The significant changes coming to Microsoft 365 and what you need to know
Microsoft has announced a significant change to how users sign in to Microsoft 365.
If your organisation uses Microsoft 365, these changes will affect how users sign in and what authentication methods you’ll need going forward.
Here’s what’s changing, and what you and your team need to know.
What’s changing
From 1st September 2026, Microsoft will make passkeys the default authentication method across Microsoft 365. Users who currently rely on text message or phone call verification will begin seeing prompts to register a passkey when they sign in.
Then, from 1st February 2027, Microsoft will retire its SMS and voice authentication entirely; at that point, users with no stronger method registered will be required to set up a passkey before they can sign in.
Why is Microsoft doing this?
Multi-factor authentication (MFA) remains one of the most effective defences against account compromise, but not all methods offer the same protection.
Attackers have become adept at bypassing phone-based verification through phishing and SIM-swapping, which is why Microsoft has long classed SMS and voice as legacy methods.
Passkeys are phishing-resistant by design, and the National Cyber Security Centre has endorsed them as the future of secure sign-in.
According to the NCSC, not only do passkeys offer greater resilience but they also found that signing in with a passkey can also be up to eight times faster than using a username, password and MFA code.
What users will notice
From September, anyone still using text or voice verification will start receiving prompts to register a passkey. These can initially be skipped, but they will appear regularly.
If you work in an internal IT team or if you’re responsible for M365 at your workplace, you’ll want to flag this now so that the prompts don’t come as a surprise and so your team knows they’re legitimate – and not a phishing – attempt.
Not happy with the support your current MSP are giving?
What Arc is doing
We’re proactively reviewing our customers’ Microsoft 365 environments ahead of these deadlines. We’ll be in touch to walk through where their organisations stand, identify any users still relying on legacy methods and discuss the options available to them, including how different Microsoft licence levels affect what’s possible.
Keeping customers secure beyond this change
Changes like this are becoming a regular feature of Microsoft 365, and keeping a tenant aligned with security best practice is an increasingly demanding task. To address this, we’ve also developed a set of carefully constructed security baselines for Microsoft 365, backed by continuous monitoring.
When a setting drifts from best practice – whether through an accidental change or a Microsoft update – we’re alerted and can review and restore the correct configuration proactively.
The MFA changes above are a perfect example: under our managed baseline, secure authentication policies are deployed to best practice and monitored continuously, so your protection doesn’t quietly erode over time.
By planning ahead and adopting modern authentication now, you’ll reduce risk, minimise disruption for current users and be prepared for future changes.
If you’d like to discuss what these changes mean for your Microsoft 365 environment, our team is always happy to help.
