If your school district uses Microsoft 365 and Microsoft Entra, an important authentication change is coming. Microsoft is moving users away from SMS text messages and voice calls for multi-factor authentication and toward passkeys. Beginning September 1, 2026 , Microsoft will automatically enable passkeys for users currently enabled for SMS or voice authentication and may begin prompting them to register one. Then, on February 1, 2027 , Microsoft-provided SMS and voice authentication will be retired. For K–12 IT teams, now is a good time to understand the change and start preparing users. What Is a Passkey? A passkey is a more secure and often easier way to sign in. Instead of entering a password and then waiting for a text message with a code, users verify their identity using a trusted device. Depending on how your district configures authentication, that could include: Face ID or Touch ID A computer PIN or biometric login Microsoft Authenticator A physical security key A passkey st...
One of the most common concerns I hear when schools discuss stronger cybersecurity practices is some version of this: “ We don’t want security to get in the way of creativity. ” It is a reasonable concern. Schools should be places where teachers experiment, students explore, and new ideas are encouraged. Technology has expanded those opportunities enormously. We do not want cybersecurity to turn classrooms into environments where every new idea is met with “ no. ” But there is a problem with the way this concern is often framed. It suggests we must choose between security and creativity. We do not. The better goal is freedom within reasonable guardrails. Cybersecurity Should Work Like Safety in a Science Lab Think about a science classroom. We want students to experiment. We want them to ask questions, test ideas, make discoveries, and sometimes learn from things that do not work. But encouraging experimentation does not mean eliminating safety expectations. Students do not get...