Passkeys Are Becoming the Default in Microsoft Entra ID – Why Charities Should Start Preparing Now

If you've ever had to reset a forgotten password on a Monday morning, chase a user for an MFA code or deal with an account compromise caused by a convincing phishing email, you'll understand why identity security remains one of the biggest challenges facing IT teams today.
For non-profit organisations, the challenge is often even greater. Small IT teams are supporting large numbers of users, budgets are under pressure and cybercriminals don't discriminate based on organisation size or sector.
That's why Microsoft's recent announcement around Microsoft Entra ID is an important one.
From 1 September 2026, Microsoft will begin making passkeys the default authentication experience in Microsoft Entra ID, automatically encouraging users who currently rely on SMS or voice authentication to register and use passkeys instead. Then, from 1 February 2027, Microsoft will retire its native SMS and voice authentication services within Entra ID altogether.
Why is Microsoft making this change?
Quite simply, because the threat landscape has changed.
SMS and voice-based authentication were a huge step forward when multifactor authentication first became mainstream. They helped move organisations away from relying solely on passwords and undoubtedly prevented countless compromises.
However, attackers have adapted.
Today, phishing attacks are more sophisticated, more convincing and increasingly powered by AI. Techniques such as SMS interception, SIM swapping and MFA fatigue attacks are becoming more common and easier for threat actors to execute at scale. Once an attacker gains access to an identity, modern attacks can move quickly through an environment, especially when AI is used to automate discovery and privilege escalation.
The reality is that passwords plus SMS codes are no longer providing the level of protection organisations need.
What exactly is a passkey?
Why this matters for non-profits
Many charities have spent years striking a balance between security and usability.
A volunteer accessing organisational data remotely isn't thinking about public-key cryptography. They just want access to the tools they need.
Passkeys help remove friction while simultaneously improving security.
Charities often rely on trustees, volunteers and part-time staff who may not be deeply technical. Simplifying secure sign-in can reduce support overhead while strengthening protection of sensitive data.
What should organisations do now?
The good news is there's no need to panic.
Microsoft has provided a clear transition timeline and the majority of organisations can move to passkeys without any additional licensing cost.
We would recommend starting with four simple steps:
1. Review your current authentication methods
2. Begin planning your passkey rollout
3. Prepare your user communications
4. Run a pilot
The bigger picture
This announcement isn't really about replacing SMS.
It's about recognising that identity has become the primary security perimeter.
As organisations embrace AI, cloud services and increasingly flexible working models, protecting user identities is more important than ever.
Microsoft is effectively signalling that phishing-resistant authentication should now be considered the standard, not the exception.
For most non-profits, the question is no longer if they should move to passkeys, but when.
If you're unsure how prepared your organisation is for the shift to passkeys, Smartdesc is here to help you assess your current authentication methods, identify potential challenges and provide guidance on planning a secure and user-friendly transition to phishing-resistant authentication. Speak to our team today.