From 1 September 2026, Microsoft Entra ID makes passkeys the default authentication method, auto-enabling every user currently relying on SMS or voice codes — with Microsoft-provided SMS and voice authentication switched off entirely on 1 February 2027. That single vendor decision, backed by learn more about phishing-resistant MFA and passkeys guidance from the UK's own cyber authority, marks the point where phishing-resistant MFA stopped being a specialist upgrade and became the default expectation for any UK organisation running Microsoft 365 or Entra ID. This study pulls together the verified adoption figures, attack data, and migration dates UK IT buyers need before that switch flips.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Pre-Default | 0 | 3 |
| Passkeys Default | 3 | 21 |
| SMS/Voice Retired | 24 | 2 |
The 2026 turning point: why OTP's days are numbered
The clearest signal that phishing-resistant MFA has gone mainstream isn't a marketing claim — it's a platform default. Microsoft has confirmed that passkeys become the default authentication experience in Entra ID from 1 September 2026, and that users currently enabled for SMS or voice authentication will be automatically switched over to passkeys. Microsoft-provided SMS and voice authentication is then retired outright on 1 February 2027.
For UK organisations that have spent the last decade treating MFA as a single tick-box control, this is a hard deadline dressed up as a feature update. Every tenant still leaning on text-message codes or automated voice calls for second-factor authentication now has a fixed window — roughly five months from the default switch to full retirement — to have a working alternative in place.
The pressure isn't coming from Microsoft alone. The UK National Cyber Security Centre's own comparison of passkeys against traditional MFA concludes that passkeys outperform traditional MFA against the attacks currently seen in the wild, specifically adversary-in-the-middle phishing and session theft — the two attack types that continue to defeat SMS one-time passcodes, TOTP apps, push approval, and email-based verification links.

What "phishing-resistant" actually means
The term gets used loosely, so it's worth being precise. Microsoft's Secure Future Initiative guidance defines phishing-resistant MFA as any method that binds the authentication event to the legitimate site or app, rather than relying on a secret — a code, a link, a push approval — that a phisher can intercept and relay to the real service in real time.
On that definition, Microsoft names three methods that qualify: passkeys, Windows Hello, and FIDO2. Everything else in common use — SMS OTP, voice OTP, TOTP authenticator apps, push notifications, and email-based magic links — falls outside the phishing-resistant category, because in each case the user is handing over something a well-positioned attacker can capture and reuse before it expires.
This is the distinction UK security teams need when a vendor claims to offer "MFA" without qualifying it. A push notification is still MFA. It is not phishing-resistant MFA. If you want to understand the basics of multi-factor authentication before deciding where your organisation sits on this spectrum, that's the right starting point — but the 2026 conversation has moved past "do you have MFA" to "which category of MFA are you running."
The Entra ID deadline UK IT teams can't ignore
Two dates matter for any UK business running Microsoft 365 or Entra ID. The first is 1 September 2026, when passkeys become the platform default and users currently set up for SMS or voice are auto-enabled for passkeys. The second is 1 February 2027, when Microsoft-provided SMS and voice authentication is retired completely.
The practical implication is that the migration isn't optional and isn't distant — it starts this quarter. UK IT teams should be checking now whether their identity platform, device estate, and conditional access policies actually support passkeys, Windows Hello, and FIDO2 hardware keys, rather than assuming the auto-enablement will handle everything cleanly. Staff who currently rely on a personal mobile number as their MFA fallback are the group most exposed to disruption if migration isn't planned ahead of the retirement date.
Regulated UK sectors that still depend on smart cards or equivalent hardware-bound credentials will need to confirm those methods sit comfortably alongside the new Entra ID defaults, rather than being treated as a legacy exception. This is squarely an explore identity and access management solutions problem, not a helpdesk one — it touches procurement, device lifecycle budgets, and recovery processes, not just a login screen.
Adoption by the numbers: global reach vs enterprise reality
The scale of passkey adoption globally is now substantial. Industry tracking cited in 2026 puts active passkeys worldwide at 5 billion, with 49% of consumers saying they use passkeys regularly when the option is available to them. Those two figures describe consumer-facing adoption and usage behaviour — they are not a measure of enterprise authentication coverage.
The enterprise picture, drawn from Okta's own user base, tells a more measured story: adoption of phishing-resistant authenticators rose from 8.6% of users to 14.0% over the course of a year — a 63% increase, but still a minority of the total user base. That combination — rapid percentage growth from a small starting point — is exactly the pattern that fuels the "adoption is stalling" narrative currently circulating. The growth rate is real and fast; the absolute coverage is still early.
Read together, the two data sets say different things and shouldn't be merged into a single adoption claim. Consumer passkey usage is running well ahead of enterprise phishing-resistant authenticator coverage — which is precisely why platform-level defaults like Entra ID's September 2026 switch matter: they force enterprise coverage to catch up to consumer behaviour rather than waiting for organic uptake.
For UK organisations running mixed identity environments — not every enterprise sits solely on Microsoft Entra ID — the same direction of travel shows up across vendors. Okta's own enterprise adoption data, tracked independently of Microsoft's Entra ID changes, confirms that the move toward phishing-resistant authenticators is a cross-platform trend rather than a single-vendor mandate. Both Microsoft and Okta build their passkey and FIDO2 support on the same underlying FIDO2/WebAuthn standard overseen by the FIDO Alliance, whose figures also underpin the 5 billion global active-passkey count cited above — meaning organisations with mixed Microsoft, Okta, or other FIDO2-compliant identity estates can expect consistent phishing-resistant behaviour across providers, rather than needing a separate strategy per platform.
Passkeys vs OTP vs hardware keys: what UK buyers need to weigh
The security case for passkeys and FIDO2 hardware keys over OTP and push approval comes down to how the credential behaves during an attack. A passkey or FIDO2 key is cryptographically bound to the legitimate origin it was registered against — it simply will not authenticate against a lookalike phishing site, because the cryptographic handshake fails before any secret changes hands. An OTP code or a push approval, by contrast, is a value the user can be tricked into handing to an attacker-controlled relay, which then passes it to the real service in real time.
This is why the NCSC's live-attack comparison singles out adversary-in-the-middle phishing and session theft as the scenarios where passkeys separate themselves from traditional MFA — these are exactly the attack types built to exploit the weakness in OTP and push-based flows.
For UK organisations choosing between synced passkeys and dedicated FIDO2 hardware keys, the decision usually tracks organisation size and regulatory exposure: consumer-facing and general staff populations tend to fit naturally with platform passkeys tied to existing devices, while regulated environments that already depend on smart cards or dedicated hardware tokens will look to FIDO2 hardware keys as the equivalent phishing-resistant option that fits existing procurement and issuance processes. Either route satisfies Microsoft's phishing-resistant definition; the right choice depends on device management maturity and recovery-process design, and it sits alongside broader delve into the principles of Zero Trust thinking about how identity is verified across every access request.
View the data behind this chart
| Passkeys | FIDO2 Hardware… | SMS OTP & Push | |
|---|---|---|---|
| Resists live AiTM… | Yes | Yes | No |
| Resists session theft | Yes | Yes | No |
| Credential model | Bound to origin | Bound to origin | Shared secret |
| Entra ID status from… | Default from Sep 2026 | Supported alternative | Retiring Feb 2027 |
Attack data and the "stalling" narrative
Some 2026 commentary has framed passkey adoption as stalling, pointing to slow enterprise uptake relative to consumer buzz. The Okta figures support part of that framing — 14.0% enterprise adoption is still a minority position even after a 63% year-on-year increase. But the attack data doesn't support waiting: the NCSC's comparison is explicit that passkeys outperform traditional MFA specifically against attacks already happening in the wild, not against a hypothetical future threat.
The residual risk in any 2026 migration isn't the passkey technology itself — it's the transition period. Until Microsoft's SMS/voice retirement date on 1 February 2027, fallback authentication paths remain available, and fallback paths are exactly what adversary-in-the-middle phishing is built to exploit. Every account still permitted to fall back to SMS or voice during the transition window is effectively still running the phishable configuration the retirement is designed to remove.
UK security teams should treat the transition window as the highest-risk phase, not a grace period. Tightening conditional access to disable fallback wherever passkeys are already provisioned, rather than leaving both options live until the forced deadline, closes that gap early rather than at the last possible moment — a point worth weighing against the broader shift toward automated, AI-assisted phishing campaigns covered in our analysis of how understand the threat of AI-powered attacks is changing the threat landscape this year.
What this means for UK procurement and risk management
For UK IT buyers, phishing-resistant MFA has shifted from a security preference to a roadmap dependency. Microsoft's 2026 Entra ID changes and the NCSC's public position are pulling procurement in the same direction: away from SMS, voice, and simple push approval, and toward passkeys and FIDO2 as the baseline expectation for any Microsoft-centric identity estate.
Budget conversations should shift accordingly — away from recurring OTP delivery costs and toward one-time onboarding, device lifecycle management, and account recovery process design. Where cloud identity is already standard practice, phishing-resistant methods are also expected to reduce helpdesk load tied to MFA fatigue prompts and interception-based phishing incidents, since there is no code or push approval left for an attacker to relay.
Buying criteria for UK organisations should now explicitly include compatibility with NCSC guidance, support for regulated-sector hardware equivalents such as smart cards where SMS/voice retirement doesn't fit the risk profile, and a concrete migration plan for staff currently dependent on phone-number fallback before that fallback disappears in February 2027. Organisations that haven't mapped this yet should treat it as a 2026 planning item, not a 2027 one — the default switch happens first, the retirement follows five months later, and both dates are now fixed.
Methodology
This study compiles figures from vendor platform documentation, national cyber authority guidance, and independent MFA adoption tracking published between November 2025 and July 2026. Sources include Microsoft Learn's Entra ID authentication documentation, Microsoft's Secure Future Initiative guidance defining phishing-resistant MFA, a Forrester analyst briefing on the Entra ID passkey default announcement, a summary of NCSC-based passkey-versus-MFA attack comparisons published by NHIMG, and a 2026 MFA statistics roundup citing FIDO Alliance and Okta adoption data.
Each figure retains the exact scope and date given by its source: consumer passkey usage figures, global active-passkey counts, and enterprise authenticator adoption shares from Okta are treated as three separate metrics rather than merged into a single adoption rate, since they measure different populations and different behaviours. Vendor migration dates — the 1 September 2026 default switch and the 1 February 2027 retirement — are drawn directly from Microsoft's own published documentation and cross-checked against Forrester's independent analyst summary of the same announcement.
Where competing commentary discusses adoption "stalling" or new attack vectors without citing verifiable, dated figures, this study has not repeated those claims unless they were independently supported by the sourced data above. No figure, percentage, or date in this piece has been estimated, averaged, or extrapolated beyond what its original source states.
Sources
Every figure in this article traces to the sources below.
- •Microsoft Learn — Entra ID SMS/voice retirement and passkey default dates
- •Microsoft Learn — Secure Future Initiative definition of phishing-resistant MFA
- •Forrester — analysis of Microsoft's Entra ID passkey default announcement
- •NHIMG — summary of NCSC passkey vs traditional MFA live-attack comparison
- •SWIF.AI — 2026 MFA statistics roundup citing FIDO Alliance and Okta data
View the data behind this chart
| Layer | Detail |
|---|---|
| 5 billion active passkeys | Worldwide count, per FIDO Alliance data cited… |
| 49% regular use when available | Share of consumers choosing passkeys over other… |
| 14.0% enterprise adoption | Okta phishing-resistant authenticator share, up… |
The 9 verified data points behind this study are free to download and reuse with attribution (CC BY 4.0).
Cite as: Servnet Research, “Phishing-Resistant MFA 2026: Passkeys vs OTP Data Study”, servnetuk.com, 2026.
