Skip to main content
Kumonix - Microsoft Solutions Partner
All articles

Microsoft MFA Changes: What Law Firms Must Do

Microsoft is making passkeys the default sign-in method in Entra ID from September 2026. Learn what this means for security, users and your organisation.

Kumonix Team 5 min read

If your firm still asks staff to type in a text-message code when they log into Microsoft 365, that's about to change — not because you're choosing it, but because Microsoft is choosing it for you.

Starting 1 September 2026, Microsoft Entra ID will begin rolling out passkeys as the default authentication method, replacing the text-message and voice-call codes most firms have relied on for years. This isn't a minor tweak to a settings page. It's Microsoft switching off the authentication method most of your team probably uses every single day, and switching them onto something they've likely never heard of. Microsoft

Here's what's actually happening, why now, and what you need to do before it happens to you rather than around you.

What's Actually Changing

Entra ID is the system behind the scenes that checks who's allowed to log into your firm's Microsoft 365 account: email, Teams, SharePoint, all of it. Most firms use a "second factor" alongside a password, either a text message with a code or a phone call reading one out.

From September 2026, anyone currently using SMS or voice authentication will be automatically switched over to passkeys, and prompted to set one up the next time they log in. A passkey is a more modern login method tied to a device: a fingerprint, a face scan, or a security key, rather than a password or a code sent over text.

Microsoft-provided SMS and voice authentication won't disappear immediately. But it will be fully retired from 1 February 2027, and any firm that still needs it after that point will have to pay a third-party provider for it rather than getting it built in for free. After that date, passkey prompts become mandatory across every tenant, with no way to opt out.

For a firm, that's not a switch you flip on a Friday afternoon. It's a rollout that touches every fee earner, every partner, and every piece of client-facing kit they log in from.

Why Microsoft Is Doing This Now

This isn't Microsoft tidying up old technology for the sake of it. The change is a direct response to a sharp rise in AI-generated phishing attacks, which Microsoft's own threat intelligence team has seen achieving click-through rates as high as 54%, compared with around 12% for older-style phishing.

Read that again. More than half the people who receive a well-crafted AI phishing email are clicking it. SMS and voice codes don't protect you from that. A convincing fake login page can capture a text code just as easily as a password, and the person on the other end has no way of knowing the difference. Passkeys are built so there's nothing to type in and steal in the first place. The cryptographic handshake happens on the device, not over a message an attacker can intercept or fake.

For law firms, this matters more than most sectors. You're holding client money, case files, and privileged correspondence: exactly the kind of target that makes a 54% click-through rate genuinely alarming rather than just a statistic.

What Happens Between Now and February 2027

The rollout isn't instant, and it isn't identical for every firm. A few dates matter:

From September 2026: if your firm uses SMS or voice MFA, staff will start seeing prompts to register a passkey the next time they log in. Microsoft is publishing information on supported providers and deployment guidance on 18 September 2026.

From late October 2026: if you have a genuine business reason to keep SMS or voice (some regulated environments do), you'll need to configure a paid third-party telecom provider through the Microsoft Security Store rather than relying on Microsoft's built-in version.

From February 2027: Microsoft's own SMS and voice delivery stops working entirely. If you haven't set up an alternative by then, affected users simply won't be able to complete MFA the way they used to.

The rollout reaches organisations gradually, so you may not see prompts on day one. That's not a reason to wait. It's a reason to get ahead of it before your partners are dealing with an unfamiliar login screen mid-client-call.

What to Do Before September

A few practical steps, none of which need to wait for Microsoft's prompts to arrive.

Find out who's actually on SMS or voice. Most firms have no clear picture of which authentication method each user is on. It was set up once, years ago, and never revisited. This is a five-minute check in the Entra admin centre, not a project.

Decide which type of passkey suits your team. Passkeys aren't one thing. They range from a fingerprint on a phone to a physical security key. Partners who travel and use personal devices need a different approach to admin staff on firm-issued laptops. Worth deciding this deliberately rather than letting Microsoft's default apply to everyone.

Prepare your partners, not just your IT team. The people most resistant to a new login step are usually the most senior, and the most likely to be targeted by a convincing phishing email. A short, plain-English heads-up before the prompts appear saves a lot of confused calls to IT in September.

Don't assume "no opt-out" means "no choices." You can't avoid the shift to passkeys, but you can control how it's rolled out, in what order, and with what support, rather than letting Microsoft's automatic prompts hit 200 staff inboxes with zero warning.

This is one of the more significant identity changes Microsoft has made to Entra ID in a while, and it's landing whether firms are ready or not. Firms who plan the rollout on their own terms over the next couple of months will have a far easier time than firms who find out about it when a partner calls asking why their phone won't log them in anymore.

If you want a second pair of eyes on your current authentication setup, who's on what, and how exposed you'd be if this rollout hit tomorrow, happy to talk it through

Next article

EnrichPoint: A Kumonix Founder Story

Read the next article

Ready to transform your business?

Let's discuss how our Microsoft solutions can drive your business forward. Get a free consultation and discover what's possible.