now.

Microsoft is moving its Entra ID customers toward stronger, phishing-resistant authentication methods such as passkeys. Beginning September 1, 2026, users who currently use SMS or voice authentication will begin being automatically enabled and prompted to register passkeys. Then, on February 1, 2027, Microsoft-provided SMS and voice authentication services will be retired.

That does not mean your organization should wait until 2027 to deal with the change. Moving dozens of employees to a new authentication method can create confusion, support calls, locked-out users, and lost productivity if it is handled at the last minute.

For small businesses, this transition is also an opportunity to improve security beyond Microsoft 365 by taking a fresh look at how passwords, passkeys, and other credentials are managed throughout the organization.

Why Microsoft Is Moving Away from SMS and Voice Authentication

For years, receiving a six-digit code by text message has been one of the most familiar forms of multi-factor authentication.

It is certainly better than protecting an account with only a password, but SMS was never designed to be a highly secure authentication system.

Text messages and phone calls can be vulnerable to several types of attacks.

  • Phishing: An attacker can create a convincing fake login page and trick an employee into entering both a password and the security code that was just texted to them.
  • SIM swapping: An attacker may convince a wireless carrier to move a victim’s phone number to another device, allowing the attacker to receive authentication messages.
  • Social engineering: Criminals may impersonate support personnel or other trusted individuals and convince employees to provide authentication codes.
  • Message interception: SMS relies on telecommunications systems that were not originally designed for modern identity security.

Passkeys approach authentication differently.

Instead of sending a secret code that an employee must type into a website, a passkey uses cryptographic credentials associated with the legitimate website or service. The user typically approves the login using something already built into a device, such as Windows Hello, a PIN, fingerprint, facial recognition, or another supported authenticator.

One of the biggest security improvements is that there is no six-digit code for an employee to accidentally give to an attacker.

Imagine an employee receives an email that appears to be a Microsoft 365 login request.

With traditional SMS authentication, the employee could enter a password into the fake website and then enter the authentication code they receive by text. The attacker may now have everything needed to access the account.

A properly implemented passkey is designed to work with the legitimate service it was created for. That makes this type of credential considerably more resistant to traditional phishing attacks.

The Advantages and Disadvantages of Passkeys

Passkeys offer some significant advantages, but businesses should understand that they are not magic. Like any technology, they need to be implemented and managed correctly.

Some of the biggest advantages include:

  • Much stronger phishing resistance. Employees are no longer responsible for recognizing whether every authentication page is legitimate before entering a security code.
  • No authentication codes to type. Employees do not have to wait for text messages or phone calls.
  • Faster logins. Signing in may be as simple as using Windows Hello, a fingerprint, facial recognition, or a device PIN.
  • Reduced dependence on passwords. Many services can use passkeys as a replacement for passwords rather than simply adding another authentication step.
  • Better protection from credential theft. There is no traditional reusable password or SMS code being transmitted during a passkey authentication process.

There are disadvantages and operational challenges businesses need to consider as well.

  • Employee education is still required. Passkeys are unfamiliar to many users, and people need to understand where their passkeys are stored and how to use them.
  • Device replacement must be planned for. Businesses need a recovery process when an employee loses a phone, replaces a computer, or receives a new device.
  • Different platforms may behave differently. Windows computers, Macs, smartphones, browsers, and various applications may offer slightly different passkey experiences.
  • Shared accounts can become complicated. Organizations still using shared usernames and passwords need to carefully determine how those accounts should be handled.
  • Recovery becomes extremely important. A stronger authentication method does little good if the emergency recovery process is poorly designed or insecure.

The goal should not simply be to turn on passkeys. The goal should be to create an authentication strategy that employees can actually use while providing the business with secure recovery and administrative controls.

Where a Password Manager Like Bitwarden Fits In

Passkeys do not eliminate the need for good credential management.

Most businesses will continue using passwords for many websites and applications for years. Some services will support passkeys while others will not. Employees may therefore find themselves working in a mixed environment containing passwords, passkeys, multi-factor authentication, and other credentials.

This is where a business password manager such as Bitwarden can become extremely valuable.

Rather than employees storing passwords in browsers, spreadsheets, notebooks, sticky notes, or trying to remember dozens of variations of the same password, a password manager provides a centralized way to securely manage credentials.

Bitwarden can also store and use passkeys for supported websites and applications. This means businesses can begin moving toward passkeys while continuing to securely manage traditional passwords from the same overall credential-management platform.

For a small business, an organized password-management strategy can help:

  • Generate strong, unique passwords for different accounts.
  • Reduce password reuse among employees.
  • Securely store business credentials.
  • Manage passkeys for supported services.
  • Control access to shared business credentials.
  • Improve employee onboarding and offboarding.
  • Reduce the temptation to share passwords through email or text messages.

Consider what happens when an employee leaves a company.

If passwords and credentials have been informally shared among employees, determining what needs to be changed can become a major project. With a properly managed credential system, administrators have much better visibility and control over who has access to business resources.

Passkeys and password managers should therefore be viewed as complementary technologies rather than competing solutions.

What Small Businesses Should Do Before Microsoft Makes the Change

The worst approach is waiting until employees start receiving mandatory registration prompts.

Businesses using Microsoft 365 should begin reviewing their authentication environment now.

A practical transition should include:

  1. Identify who is still using SMS or voice authentication. Determine which Microsoft 365 users currently depend on these methods.
  2. Develop a passkey strategy. Decide which authentication methods your organization will support and how passkeys will be deployed.
  3. Create a recovery plan. Establish what happens when an employee loses or replaces an authenticated device.
  4. Review password management. If employees are still managing business passwords individually, consider implementing a business password manager such as Bitwarden.
  5. Educate employees before making changes. A short explanation and clear instructions can prevent significant confusion and support calls.
  6. Roll out the change gradually. Moving a few users first provides an opportunity to identify problems before deploying the new authentication process throughout the company.

Microsoft’s move away from SMS and voice authentication is part of a much larger shift toward phishing-resistant authentication across the technology industry.

For small businesses, that is a good thing. But stronger security still requires planning, configuration, employee education, and ongoing management.

Newby Technologies can help your organization evaluate its Microsoft 365 authentication configuration, develop a passkey migration strategy, implement a password management platform such as Bitwarden, and identify other areas where account security can be improved.

NT Cyber Shield provides small businesses with a comprehensive cybersecurity approach designed to protect users, devices, accounts, and business data against today’s constantly changing threats.

Learn more about NT Cyber Shield and how Newby Technologies can help strengthen your organization’s cybersecurity.

Schedule a consultation and let us help you build a practical plan for moving from passwords and SMS authentication toward stronger, phishing-resistant security.