Microsoft will start making passkeys the default in Entra ID on September 1. On February 1, 2027, it stops delivering SMS and voice itself.[1] That calendar is honest for people with a laptop and a phone they own. It is a different job on a store floor.
I still run into SMS as a first factor. I still run into phone sign-in. In the retail and consumer-goods tenants I see, information workers are maybe 20 to 35 percent of the headcount. The rest is frontline. Microsoft’s own number for the planet is worse: it says frontline workers are over 80 percent of the global workforce.[4] I am not going to pretend a registration campaign that assumes a personal iPhone is a plan.
I do not have the answer. I have the questions I keep walking into, and what Entra actually ships.
Two different phone problems
SMS as MFA and SMS as sign-in are not the same switch. After February 1, 2027, Microsoft-provided telecom for SMS and voice authentication ends. If you still need that channel you buy it from a Security Store partner, and users who stay on SMS or voice for MFA get forced through a passkey prompt with no opt-out.[1]
SMS sign-in is a first-factor method Microsoft still documents for frontline: phone number plus a one-time code, no username, no password. They tell you not to give it to information workers, and they now point those same tenants at QR code authentication instead.[7]
If your floor still lives on SMS sign-in, February is not “turn on passkeys.” February is “who is paying for the text, and what is the other door.”
What Microsoft actually built for the floor
QR code authentication is not a passkey, and it is not “scan this with Authenticator on your own phone.” It is a printed code on a badge plus an 8 to 20 digit PIN. Single factor. Something you know, bound to that code. iOS and Android only. No desktop. No self-service PIN reset. No bulk provisioning in the current release. First sign-in after you enable it still needs some other method, or the user gets “Incorrect QR code."[2]
Microsoft is blunt: this is for frontline, not IW. Do not turn it on for the whole tenant. Pair it with Conditional Access, compliant or shared devices, and a tighter method when they leave the store network.[2][6]
Shared device mode is the other half. One sign-in, one sign-out, apps that actually wipe the last associate. If MFA is not feasible they tell you to lean on device compliance and trusted networks instead of pretending the PIN is phishing-resistant.[6]
Authenticator Lite lives in Outlook mobile. Push or TOTP without installing the full app. It is not eligible when Outlook is in shared device mode. Users who already have Authenticator on that phone do not get Lite. Registration is inside Outlook, not My Sign-Ins.[3] So the BYOD / MAM / “Authenticator Lite on a personal phone” path and the shared-cradle path are different designs. You do not get both for free.
Passkeys themselves split. Authenticator passkeys are device-bound: they do not leave the phone they were created on.[8] Synced passkeys live in iCloud Keychain or Google Password Manager. Entra will take both. If you enforce attestation, synced ones drop out.[9] Device-bound is the closer match to “this is this person’s factor.” It also means a lost phone is a recovery problem, not a sync problem.
FIDO2 keys exist. I have not seen a retail floor that wants to buy and replace them at frontline scale. Microsoft says a printed QR is cheaper for temporary labor.[2] That is accounting, not a security argument.
The questions I will not fake an answer to
Does the union contract let you put work identity on a personal phone. Microsoft’s own device guidance already flags union rules, regulation, and workers who do not have a reliable phone.[5] I am not a labor lawyer. I am the person who has to ask HR before I write the Conditional Access policy.
Who pays if the answer is BYOD. Stipend, reimbursement, company phone, or shared cradle. Dedicated phones are the clean identity story. Microsoft calls them uncommon on the frontline because they cost.[5]
What happens at 2 a.m. when the badge QR is in a jacket at home. Temporary QR codes exist, up to 12 hours.[2] That is a manager workflow in My Staff, not a helpdesk script I have tested at volume.
Phone sign-in on Authenticator is still out there. It is not a passkey. It is still a phone. If we are stumbling on it in 2026, we should count it before we celebrate the SMS sunset.
I wrote last week that password spray is still the boring hole while we argue about agents.[10] A floor that only has SMS or a PIN on a badge is that hole with a lanyard.
Monday morning
I would not flip passkeys on for everyone and call it done. I would split the directory the way the building is already split.
- Export who still has SMS, voice, or phone sign-in. Two lists: IW and FLW. Do not treat them as one registration campaign.[1]
- Pick the device model first. Shared cradle, BYOD with app protection, or a real company phone. Authenticator Lite only makes sense on the personal-phone path, and not on shared Outlook.[3][5]
- Pilot QR plus PIN on one store’s shared devices, scoped to a group, with Conditional Access that gets stricter off the floor. Leave IW on passkeys.[2][6]
- Decide recovery before you disable SMS. Temporary Access Pass for bootstrap. Temporary QR for a forgotten badge. A named person who can issue both on a Saturday.
- Walk the union and stipend question to HR in writing. I will not invent that policy in a blog post.
Entra as a bouncer still works.[11] The bouncer just asked a cashier for a passkey, and she is holding a shared handheld that three other people used this shift.
Sources
[1] https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id — Passkeys default / SMS voice retirement [2] https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-qr-code — QR code authentication method [3] https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-mfa-authenticator-lite — Authenticator Lite Outlook [4] https://learn.microsoft.com/en-us/entra/fundamentals/frontline-worker-management — Frontline worker management [5] https://learn.microsoft.com/en-us/microsoft-365/frontline/flw-devices?view=o365-worldwide — FLW device management [6] https://learn.microsoft.com/en-us/microsoft-365/frontline/flw-shared-devices?view=o365-worldwide — FLW shared devices [7] https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-sms-signin — SMS-based sign-in [8] https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-authenticator-app — Authenticator device-bound passkeys [9] https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2 — Passkeys FIDO2 types [10] https://blog.darkpixeltech.com/posts/looking-back-the-security-agent-learned-to-talk — DPT lookback agents [11] https://blog.darkpixeltech.com/posts/entra-digital-bouncer — DPT Entra bouncer