Signing in is about to get a whole lot safer and simpler. With Microsoft retiring text and phone call authentication codes, here is why passkeys strengthen your defences and how to make the move with confidence.
For years, passwords have been the weakest link in almost every organisation’s defences. That is now changing, and the timing is no accident. As more organisations look to adopt AI, identity has become the foundation everything else rests on, and the old methods are no longer strong enough to carry it.
From 1 September 2026, Microsoft is making passkeys the default way people sign into Microsoft 365 and other work accounts, and Microsoft will stop providing SMS codes and voice calls for authentication on 1 February 2027.
By making passkeys the default, Microsoft is giving every organisation phishing resistant security as standard rather than something you have to opt into or configure. This change marks a real step up in cyber resilience, shutting down the route many attackers rely on most while making everyday sign in simpler.
A passkey lets you sign in without a password. Rather than typing something you have to remember, you confirm it is you using the same thing you already use to unlock your phone or laptop: your fingerprint, your face, or a PIN.
For example, in a working day a passkey is used for:
What makes it secure is that your device holds a private key that never leaves it, and shares only a matching public key with the site you are signing into. When you sign in, your device proves it holds the private key without ever revealing it. The reassuring part is that none of this is something the user has to think about. The experience is simply quicker and easier than a password.
So what does phishing resistant actually mean? Put simply, a passkey is tied to the genuine website it was created for, so it cannot be used anywhere else. If someone is tricked into visiting a convincing fake, their device will not present the passkey at all. The mistake that usually lets an attacker in no longer opens the door.
The second benefit is that if a provider’s systems are breached, attackers gain only the public key, which is useless on its own. There is no password sitting in a database waiting to be stolen and reused elsewhere. This is why the UK’s National Cyber Security Centre now recommends passkeys as the default choice, describing the move as a genuine step forward in resilience against phishing.
The outcome is a sign in that is both safer and easier to live with day to day.
In short, the burden shifts away from your people and onto technology that is built to resist attack. Your defences get stronger, while the people who rely on them every day are asked to do less.
After 1 February 2027, if someone’s only sign in method is still a text or phone call code, they will be prompted to set up a passkey before they can continue, this cannot be skipped, meaning its vital to be prepared in advance of this date.
This does not mean SMS and voice authentication will disappear entirely. Organisations that still need those methods may be able to continue using them through a third-party provider, but that would need to be onboarded, managed and maintained separately from Microsoft’s native authentication experience.
We are encouraging all organisations to adopt passkeys to strengthen their cyber resilience and bring them in line with current best practice by removing one of the weaknesses most commonly exploited by attackers.
For some organisations this will be a straightforward change. For others it will take a little planning, particularly where different devices and ways of working are involved. Working alongside your team, we can help you understand who needs to move, guide the transition so it feels effortless for your people, and make sure nobody is caught out before the deadline.
If you would like to talk through what this means for your organisation, contact us.
Hospices are being asked to do more with technology than ever, from tighter compliance and smarter ways of working to safer systems and a serious conversation around AI. It is a lot to navigate when budgets are tight and teams are stretched. The Southern Hospices Technology Leaders Forum brings together leaders from across the south…
Eight members of the Trident team have successfully completed The Clock Tower Sanctuary’s annual half marathon hike from Lewes to Brighton, raising more than £2,000 to support young people experiencing homelessness across Brighton & Hove. Taking place on 11 July 2026 during sweltering temperatures, the challenge saw the team cover over 13 miles across the…
In many hospices, internal communications have grown organically over time. Policies are shared as email attachments, news goes out across multiple channels, and teams across clinical, fundraising and operations often have their own ways of storing and sharing information. This approach works in practice, but over time it can make it harder for people to…
“Working with Trident gives reassurance which is important for me, for our board, and for our people here at Southern Hospice Group.” – Stuart Palma, Chief Executive Officer at Southern Hospice Group Confidence, clarity and continuity are critical during any merger. In this case study video, Southern Hospice Group shares how partnering with Trident helped…
Upcoming event: Southern Hospices Technology Leaders Forum 23 September 2026 | 8:30am – 2pm | Leonardslee Lakes & Gardens The Southern Hospices Technology Leaders Forum brings together leaders from across the south for a half-day event focused on the topics shaping hospice technology right now. Expect expert-led sessions on compliance, AI and cyber security, plus an…
Over the past few days, a large-scale campaign has emerged targeting Fortinet firewalls and SSL VPN services. Security researchers have identified almost 74,000 internet facing Fortinet devices that may be exposed, with attackers using stolen usernames and passwords to attempt access at scale. The headlines are focused on Fortinet, with organisations such as the…
On 11 July, eight members of the Trident team will take on The Clock Tower Sanctuary’s annual half marathon hike from Lewes to Brighton, raising funds and awareness to support young people experiencing homelessness across Brighton and Hove. The team is aiming to raise £1,600 to help The Clock Tower Sanctuary continue providing vital support…
30 June 2026 | 10am – 11am | Microsoft Teams In many hospices, internal communications have grown organically over time. Policies are shared as email attachments, news goes out across multiple channels, and teams across clinical, fundraising and operations often have their own ways of storing and sharing information. This approach works in practice, but…
Modern organisations rely heavily on digital systems to support day‑to‑day operations. Cloud platforms, connected devices and integrated applications now play a central role in how teams communicate, collaborate and deliver services. As a result, IT environments have become larger, more interconnected and constantly active. Systems generate continuous activity across users, devices, networks and cloud services, making it increasingly difficult to recognise when something unusual is…
As IT environments have become more interconnected and the risk landscape has changed, Trident has extended its Monitoring and Protection Service with the introduction of MPS Pro. MPS Pro builds on Trident’s well-established monitoring and protection capability by adding 24/7 managed detection and response; Activity across environments is continuously monitored, reviewed and actioned by Trident’s security specialists, providing…