Signing in is about to get a whole lot safer and simpler. With Microsoft retiring text and phone call authentication codes, here is why passkeys strengthen your defences and how to make the move with confidence.
For years, passwords have been the weakest link in almost every organisation’s defences. That is now changing, and the timing is no accident. As more organisations look to adopt AI, identity has become the foundation everything else rests on, and the old methods are no longer strong enough to carry it.
From 1 September 2026, Microsoft is making passkeys the default way people sign into Microsoft 365 and other work accounts, and Microsoft will stop providing SMS codes and voice calls for authentication on 1 February 2027.
By making passkeys the default, Microsoft is giving every organisation phishing resistant security as standard rather than something you have to opt into or configure. This change marks a real step up in cyber resilience, shutting down the route many attackers rely on most while making everyday sign in simpler.
A passkey lets you sign in without a password. Rather than typing something you have to remember, you confirm it is you using the same thing you already use to unlock your phone or laptop: your fingerprint, your face, or a PIN.
For example, in a working day a passkey is used for:
What makes it secure is that your device holds a private key that never leaves it, and shares only a matching public key with the site you are signing into. When you sign in, your device proves it holds the private key without ever revealing it. The reassuring part is that none of this is something the user has to think about. The experience is simply quicker and easier than a password.
So what does phishing resistant actually mean? Put simply, a passkey is tied to the genuine website it was created for, so it cannot be used anywhere else. If someone is tricked into visiting a convincing fake, their device will not present the passkey at all. The mistake that usually lets an attacker in no longer opens the door.
The second benefit is that if a provider’s systems are breached, attackers gain only the public key, which is useless on its own. There is no password sitting in a database waiting to be stolen and reused elsewhere. This is why the UK’s National Cyber Security Centre now recommends passkeys as the default choice, describing the move as a genuine step forward in resilience against phishing.
The outcome is a sign in that is both safer and easier to live with day to day.
In short, the burden shifts away from your people and onto technology that is built to resist attack. Your defences get stronger, while the people who rely on them every day are asked to do less.
After 1 February 2027, if someone’s only sign in method is still a text or phone call code, they will be prompted to set up a passkey before they can continue, this cannot be skipped, meaning its vital to be prepared in advance of this date.
This does not mean SMS and voice authentication will disappear entirely. Organisations that still need those methods may be able to continue using them through a third-party provider, but that would need to be onboarded, managed and maintained separately from Microsoft’s native authentication experience.
We are encouraging all organisations to adopt passkeys to strengthen their cyber resilience and bring them in line with current best practice by removing one of the weaknesses most commonly exploited by attackers.
For some organisations this will be a straightforward change. For others it will take a little planning, particularly where different devices and ways of working are involved. Working alongside your team, we can help you understand who needs to move, guide the transition so it feels effortless for your people, and make sure nobody is caught out before the deadline.
If you would like to talk through what this means for your organisation, contact us.
“I like to believe that working together with Trident, we are far more assured than we’ve ever been as to our own resilience, security and safety, which is a tremendous boon to our reputation.” – Giles Tomsett, Chief Executive at St Catherine’s Hospice In this case study video, St Catherine’s Hospice shares how working in…
At a glance Sussex Wildlife Trust (SWT) partnered with us to successfully relocate from their long-standing premises of over 60 years into a modern office environment built around flexibility, collaboration, and sustainable working practices. This move formed a key milestone within a broader IT roadmap designed to modernise SWT’s technology environment and bring systems and…
In today’s fast-moving digital environment, organisations need strong technology leadership to stay competitive, manage risk, and scale effectively. But for many organisations, hiring a full-time IT director isn’t always practical, or necessary. A fractional IT director offers an alternative: experienced, strategic technology leadership delivered on a flexible basis. Instead of committing to a permanent executive…
At a glance YMCA DownsLink Group, the leading charity for children and young people in Sussex and Surrey, transformed its operations by partnering with Trident to modernise its IT environment. Moving from outdated, on-premises servers to a secure, cloud-based infrastructure, YMCA DLG benefited from dedicated on-site IT support, cybersecurity improvements, (including Cyber Essentials PLUS certification),…
We’re excited to announce that Trident is sponsoring the Under-14s Academy team at Bognor Regis Town Football Club, as well as one of their talented defenders, Liam H. We’re incredibly proud to support such a dedicated young team and to be part of their journey this season. We wish the entire squad great success on…
Microsoft has introduced significant changes to its New Commerce Experience (NCE) licensing offering – and these updates aren’t just about pricing. They’re about giving organisations more flexibility, better security, enhanced productivity, stronger compliance, accelerate AI adoption, and opportunities to optimise spend. Understanding these changes now means you can make informed decisions that protect your budget and strengthen your IT strategy. …
As the year draws to a close, the festive season is always a time for celebration, but for us at Trident, it’s also a time to give back to the community that means so much to us. While we enjoyed plenty of seasonal cheer, from hot chocolates delivered by our very own Santa to laughter-filled…
At a glance – Enhanced system performance post-Citrix migration Tectrans, a global translation specialist, transformed its business by moving from a restrictive Citrix-hosted IT setup to a secure, flexible Microsoft 365 cloud environment. This shift delivered immediate cost savings, improved productivity, and enabled the team to deliver exceptional service to their clients worldwide. About Tectrans…
Hospices are under constant pressure, balancing limited time, stretched resources, and growing demand. AI offers a helping hand to ease that burden: streamlining administrative tasks, saving time, and allowing staff to focus on what truly matters, delivering compassionate patient care. In this session, Louis Graham, Microsoft Copilot Specialist, shared how Microsoft Copilot is being used in…
Hear from Giles Tomsett, Chief Executive at St Catherine’s Hospice, and Stuart Palma, Chief Executive Officer at Southern Hospice Group, on challenges they face in the hospice sector, and how Trident has partnered with them to solve their IT challenges.