Skip to main content

Microsoft Is Moving Toward Passkeys: What K–12 IT Teams Need to Know

If your school district uses Microsoft 365 and Microsoft Entra, an important authentication change is coming.

Microsoft is moving users away from SMS text messages and voice calls for multi-factor authentication and toward passkeys.


Beginning September 1, 2026, Microsoft will automatically enable passkeys for users currently enabled for SMS or voice authentication and may begin prompting them to register one.


Then, on February 1, 2027, Microsoft-provided SMS and voice authentication will be retired.


For K–12 IT teams, now is a good time to understand the change and start preparing users.


What Is a Passkey?


A passkey is a more secure and often easier way to sign in.

Instead of entering a password and then waiting for a text message with a code, users verify their identity using a trusted device.


Depending on how your district configures authentication, that could include:

  • Face ID or Touch ID
  • A computer PIN or biometric login
  • Microsoft Authenticator
  • A physical security key
  • A passkey stored through a supported password manager


For users, the experience can be as simple as:

Sign in → verify with your device → continue.


Why Is Microsoft Making This Change?


The main reason is phishing.


Text-message codes are better than using passwords alone, but attackers have become very good at tricking users into providing those codes.


Passkeys are designed to resist traditional phishing attacks. A fake Microsoft login page can't simply convince someone to provide a six-digit authentication code because there isn't one to hand over.


For schools, this provides an opportunity to improve account security while potentially making the login experience easier for users.


Two Dates to Know


September 1, 2026

Users currently enabled for SMS or voice authentication will become eligible for passkeys.


They may begin seeing Microsoft prompts encouraging them to register a passkey. Initially, users can postpone registration.


This makes communication important. A short message explaining the new prompt ahead of time could prevent a lot of unnecessary help desk calls.


February 1, 2027

Microsoft-provided SMS and voice authentication will be retired.


Users who still rely solely on those methods will need another supported authentication option.


For most districts, the better approach will be to use the coming months to transition users rather than waiting until the deadline.


What Should K–12 IT Teams Do?


The process doesn't have to be complicated.


1. Find Out Who Still Uses SMS or Voice

Start with your current authentication methods.

Determine how many staff members still depend on text messages or phone calls for MFA. Users already using Microsoft Authenticator, Windows Hello, security keys, or another stronger method may require less work.

This gives you an actual scope for the project instead of guessing.


2. Decide Which Authentication Methods You Want to Support

You don't necessarily need the same option for everyone.

For regular staff, a passkey stored on a supported device may provide a good balance between security and convenience.

For administrators and other highly privileged accounts, consider stronger device-bound options such as Microsoft Authenticator passkeys or physical security keys.


3. Pilot Before Rolling It Out

Start with IT and a small group of staff.

Have them register and use passkeys before expanding the rollout.

Pay attention to the questions they ask, because those will probably become your documentation and help desk questions later.


4. Plan for Device Changes and Recovery

Before deployment, answer a few important questions:

  • What happens when someone gets a new phone?
  • What happens if a device is lost?
  • How will IT verify the user's identity during recovery?
  • Should users register more than one authentication method?
  • What backup method will administrators use?

Authentication is only effective if the recovery process is secure too.


5. Communicate Before Microsoft Does

Keep the message simple.

Staff don't need a technical explanation of FIDO2 authentication. They need to know:

  • What is changing
  • Why it is changing
  • What they may see during sign-in
  • What they need to do
  • Where to get help


Something as simple as this may be enough:

Microsoft is changing how we securely verify your identity. Instead of receiving a text message, you may be asked to set up a passkey that allows you to verify your identity using your phone or computer.


Good News for Budget-Conscious Schools


Microsoft says passkey authentication is available across Microsoft Entra ID editions, including Entra ID Free.


That means districts don't necessarily need to purchase premium licensing just to begin using passkeys.


There may still be costs if you choose to provide physical security keys, but the core capability is available without adding another security product.


Closing Thoughts

Passkeys aren't something K–12 IT teams need to panic about, but they are something worth preparing for now.


Start by answering one question:


How many of our users still depend on text messages or voice calls for MFA?

Then:

  1. Identify affected users.
  2. Choose the authentication methods you want to support.
  3. Run a small pilot.
  4. Plan the recovery process.
  5. Communicate clearly before expanding the rollout.


A little preparation now will make the February 2027 transition much easier for both IT and the people we support.


Important Dates


September 1, 2026

Microsoft begins automatically enabling passkeys for eligible SMS and voice users.


February 1, 2027

Microsoft-provided SMS and voice authentication is retired.

Comments

Popular posts from this blog

Why Securing Things “Backwards” Is So Difficult in K–12 IT

Many K–12 districts are facing a difficult reality: after years of convenience-first technology use, the time has come to adopt a more secure, structured approach. Cyber insurance requirements are tightening. State and federal regulations are growing. Threats are increasing. And school systems are expected to modernize their security posture quickly and without disrupting learning. But strengthening security in a district that has operated with wide-open access for years isn’t just a technical challenge; it’s a cultural renovation. Transitioning from “anything goes” to “secured by design” is one of the hardest shifts for schools to make. Not because people don’t care about security, but because securing things backwards means undoing years of habits, expectations, and legacy decisions. Here’s why it’s so difficult , and how districts can make the transition without breaking what’s working. Why Securing Things Backwards Is Hard 1. You’re Taking Away What People Are Used To When classr...

Incident Response for Schools: Why Playbooks Matter

When a cybersecurity incident occurs, such as a phishing email, ransomware outbreak, or accidental exposure of student data, the first few minutes are crucial. Yet, many school districts lack a clear, step-by-step plan for responding. The result? Confusion, delayed decisions, extended downtime, and even compliance failures. That’s why every school should have Incident Response (IR) playbooks : simple, one-page guides that outline who to call, what to do, and how to contain and recover from common incidents. Why Playbooks Are Critical in Schools Clarity Under Pressure: When panic sets in, playbooks provide structure. Staff know exactly what steps to take. Consistency: Every incident is handled the same way, reducing the risk of mistakes. Compliance: For Kansas schools, ITEC 7230a requires incident response planning and documentation. Playbooks help districts meet that standard. Framework Alignment: The NIST Cybersecurity Framework (CSF) 2.0 emphasizes Respond as o...

Vendor and Third-Party Risk Management in K–12: Protecting Student Data Beyond Your Walls

Modern school districts rely on hundreds of third-party applications, ranging from learning management systems and browser extensions to assessment platforms and parent communication tools. Each of these vendors connects to your network, accesses your data, or processes sensitive student information. Every one of them represents potential risk. While internal defenses like patching, MFA, and backups are essential, vendor risk management ensures your district is protected from vulnerabilities that originate outside your network . Why Vendor Risk Management Matters for Schools School technology ecosystems have expanded rapidly over the last decade. What used to be a handful of software systems is now a web of cloud tools, integrations, and data sharing agreements. Without strong oversight, this complexity creates real-world risk: Data Breaches via EdTech Vendors: Many school breaches occur not from internal attacks, but through compromised third-party systems. Privacy Compliance Exp...