Signing in is about to get a whole lot safer and simpler. With Microsoft retiring text and phone call authentication codes, here is why passkeys strengthen your defences and how to make the move with confidence.
For years, passwords have been the weakest link in almost every organisation’s defences. That is now changing, and the timing is no accident. As more organisations look to adopt AI, identity has become the foundation everything else rests on, and the old methods are no longer strong enough to carry it.
From 1 September 2026, Microsoft is making passkeys the default way people sign into Microsoft 365 and other work accounts, and Microsoft will stop providing SMS codes and voice calls for authentication on 1 February 2027.
By making passkeys the default, Microsoft is giving every organisation phishing resistant security as standard rather than something you have to opt into or configure. This change marks a real step up in cyber resilience, shutting down the route many attackers rely on most while making everyday sign in simpler.
A passkey lets you sign in without a password. Rather than typing something you have to remember, you confirm it is you using the same thing you already use to unlock your phone or laptop: your fingerprint, your face, or a PIN.
For example, in a working day a passkey is used for:
What makes it secure is that your device holds a private key that never leaves it, and shares only a matching public key with the site you are signing into. When you sign in, your device proves it holds the private key without ever revealing it. The reassuring part is that none of this is something the user has to think about. The experience is simply quicker and easier than a password.
So what does phishing resistant actually mean? Put simply, a passkey is tied to the genuine website it was created for, so it cannot be used anywhere else. If someone is tricked into visiting a convincing fake, their device will not present the passkey at all. The mistake that usually lets an attacker in no longer opens the door.
The second benefit is that if a provider’s systems are breached, attackers gain only the public key, which is useless on its own. There is no password sitting in a database waiting to be stolen and reused elsewhere. This is why the UK’s National Cyber Security Centre now recommends passkeys as the default choice, describing the move as a genuine step forward in resilience against phishing.
The outcome is a sign in that is both safer and easier to live with day to day.
In short, the burden shifts away from your people and onto technology that is built to resist attack. Your defences get stronger, while the people who rely on them every day are asked to do less.
After 1 February 2027, if someone’s only sign in method is still a text or phone call code, they will be prompted to set up a passkey before they can continue, this cannot be skipped, meaning its vital to be prepared in advance of this date.
This does not mean SMS and voice authentication will disappear entirely. Organisations that still need those methods may be able to continue using them through a third-party provider, but that would need to be onboarded, managed and maintained separately from Microsoft’s native authentication experience.
We are encouraging all organisations to adopt passkeys to strengthen their cyber resilience and bring them in line with current best practice by removing one of the weaknesses most commonly exploited by attackers.
For some organisations this will be a straightforward change. For others it will take a little planning, particularly where different devices and ways of working are involved. Working alongside your team, we can help you understand who needs to move, guide the transition so it feels effortless for your people, and make sure nobody is caught out before the deadline.
If you would like to talk through what this means for your organisation, contact us.
Date: 9 December 2025 Time: 10am – 11am Where: Microsoft Teams webinar Hospices are under constant pressure, balancing limited time, stretched resources, and growing demand. AI offers a helping hand to ease that burden: streamlining administrative tasks, saving time, and allowing staff to focus on what truly matters, delivering compassionate patient care. In this session,…
We’re delighted to announce that we have recently become a corporate member of Sussex Wildlife Trust, a respected local charity formed in 1961, and is now the largest local organisation dedicated to protecting the wildlife and natural environment across Sussex. By joining as a corporate member, we’re supporting vital work that helps safeguard local habitats,…
We’re pleased to share that following our latest independent surveillance audit, Trident continues to meet the internationally recognised standards of ISO 27001, a certification we’ve held since 2019. In today’s complex digital world, information security is more than a requirement, it’s a responsibility. Our ISO 27001 certification reflects our ongoing commitment to safeguarding our systems,…
Hospices face growing cybersecurity risks, often with limited internal IT capacity. Our services are designed to support your team with additional insight, helping you stay secure without adding pressure. To do this, we’ve developed a two-part security review service tailored specifically for hospices. Why two parts? Because securing Microsoft 365 isn’t just about getting the…
This past Saturday, our team proudly took to the water at Tilgate Park for St Catherine’s Hospice‘s annual Dragon Boat Race! With paddles in hand and team spirit in full force, we joined 18 other teams in a series of races, each crew battling it out on the water with determination whilst being cheered on…
Microsoft has confirmed that support for Windows 10 will officially end on 14 October 2025. To ease the transition, they’ve introduced an Extended Security Updates (ESU) program, available to all organisations for a fee, but offered free for one year to charities and education providers.
Yesterday, we hosted a fantastic fundraiser quiz night in support of our upcoming dragon boat race for St Catherine’s Hospice on 6th September – and what a night it was!
Trident offers a zero-cost, zero commitment review that assesses an organisation’s IT, focusing on the use of Microsoft 365.
Cybersecurity is no longer just an IT issue. It is a business-critical priority. For C-suite/board members/senior leadership teams, the key question is not if a cyber threat will happen, but how well your organisation is prepared to handle it.
Cyber threats don’t wait, and neither should your defences. By taking five focused actions, you can immediately reduce your exposure, strengthen your resilience, and build confidence in your organisation’s ability to respond. And with Trident as your partner, you gain access to expert support, proven tools, and ongoing guidance, so your internal team can stay focused while we help you stay secure. And here’s where to start.