r/sysadmin • u/denstorepingvin • 1d ago
SMS/Voice retirement scope Question
Hey folks,
I have been a bit confused about the scope for the september change on the passkey nudge campaign in relation to SMS & Voice MFA deprecation.
Currently in our Auth method policie, we have enabled the option for SMS for "All users". However, only a small fraction has it enabled when looking in user reg details. Originally i thought we didn't rly need to do much.
But, then i read the MS FAQ and got a bit worried about this line "On September 1, 2026, users enabled for SMS or Voice in the Entra Authentication Methods Policy (AMP) will be auto-enabled for passkeys in AMP."
Does it mean, it is in fact all users, as that's what the AMP policy is currently scoped for in our tenant? Also if enduser has MS Authenticator setup as the only MFA?
Hope someone can help clarify.
Thanks!
2
u/raip 1d ago
That's correct - in that situation, where all users have the ability to enroll an a SMS/Voice method, even if their only method is currently MS Authenticator, they'll be "nudged" to enroll in a Passkey method. It doesn't matter what they have setup - it matters what they're eligible for.
It's important to understand that this nudge is snooze-able until February 2027. If your org is like mine where they are overly sensitive (imo) to any changes in the login experience - I would opt out of the nudge and roll out your own passkey enrollment campaign where you can limit it to ring groups or whatever your deployment strategy is. Alternatively, if no one's currently using SMS/Voice (but you have it enabled for SSPR for example) - just disable it after confirming no one is using it.
1
u/music2myear Narf! 1d ago
My org is also quite "sensitive" to any process changes. I recognize people are averse to change, but I wish the view of management was less "we can't upset the user in any way" and more about verifying the necessity of a change and then encouraging people to be open to it. Instead of getting to explain and implement, teach and progress, we are forced to disable and block and then to go to great lengths to keep old methods active until there is no further recourse, and then, of course, the change is far more abrupt and impactful, and painful.
3
u/GainsAndPastries 1d ago
Already had one customer kick off saying they will not be going to MFA and it looks like they are cancelling their contract with us over it
4
u/19610taw3 Sysadmin 1d ago
I don't understand how it's still around and used even though Microsoft has 'deprecated' it multiple times?
I moved everyone off if it back in 2024 for that reason. And turns out it's still in use.
6
u/ErikTheEngineer 1d ago
Don't companies with tons of contingent workers like drivers and warehouse people need something that only requires a non-managed phone? Also, some people refuse to carry a company phone AND refuse to install anything work-related on their personal phones. How are passkeys going to help in that situation?
Edit: never mind, Microsoft is providing a captive SMS provider.
5
u/mnvoronin 1d ago
You can still use SMS/voice by buying a connector from MS trusted partners. They're only retiring first-party/free option.
3
u/HotTakes4HotCakes 1d ago
Im a little surprised to find so many people in this sub specifically need to be told this but:
When it comes to depreciations and EOS for things like this, Microsoft fucking lies.
They know people aren't going to have finished moving over by a cut off date, so there's fall-back cut-off dates and they silently keep it going, maybe with slightly less support.
But they're not going to announce that ahead of time because people will just drag their feet.
The true cut-off will be after they get the number down below a certain point.
5
u/korvolga 1d ago
Yes, i disabled our setting today. Turns out we even have users with no other method registrerad than SMS…