July 23, 2026 Microsoft Is Retiring SMS Codes: What Passkeys-by-Default Means for Your Dental Practice
If your practice signs in to Microsoft 365 with a password and a code texted to a phone, that workflow is on the clock. Microsoft has confirmed it is making passkeys the default authentication method across Microsoft Entra ID, and it is retiring its own SMS and voice verification on February 1, 2027. For a dental office, this is not a nuisance setting change buried in the admin center — it is a security upgrade with a deadline, and getting ahead of it is far easier than being surprised by it at the front desk on a Monday morning.

What Microsoft actually announced
Two things are happening on a staggered timeline. Starting September 1, 2026, passkeys become the default sign-in experience in Entra ID: any user currently relying on SMS or voice will be automatically enabled for passkeys and nudged to register one at their next multi-factor prompt. Then, on February 1, 2027, Microsoft retires Microsoft-provided SMS and voice delivery entirely — those codes will simply no longer be offered as native Entra methods.
One important clarification for practices that use text or call codes for patient-facing systems: this change is about Microsoft’s own telecom delivery for account sign-in. If your organization has configured its own external telecom provider for SMS or voice, that remains unaffected. The retirement targets the free, Microsoft-delivered codes that most small offices quietly depend on for staff logins.
Why passkeys beat a texted code
A passkey is a cryptographic credential that lives on a device you already trust — a phone, a laptop, or a hardware security key — and is unlocked with a fingerprint, face scan, or PIN. Crucially, it never travels across the network as a secret a criminal can intercept. That single design difference closes the three most common ways staff accounts get compromised.
A texted code can be phished — a fake login page asks for it and relays it in real time. It can be replayed if intercepted. And the phone number itself can be hijacked through a SIM-swap, where an attacker convinces a carrier to move the number to their own SIM. Passkeys are immune to all three: there is no code to type into a fake page, nothing reusable to intercept, and no phone number to steal.

What this means for a dental practice specifically
Dental offices are a favored target precisely because they hold protected health information and often run lean on IT. A single compromised Microsoft 365 login can expose email, shared patient correspondence, imaging portals, and cloud backups — the kind of breach that triggers PHIPA and HIPAA reporting obligations and erodes patient trust overnight. The most common entry point is not a sophisticated exploit; it is a staff member typing a real code into a convincing fake page.
Passkeys remove that failure mode. When the front desk, hygienists, and clinical staff sign in with a passkey, there is no code for a phishing kit to harvest. For a practice, that is arguably the highest-leverage security improvement available today, and Microsoft is now doing the heavy lifting of making it the default rather than an obscure opt-in.

How to set up a passkey before the deadline
You do not need to wait for the automatic rollout. Each staff member can register a passkey in about a minute:
- Sign in to the account security page at aka.ms/mysecurityinfo.
- Choose to add a sign-in method and select passkey (or “security key / passkey”).
- Follow the prompt to create it on the phone or laptop, confirming with a fingerprint, face scan, or device PIN.
- Register a second passkey on a backup device so no one is locked out if a phone is lost.
Administrators should also enable the passkey (FIDO2) method in the Entra admin center if it is not already on, and consider requiring phishing-resistant authentication for accounts with access to sensitive data. Doing this now, on your schedule, is far calmer than doing it reactively when a staff member gets a blocking prompt at 8:55 a.m. with a full waiting room.

A practical rollout plan for a small office
Treat this as a short project, not a fire drill. A sensible sequence for a practice of any size:
- This month: confirm passkeys are enabled in your tenant and register one for the practice’s most privileged accounts first.
- Before September: have every staff member enroll a passkey plus a backup, and document who is enrolled.
- By year end: phase out SMS as a fallback for anyone who has a working passkey, so the February 2027 retirement is a non-event.
The goal is simple: when Microsoft flips the switch, your team has already been signing in with passkeys for months and nobody notices the change.

Where Compudent fits in
If you are not sure whether passkeys are enabled in your Microsoft 365 tenant, which accounts still rely on SMS, or how to roll this out without disrupting a busy schedule, that is exactly the kind of quiet, deadline-driven IT work we handle for practices every day. Compudent Systems can assess your current authentication setup, enable phishing-resistant sign-in across your team, and make sure no one is left dependent on a method that is about to disappear.
Passwords and texted codes had a good run. Passkeys are simpler for your staff and dramatically harder for attackers — and now they are the default. Contact Compudent Systems to review your practice’s sign-in security before the 2027 deadline arrives.
Sources & further reading:
- Microsoft Entra ID: Passkeys are the default authentication method (Microsoft Security Blog)
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication (Microsoft Learn)