Microsoft Is Retiring SMS Codes: What Passkeys-by-Default
Information Technology Solutions for Dentists and the Dental Industry. Serving the GTA and Southern Ontario.
Dental I/T, Dental Information Technology, Network Security, Toronto, GTA, Dental, Network, I/T, Information Technology, Computer, Data, Abeldent, Dentrix, LiveDDM, Patterson Dental, Henry Schein, K-Dental, Sinclair Dental, Schick CDR, Dexis, Carestream, Carestream Dental, Digital Radiography, X-ray, Dental X-ray, Dental Software Support, Software
17411
bp-nouveau,wp-singular,post-template-default,single,single-post,postid-17411,single-format-standard,wp-theme-bridge,wp-child-theme-bridge-child,theme-bridge,woocommerce-no-js,ajax_fade,page_not_loaded,,columns-4,qode-child-theme-ver-1.0.0,qode-theme-ver-10.0,wpb-js-composer js-comp-ver-4.12,vc_responsive

Microsoft Is Retiring SMS Codes: What Passkeys-by-Default Means for Your Dental Practice

A passkey icon securing a dental office computer, replacing password entry

Microsoft Is Retiring SMS Codes: What Passkeys-by-Default Means for Your Dental Practice

If your practice signs in to Microsoft 365 with a password and a code texted to a phone, that workflow is on the clock. Microsoft has confirmed it is making passkeys the default authentication method across Microsoft Entra ID, and it is retiring its own SMS and voice verification on February 1, 2027. For a dental office, this is not a nuisance setting change buried in the admin center — it is a security upgrade with a deadline, and getting ahead of it is far easier than being surprised by it at the front desk on a Monday morning.

A passkey icon securing a dental office computer, replacing password entry
Passkeys replace the password-and-code ritual with a single phishing-resistant sign-in tied to your device.

What Microsoft actually announced

Two things are happening on a staggered timeline. Starting September 1, 2026, passkeys become the default sign-in experience in Entra ID: any user currently relying on SMS or voice will be automatically enabled for passkeys and nudged to register one at their next multi-factor prompt. Then, on February 1, 2027, Microsoft retires Microsoft-provided SMS and voice delivery entirely — those codes will simply no longer be offered as native Entra methods.

One important clarification for practices that use text or call codes for patient-facing systems: this change is about Microsoft’s own telecom delivery for account sign-in. If your organization has configured its own external telecom provider for SMS or voice, that remains unaffected. The retirement targets the free, Microsoft-delivered codes that most small offices quietly depend on for staff logins.

Why passkeys beat a texted code

A passkey is a cryptographic credential that lives on a device you already trust — a phone, a laptop, or a hardware security key — and is unlocked with a fingerprint, face scan, or PIN. Crucially, it never travels across the network as a secret a criminal can intercept. That single design difference closes the three most common ways staff accounts get compromised.

A texted code can be phished — a fake login page asks for it and relays it in real time. It can be replayed if intercepted. And the phone number itself can be hijacked through a SIM-swap, where an attacker convinces a carrier to move the number to their own SIM. Passkeys are immune to all three: there is no code to type into a fake page, nothing reusable to intercept, and no phone number to steal.

A timeline showing SMS and voice codes fading out as passkeys become the default
The transition has two dates that matter: default in September 2026, retirement in February 2027.

What this means for a dental practice specifically

Dental offices are a favored target precisely because they hold protected health information and often run lean on IT. A single compromised Microsoft 365 login can expose email, shared patient correspondence, imaging portals, and cloud backups — the kind of breach that triggers PHIPA and HIPAA reporting obligations and erodes patient trust overnight. The most common entry point is not a sophisticated exploit; it is a staff member typing a real code into a convincing fake page.

Passkeys remove that failure mode. When the front desk, hygienists, and clinical staff sign in with a passkey, there is no code for a phishing kit to harvest. For a practice, that is arguably the highest-leverage security improvement available today, and Microsoft is now doing the heavy lifting of making it the default rather than an obscure opt-in.

A phishing hook failing to capture a passkey-protected login, next to a broken SIM card
A passkey cannot be phished, replayed, or stolen by a SIM-swap the way a texted code can.

How to set up a passkey before the deadline

You do not need to wait for the automatic rollout. Each staff member can register a passkey in about a minute:

  • Sign in to the account security page at aka.ms/mysecurityinfo.
  • Choose to add a sign-in method and select passkey (or “security key / passkey”).
  • Follow the prompt to create it on the phone or laptop, confirming with a fingerprint, face scan, or device PIN.
  • Register a second passkey on a backup device so no one is locked out if a phone is lost.

Administrators should also enable the passkey (FIDO2) method in the Entra admin center if it is not already on, and consider requiring phishing-resistant authentication for accounts with access to sensitive data. Doing this now, on your schedule, is far calmer than doing it reactively when a staff member gets a blocking prompt at 8:55 a.m. with a full waiting room.

A dental team registering a passkey on their Microsoft 365 account
Registering a passkey takes a minute per person and pays off every single sign-in afterward.

A practical rollout plan for a small office

Treat this as a short project, not a fire drill. A sensible sequence for a practice of any size:

  • This month: confirm passkeys are enabled in your tenant and register one for the practice’s most privileged accounts first.
  • Before September: have every staff member enroll a passkey plus a backup, and document who is enrolled.
  • By year end: phase out SMS as a fallback for anyone who has a working passkey, so the February 2027 retirement is a non-event.

The goal is simple: when Microsoft flips the switch, your team has already been signing in with passkeys for months and nobody notices the change.

A layered passkey shield protecting a dental practice's devices and patient records
Phishing-resistant sign-in is the single highest-leverage upgrade a practice can make to protect patient data.

Where Compudent fits in

If you are not sure whether passkeys are enabled in your Microsoft 365 tenant, which accounts still rely on SMS, or how to roll this out without disrupting a busy schedule, that is exactly the kind of quiet, deadline-driven IT work we handle for practices every day. Compudent Systems can assess your current authentication setup, enable phishing-resistant sign-in across your team, and make sure no one is left dependent on a method that is about to disappear.

Passwords and texted codes had a good run. Passkeys are simpler for your staff and dramatically harder for attackers — and now they are the default. Contact Compudent Systems to review your practice’s sign-in security before the 2027 deadline arrives.


Sources & further reading:

Related Reading



Contact us today - How can we help you?