If your school district uses Microsoft 365 and Microsoft Entra, an important authentication change is coming.
Microsoft is moving users away from SMS text messages and voice calls for multi-factor authentication and toward passkeys.
Beginning September 1, 2026, Microsoft will automatically enable passkeys for users currently enabled for SMS or voice authentication and may begin prompting them to register one.
Then, on February 1, 2027, Microsoft-provided SMS and voice authentication will be retired.
For K–12 IT teams, now is a good time to understand the change and start preparing users.
What Is a Passkey?
A passkey is a more secure and often easier way to sign in.
Instead of entering a password and then waiting for a text message with a code, users verify their identity using a trusted device.
Depending on how your district configures authentication, that could include:
- Face ID or Touch ID
- A computer PIN or biometric login
- Microsoft Authenticator
- A physical security key
- A passkey stored through a supported password manager
For users, the experience can be as simple as:
Sign in → verify with your device → continue.
Why Is Microsoft Making This Change?
The main reason is phishing.
Text-message codes are better than using passwords alone, but attackers have become very good at tricking users into providing those codes.
Passkeys are designed to resist traditional phishing attacks. A fake Microsoft login page can't simply convince someone to provide a six-digit authentication code because there isn't one to hand over.
For schools, this provides an opportunity to improve account security while potentially making the login experience easier for users.
Two Dates to Know
September 1, 2026
Users currently enabled for SMS or voice authentication will become eligible for passkeys.
They may begin seeing Microsoft prompts encouraging them to register a passkey. Initially, users can postpone registration.
This makes communication important. A short message explaining the new prompt ahead of time could prevent a lot of unnecessary help desk calls.
February 1, 2027
Microsoft-provided SMS and voice authentication will be retired.
Users who still rely solely on those methods will need another supported authentication option.
For most districts, the better approach will be to use the coming months to transition users rather than waiting until the deadline.
What Should K–12 IT Teams Do?
The process doesn't have to be complicated.
1. Find Out Who Still Uses SMS or Voice
Start with your current authentication methods.
Determine how many staff members still depend on text messages or phone calls for MFA. Users already using Microsoft Authenticator, Windows Hello, security keys, or another stronger method may require less work.
This gives you an actual scope for the project instead of guessing.
2. Decide Which Authentication Methods You Want to Support
You don't necessarily need the same option for everyone.
For regular staff, a passkey stored on a supported device may provide a good balance between security and convenience.
For administrators and other highly privileged accounts, consider stronger device-bound options such as Microsoft Authenticator passkeys or physical security keys.
3. Pilot Before Rolling It Out
Start with IT and a small group of staff.
Have them register and use passkeys before expanding the rollout.
Pay attention to the questions they ask, because those will probably become your documentation and help desk questions later.
4. Plan for Device Changes and Recovery
Before deployment, answer a few important questions:
- What happens when someone gets a new phone?
- What happens if a device is lost?
- How will IT verify the user's identity during recovery?
- Should users register more than one authentication method?
- What backup method will administrators use?
Authentication is only effective if the recovery process is secure too.
5. Communicate Before Microsoft Does
Keep the message simple.
Staff don't need a technical explanation of FIDO2 authentication. They need to know:
- What is changing
- Why it is changing
- What they may see during sign-in
- What they need to do
- Where to get help
Something as simple as this may be enough:
Microsoft is changing how we securely verify your identity. Instead of receiving a text message, you may be asked to set up a passkey that allows you to verify your identity using your phone or computer.
Good News for Budget-Conscious Schools
Microsoft says passkey authentication is available across Microsoft Entra ID editions, including Entra ID Free.
That means districts don't necessarily need to purchase premium licensing just to begin using passkeys.
There may still be costs if you choose to provide physical security keys, but the core capability is available without adding another security product.
Closing Thoughts
Passkeys aren't something K–12 IT teams need to panic about, but they are something worth preparing for now.
Start by answering one question:
How many of our users still depend on text messages or voice calls for MFA?
Then:
- Identify affected users.
- Choose the authentication methods you want to support.
- Run a small pilot.
- Plan the recovery process.
- Communicate clearly before expanding the rollout.
A little preparation now will make the February 2027 transition much easier for both IT and the people we support.
Important Dates
September 1, 2026
Microsoft begins automatically enabling passkeys for eligible SMS and voice users.
February 1, 2027
Microsoft-provided SMS and voice authentication is retired.
Comments
Post a Comment