Microsoft has begun moving users away from text message and phone call verification for signing in to Microsoft 365, encouraging them to use passkeys instead. The change started on 1 September 2026. From February 2027, Microsoft provided text and voice verification will be retired for most users, with a later deadline for some administrator and external accounts.

It is a sensible change. A six digit code can be read out to the wrong person or entered into a convincing fake sign in page. Passkeys are designed to make that kind of phishing much harder.

The problem is that attackers know the change is happening too.

In September, Microsoft reported active attacks in which criminals posed as IT support and used passkey or sign in updates as the reason for contacting employees. The aim was not to break the passkey itself, but to persuade the user to take an action that gave the attacker access to their account.

Neither an authentication change nor an IT support scam is unusual on its own. The risk comes from the two happening at the same time.

Why smaller businesses feel this more

A larger company may have an IT team whose job is to manage a change like this and explain it to staff. In a smaller business, that responsibility often sits with the owner, or with whoever looks after IT alongside their main job.

If nobody has explained what the genuine change will look like, an unexpected message saying your account needs updating has nothing obvious to be measured against. It may simply look like the Microsoft change everyone was expecting, and that is where the attacker gains credibility.

What a genuine request should look like

Microsoft passkey prompts are part of the normal Microsoft sign in process. Staff should be cautious about an unsolicited phone call, Teams message or email telling them to take urgent action.

Warning signs include someone asking you to install remote access software, read out a verification code, approve a sign in you did not start, or follow a link while they stay on the phone.

If in doubt, stop and check independently. Call your IT provider on a number you already know, speak to the person who normally looks after IT, or open Microsoft 365 through your usual route rather than the link in the message.

Three things to sort this month

  1. Decide who will communicate sign in changes. Make it clear who will contact staff about changes to Microsoft 365, and how they will do it.
  2. Agree how unexpected IT requests are checked. Nobody should grant remote access, read out a code or approve a sign in simply because someone claiming to be IT asked them to. Urgent requests should be verified independently.
  3. Find out who is still using text or phone verification. If you have an IT provider, ask them. If you manage Microsoft 365 yourselves, check which users are affected and plan the move before the deadline forces it.

The change is not the problem

None of this is an argument against the move to passkeys. It is a worthwhile security improvement. The risk sits in the period where people know something is changing but are not yet sure what the new normal looks like.

For businesses without a dedicated cyber security team, that is the lesson worth keeping. Good security is not only about choosing stronger technology. It is also about making sure people know what to expect, who to trust, and what to do when something feels wrong.

Sources: Microsoft Learn on passkeys by default and the retirement of Microsoft provided SMS and voice authentication, and Microsoft Security Research on passkey themed social engineering, 9 September 2026.

Not sure how the Microsoft sign in changes affect your organisation. Talk to an expert.