Microsoft 365 Passkeys for Small Business: The Sign-In Change That Started This Month and the Deadline With No Opt-Out
Microsoft is retiring SMS and voice sign-in codes by February 2027. What passkeys mean for your small business, and how to roll them out without lockouts.
One of your staff gets a text message. It says their Microsoft 365 account needs a passkey set up, and they have until the end of the week or they will lose access to their email. There is a link. It looks like a Microsoft sign-in page. They are mid-job, the message sounds official, and honestly, they have been getting prompts from Microsoft about exactly this for the past fortnight.
So which one is it? Microsoft, or somebody pretending to be Microsoft?
That question is now a live problem for every small business running Microsoft 365, because Microsoft 365 passkeys for small business accounts are being switched on by default right now, and both things are happening at the same time. Microsoft has started a real, tenant-wide change to how people sign in. Criminals noticed the same calendar you did, and they are using it as cover. This is one of those rare moments where a boring admin change and an active attack campaign land in the same inbox, in the same week, wearing the same clothes.
Microsoft 365 passkeys for small business: what changed on 1 September
From 1 September 2026, passkeys became the default sign-in method in Microsoft Entra ID, which is the identity system sitting underneath Microsoft 365. Microsoft's own documentation is blunt about what that means in practice. Any user currently enabled for SMS or voice codes gets automatically enabled for passkeys, and they will be nudged to register one the next time they complete a multi-factor prompt.
If you have never touched an Entra setting in your life, nothing was asked of you. That is rather the point. Microsoft turned it on across tenants, and your team started seeing the prompts.
A quick plain-English version of what a passkey actually is, because the word gets thrown around as if everyone already knows. A passkey is a sign-in credential stored on a device you already own, usually your phone or laptop, unlocked by your fingerprint, your face, or your device PIN. There is no code to type and nothing to read out loud. The secret never leaves your device, which is why it cannot be repeated to a stranger on the phone or typed into a fake sign-in page. That last part is the whole reason Microsoft is doing this. Texted codes are exactly what real-time phishing kits and IT-impersonation calls are built to capture, which is why MFA on its own has stopped being enough.
There are two more dates in the rollout worth writing down. Microsoft said information on customer-managed telecoms providers would be available from 18 September 2026, and that businesses could begin selecting and configuring those providers through the Microsoft Security Store from 30 October 2026. Those exist for the small number of businesses that genuinely need SMS or voice to keep working. Most businesses with under twenty staff will never need to look at either.
The date that really matters is 1 February 2027
The September change is a nudge. February is a wall.
On 1 February 2027, Microsoft fully retires its own SMS and voice delivery in Entra ID. After that date, any user whose only available sign-in method is a text message or a phone call gets a blocking prompt. They must register a passkey before they can continue signing in. Microsoft's guidance states there is no opt out from the February behaviour and that it will be enforced for all tenants.
There is a temporary opt out, but read it carefully before you feel relieved. It only covers the window between 1 September 2026 and 1 February 2027, it has to be set through a Graph API call rather than a settings page, and it delays the passkey enablement and the registration prompts. It does not exempt anyone from the February enforcement. Deferring it just moves the same work to a worse moment.
Here is the part I would want a business owner to sit with. If you have a bookkeeper who only comes in on Tuesdays, a casual who works school hours, or a director who checks email on an old iPad, those are the people who will hit the February wall, and they will hit it while you are not in the room. A person who cannot sign in is a person who calls whoever they think can fix it. In a small business, that is usually you, and usually at a bad time.
Four and a half months is plenty of runway. It is only plenty if somebody starts.
Why attackers picked this exact moment
On 9 September 2026, Microsoft published research on a campaign built entirely around this transition. The technique is not clever in a technical sense, and that is what makes it work.
Attackers ring or text staff directly, claiming to be the IT help desk, and tell them their passkey or MFA setup needs updating urgently or they will lose access to company systems. The victim gets sent to a counterfeit Microsoft sign-in page. Microsoft noted the domains often combine the target's own company name with passkey wording, so an employee sees something like their company name sitting in front of secure-passkey followed by a domain, which reads as legitimate at a glance. Credentials get captured live, the attacker relays the multi-factor prompt in real time, and then comes the move that matters: they register their own authentication method on the account. A new authenticator app, a new phone number, or a software token they control.
From that point the password is irrelevant. They have their own key to the front door.
Microsoft attributed the activity to groups it tracks as Storm-3121 and Storm-3032, and reported the pattern afterwards is consistent. The attackers use the Microsoft Graph API to enumerate users, groups, roles and file locations, then pull documents from SharePoint and OneDrive and collect mailbox contents. BleepingComputer's coverage on 11 September 2026 added a detail that says a lot about the maturity of this: the activity has been running since May 2026, and the attackers deliberately keep downloads under roughly 1,000 files per hour so the volume does not trip alarms. Theft runs from a few hours to several days.
Worth adding one number for context. In its July 2026 post announcing the passkey default, Microsoft cited its Digital Defense Report finding that AI-assisted phishing campaigns reach click-through rates as high as 54%, against roughly 12% for traditional campaigns. The lures are not clumsy anymore. Assuming your team will spot a fake because it looks off is no longer a plan.
The bit small businesses always miss: who owns recovery
Most of the advice written about this change is aimed at businesses with an IT department. Conditional access policies, device compliance rules, blocking device code flows. All good, all real, and mostly written for someone who does not exist at a ten-person company.
The gap at small businesses is simpler and more human. Nobody owns the question of what happens when somebody cannot sign in.
Think about what a passkey migration actually touches. Which staff member has which sign-in method right now. Which accounts still have only a mobile number attached. Which phone that number belongs to, including the ones that left with an ex-employee. Who has administrator rights and could approve a change. What the recovery path is when someone loses the phone their passkey lives on, which will happen to someone eventually.
In most businesses under twenty people, none of that is written down anywhere. It lives in memory, and usually in one person's memory. That is exactly the vacuum this attack campaign feeds on. A staff member who has no idea who to check with, when a message arrives claiming to be IT, will make their own call. The fix is unglamorous. You write it down, and you tell people who to ask.
A rollout plan for a business with no IT person
This is not a big project. It is a couple of hours spread over a few weeks, and it removes a February emergency entirely.
Start with a list of who has what. Before changing anything, get a picture of your accounts and what each one can currently use to sign in. You want names, accounts, current sign-in methods, whether the person has a work phone or a personal one, and who has administrator rights. A spreadsheet is fine for a first pass. The goal is that this stops living in your head.
Do your own account first. Register a passkey on your own phone or laptop and sign in with it a few times before you ask anyone else to. You will find the two or three friction points specific to your setup, and you will be able to answer questions from experience rather than from a Microsoft help page. It also means the person with the most access is the first one protected.
Register a second method for every admin. The single worst outcome here is an owner locked out of their own tenant with no way back in. Anyone with administrator rights should have at least two working ways to sign in, on two separate devices. Do this before February, not after something goes wrong.
Roll out to the team one person at a time. Five minutes each, in person or on a call, ideally while they have their phone in hand. Doing this live is what stops the "I will get to it later" pile that turns into a February queue. Tick them off the list as you go, and add the passkey step to your onboarding checklist so the next hire starts on the right method from day one.
Deal with the awkward accounts deliberately. Shared mailboxes, the reception login, an account tied to a phone number nobody can place, the dormant login nobody has used since spring, the director who refuses to install anything. These are the ones that will bite. Handle each one on purpose now, rather than discovering them at the blocking prompt.
Agree one rule about IT messages. Tell your team plainly: nobody from IT will ever ring or text asking you to set up a passkey or approve a prompt. If a message asks for that, they check with you first, through a channel they already use. This one sentence defeats the entire campaign Microsoft described, and it costs nothing.
Watch for new sign-in methods appearing. A new authentication method added to an account that the owner did not add is the clearest signal of a compromise in this campaign. If nobody is looking at that, it goes unnoticed for days.
What to tell your team, in one short message
You do not need a policy document. You need one message people actually read.
Something close to this works: Microsoft is changing how we sign in. Over the next few weeks you will be asked to set up a passkey, which uses your fingerprint, face or device PIN instead of a texted code. This is real and we are doing it. Nobody from IT will ever ring or text you about it. If you get a call or message about passkeys, hang up or ignore it and check with me first. Text codes stop working in February, so please do not put this off.
Short, specific, and it gives people a rule they can follow when they are busy and someone sounds authoritative on the phone.
Where Vera fits
Everything above depends on one thing: knowing what you have. Who your accounts belong to, which devices they sit on, who has administrator rights, which phone numbers are still attached to people who left in 2024. The migration is easy. Finding out what you are migrating is the part that stalls, because the information is scattered across a mailbox, a phone, somebody's memory and an old spreadsheet.
Vera gives small businesses the IT overview, simplified. Your hardware, your software and licences, your team directory and your security signals in one dashboard, so the answer to "who has what" is something you look up rather than something you reconstruct. When a deadline like February lands, you start from a list instead of starting from scratch.
The Microsoft 365 passkey change is genuinely good news for small business security, and unlike the July price increase, this one costs nothing but an afternoon. Phishing-resistant sign-in is a real improvement for small businesses, who get targeted precisely because they are assumed to be soft. But a security upgrade handed to a business with no record of its own accounts turns into a lockout risk and an opening for whoever calls first.
You have until February. If you do not currently have a clear picture of your accounts, sign-in methods and devices, that is the thing to fix first, and it is the gap Vera was built to close. Your IT, simplified, starts with being able to see it.