Passkeys are coming. Is your team ready?

If your team is still logging into Microsoft 365 with a password and a text code, that's about to change. Microsoft is phasing out SMS verification codes, and the clock is ticking. Here's what you need to know (and what to do about it).
What's actually changing with Microsoft sign-ins?
Microsoft is retiring verification codes sent by text and phone call. Two dates matter:
1 September 2026: Anyone still using text or voice codes gets automatically enabled for passkeys and will see a prompt to register one. Nobody gets locked out on this date - they can choose ‘Not now’ and keep working.
1 February 2027: Text and voice codes stop working entirely. If a text code is someone's only way to verify a sign-in, Microsoft will block access until they register a passkey. There's no opt-out on that one.
So, now is the time to use that window.
What exactly is a passkey?
A passkey replaces your password with something already on your device -a fingerprint, a face scan, or a PIN. Nothing to remember, nothing to type, and nothing a scammer can talk out of you.
As Yorb Digital Technology Manager Troy Gerrie puts it: "A passkey is like a modern reincarnation of a smart card, but virtual. Instead of entering a password and then a second factor, it's two factors rolled into one. When I log into Microsoft 365 now, it just pops up and asks for my face. That's it."
Passkeys can live on your phone, your laptop, Microsoft Authenticator, a physical security key like a YubiKey, or a password manager. Microsoft says passkeys are also phishing-resistant - unlike passwords or text codes, a passkey is tied to the specific website it was created for, so it can't be handed over to a fake site even if someone clicks a dodgy link.
Text codes, by comparison, can be phished, intercepted, or captured after a criminal convinces your telco to swap a SIM. Passkeys sidestep all of that.
Why your rollout depends on your team's devices
Yorb went through this process firsthand when rolling out passkeys to their team - and device compatibility turned out to be the biggest hurdle.
"Older Android devices may not necessarily support passkeys - that's been a little bit of a challenge," says Troy. "But nothing major. Out of all our staff-owned phones, only two were incompatible."
Work laptops and desktops were a non-issue. The friction, where it existed, was with personal mobile devices.
Yorb Cyber Security Analyst Jane Moya handled the hands-on setup: "It was easy for us because we're mostly engineers and they pretty much followed their nose. There were only a couple of people who needed help, and even then it was just two or three minutes."
The key takeaway is that supported devices generally include anything running Windows 10+, iOS 16+, Android 9+, or macOS Ventura and newer. If your team's phones are a few years old, it's worth checking before you assume the rollout will be seamless.
Getting passkeys onto your security roadmap: a checklist
If you're not sure where to start, use this as your starting point:
Identify who's still on SMS codes. These are the people who need to move first.
Audit your team's devices. Flag any phones or tablets that may not support passkeys.
Check whether Microsoft Authenticator is in use. If so, those users are largely sorted - Authenticator stays fully supported.
Get leadership buy-in before rolling anything out. Troy is clear on this: "Don't leave it up to your IT team to sell it to people. It needs to come from top management." When security changes are framed as a burden by senior staff, that attitude flows downward.
Have hands-on support ready for non-technical staff. Jane's advice: "Just having that support available is needed - hands-on help for people who find it foreign or difficult."
Set a deadline ahead of Microsoft's. Don't wait until February 2027. Plan the transition on your schedule, not Microsoft's.
Stop configuring SMS-based verification on new accounts. Make passkeys the default from here on.
If you're concerned about your team's AI data security during any of these changes, it's worth reading this post on keeping your data safe as well.
What Yorb learned from going first
Yorb recently implemented passkeys internally - partly to understand the experience before recommending it to clients, and partly because they are working through their ISO 27001 certification.
The verdict is that the transition was smoother than expected. Jane notes that day-to-day, the experience feels largely unchanged: "We already logged in with a PIN number, and it's no different." The security improvement is real, but the disruption is minimal.
Troy sums it up plainly: "The login experience with passkeys is more convenient. The passkey is already on your device. You just activate it."
Don't wait for the prompt
The September date has come and gone, and if your team wasn’t prepared, the ‘Not now’ button will only hold things off until February. Getting ahead of this now means the transition happens on your terms - with time to check devices, communicate the change, and sort out anyone who needs a hand.
At Yorb. we're already working through client environments to identify anyone still on text or voice codes, and we won't configure SMS-based verification on any new accounts going forward.
If you want help reviewing your current setup and mapping out the move to passkeys, reach out to the Yorb team today.



