Signing in is about to get a whole lot safer and simpler. With Microsoft retiring text and phone call authentication codes, here is why passkeys strengthen your defences and how to make the move with confidence.
For years, passwords have been the weakest link in almost every organisation’s defences. That is now changing, and the timing is no accident. As more organisations look to adopt AI, identity has become the foundation everything else rests on, and the old methods are no longer strong enough to carry it.
From 1 September 2026, Microsoft is making passkeys the default way people sign into Microsoft 365 and other work accounts, and Microsoft will stop providing SMS codes and voice calls for authentication on 1 February 2027.
By making passkeys the default, Microsoft is giving every organisation phishing resistant security as standard rather than something you have to opt into or configure. This change marks a real step up in cyber resilience, shutting down the route many attackers rely on most while making everyday sign in simpler.
A passkey lets you sign in without a password. Rather than typing something you have to remember, you confirm it is you using the same thing you already use to unlock your phone or laptop: your fingerprint, your face, or a PIN.
For example, in a working day a passkey is used for:
What makes it secure is that your device holds a private key that never leaves it, and shares only a matching public key with the site you are signing into. When you sign in, your device proves it holds the private key without ever revealing it. The reassuring part is that none of this is something the user has to think about. The experience is simply quicker and easier than a password.
So what does phishing resistant actually mean? Put simply, a passkey is tied to the genuine website it was created for, so it cannot be used anywhere else. If someone is tricked into visiting a convincing fake, their device will not present the passkey at all. The mistake that usually lets an attacker in no longer opens the door.
The second benefit is that if a provider’s systems are breached, attackers gain only the public key, which is useless on its own. There is no password sitting in a database waiting to be stolen and reused elsewhere. This is why the UK’s National Cyber Security Centre now recommends passkeys as the default choice, describing the move as a genuine step forward in resilience against phishing.
The outcome is a sign in that is both safer and easier to live with day to day.
In short, the burden shifts away from your people and onto technology that is built to resist attack. Your defences get stronger, while the people who rely on them every day are asked to do less.
After 1 February 2027, if someone’s only sign in method is still a text or phone call code, they will be prompted to set up a passkey before they can continue, this cannot be skipped, meaning its vital to be prepared in advance of this date.
This does not mean SMS and voice authentication will disappear entirely. Organisations that still need those methods may be able to continue using them through a third-party provider, but that would need to be onboarded, managed and maintained separately from Microsoft’s native authentication experience.
We are encouraging all organisations to adopt passkeys to strengthen their cyber resilience and bring them in line with current best practice by removing one of the weaknesses most commonly exploited by attackers.
For some organisations this will be a straightforward change. For others it will take a little planning, particularly where different devices and ways of working are involved. Working alongside your team, we can help you understand who needs to move, guide the transition so it feels effortless for your people, and make sure nobody is caught out before the deadline.
If you would like to talk through what this means for your organisation, contact us.
Over the past 10 years, Martlets has partnered with Trident to progressively modernise their IT environment. Martlets is a charity providing essential hospice care to people affected by terminal illness in Brighton and Hove, and surrounding areas.
Microsoft Windows 10 will reach the end of support on 14 October 2025, to focus on transitioning to its modern, security-enhanced platform – Windows 11.
After this date, devices running Windows 10 will no longer receive security updates or technical support. This change presents a valuable opportunity for organisations to plan ahead and ensure their IT environment remains secure, efficient, and aligned with future needs.
We’re excited to announce that Team Trident will be taking part in the Dragon Boat Race at Tilgate Park on Saturday 6 September 2025, in support of St Catherine’s Hospice.
At Trident, we’ve seen how transformational SharePoint can be for hospices.
With experience in hospice IT and SharePoint, we can guide your team through a smooth, tailored rollout that improves collaboration, protects sensitive data, and simplifies daily operations.