Spread the love

Heads up: some links in this post are affiliate links, which means HenkTek may earn a commission if you buy through one. It costs you nothing extra and it does not change what we recommend.

If your office runs on Microsoft 365, the login screen your staff stares at every morning is about to change, and nobody mailed out a memo about it. On September 1 Microsoft starts flipping Entra ID accounts over to passkeys by default. Passkeys in Fort Myers offices go from a nice idea somebody read about to the thing your team gets nudged into whether you planned for it or not.

The six digit text codes everyone has been living with for a decade are on a countdown clock now. Microsoft laid out the full timeline in mid July and it runs into 2027, so there’s room to breathe. Not a ton of it though. The first change lands in about five weeks and it hits during hurricane season, which is either lousy timing or the single best argument for making the switch. More on that in a minute.

What Actually Changes on September 1

Nothing breaks that morning. That’s worth saying up front, because the version of this story going around makes it sound like people will be locked out of their email. They won’t be.

What happens is that Microsoft turns on auto enablement for passkeys and starts prompting anyone who signs in with a text or voice code to register one instead. Your bookkeeper logs in, gets the usual code, and then sees a screen asking her to set up a passkey. She can dismiss it. She’ll see it again tomorrow.

The rest of the calendar looks like this:

  • September 1, 2026: auto enablement kicks in and the passkey prompts start showing up at sign in
  • September 18: Microsoft publishes pricing and the list of outside telecom providers for anyone who has to keep SMS
  • October 30: admins can pick and set up a third party SMS or voice provider
  • February 1, 2027: Microsoft stops delivering its own SMS and voice codes entirely, and the passkey prompt becomes mandatory with no way to skip it

That last date is the real deadline. After February 1 a user who relies on text codes has to register a passkey before they can get in. There’s no opt out at the tenant level. If your business genuinely needs SMS for a compliance reason, you’ll be paying an outside telecom provider for it, and you can read Microsoft’s own writeup of the SMS and voice retirement for the fine print.

Why Microsoft Is Pulling the Plug on Text Codes

Because they don’t work anymore. Text codes stop a lazy attacker guessing a password, and that’s about where their usefulness ends.

An attacker who has your password and a convincing fake login page just asks you for the code and types it in on the real site within the thirty seconds it stays valid. We’ve watched this happen to a Cape Coral client. The owner did everything right, got a code on her phone, and handed it to a page that looked exactly like the Microsoft sign in. Money moved that afternoon.

SIM swaps are the other half of it. Somebody talks a carrier rep into moving a phone number to a new SIM, and now the codes arrive on their device instead. And if you’ve already read our piece on MFA push bombing, you know app approvals have their own version of the same problem, where people tap approve at 2am just to make the buzzing stop.

A passkey can’t be handed over, because there’s nothing to hand over. The credential is tied to the site it was created for and it lives in the phone’s secure hardware. Point a staffer at a fake Microsoft page and the passkey won’t fire, since the domain doesn’t match. That’s the whole trick and it’s why CISA has been pushing phishing resistant MFA for years.

USB hardware security key plugged into a laptop with a backup key on a keyring, used for passkeys at a Fort Myers office
A hardware security key plus a spare, the setup we use for payroll and admin accounts

Passkeys in Fort Myers: What to Do in the Next Five Weeks

Start with a list of who signs in with what. Most small offices around here have never audited this and the answers are usually a mess: the owner uses the authenticator app, two people use text codes, and there’s a shared front desk account that nobody wants to admit exists.

What Fort Myers businesses should do first: pull the authentication methods report in Entra ID and find every account still on SMS or voice. Those are the accounts that will get prompted in September, and they’re the ones that break in February if nobody acts.

Then pick your pilot. Two or three people who won’t panic, ideally including whoever handles payroll or wire approvals, since those accounts are the ones attackers actually want. Get them registered on a phone based passkey first. Face ID or the fingerprint sensor, thirty seconds, done.

Roll the rest out in small batches through September and October. Don’t do the whole staff on one afternoon. Something will go sideways with somebody’s phone and you want that to be a two person problem, not a twelve person one.

The storm angle matters here more than people realize. A passkey sits on the device itself and doesn’t need a cell signal to work. When a tower goes down after a storm and text codes stop arriving, the person with a passkey still gets into email and the person waiting on a six digit code does not. We wrote about the rest of that prep in our cloud backup checklist, and this belongs on the same list.

Hardware Keys for the Accounts You Can’t Afford to Lose

Phone based passkeys cover most of your staff just fine. For the handful of accounts that would ruin your month if somebody got into them, put a physical key on it instead.

The YubiKey 5 line is what we hand clients. It’s a small metal fob that lives on a keyring, and signing in means touching it. No app, no battery, nothing to charge or update. It runs about $58, which is roughly what one hour of incident response costs, so the math isn’t hard.

Get the USB-C version if your laptops are recent. The USB-A version is the same key with the older connector, so check what’s actually on the side of the machine before ordering. Both do NFC too, which means tapping it against a phone works for mobile logins.

Buy two per person. This is the part everybody skips and then regrets. One key lives on the keyring, the backup goes in the office safe or a drawer at home. Lose the only key you own and you’re into account recovery, which on a Friday afternoon is miserable. We went through the whole setup in our YubiKey 5 review if you want the longer version.

Where This Trips Up Small Offices

Shared accounts are the big one. The front desk login that four people use, the info@ mailbox, the account the old bookkeeper set up in 2019 that still has a license attached. Passkeys are tied to a person and a device, so a shared account with one passkey means one person can get in. Sort those out now rather than in February.

Older hardware causes the other headaches. A Windows 10 machine that never got Hello configured, an ancient iPad at the front counter, a scanner that logs into a mailbox with a saved password. None of those handle passkeys gracefully and each one needs its own answer.

And somebody on your staff will lose their phone. Plan for it before it happens instead of after, because the recovery path you set up in advance takes ten minutes and the one you improvise takes half a day.

Need a Hand Rolling This Out?

HenkTek handles Microsoft 365 and identity work for businesses across Fort Myers, Cape Coral, Bonita Springs and Naples. We’ll audit which of your accounts are still sitting on text codes, register passkeys with your staff without turning it into an all day event, and set up the recovery process so a lost phone doesn’t become a lost afternoon.

Five weeks is plenty of time to do this calmly. It is not plenty of time to do it in January. Give us a call at (239) 234-2334 or reach out through the contact page for a free consultation, and we’ll tell you straight whether this is a thirty minute job or something bigger.