UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber Security

Phishing-Resistant MFA 2026: Passkeys vs OTP Data Study

Servnet Editorial · IT infrastructure analysis9 min read
Share

From 1 September 2026, Microsoft Entra ID makes passkeys the default authentication method, auto-enabling every user currently relying on SMS or voice codes — with Microsoft-provided SMS and voice authentication switched off entirely on 1 February 2027. That single vendor decision, backed by learn more about phishing-resistant MFA and passkeys guidance from the UK's own cyber authority, marks the point where phishing-resistant MFA stopped being a specialist upgrade and became the default expectation for any UK organisation running Microsoft 365 or Entra ID. This study pulls together the verified adoption figures, attack data, and migration dates UK IT buyers need before that switch flips.

The Microsoft Entra ID passkey migration window
W0W5W10W15W20W25W26Pre-Default3wPasskeys Default21wSMS/Voice Retired2wTotal: 26 weeks end-to-end
View the data behind this chart
The Microsoft Entra ID passkey migration window
PhaseStarts (week)Duration (weeks)
Pre-Default03
Passkeys Default321
SMS/Voice Retired242

The 2026 turning point: why OTP's days are numbered

The clearest signal that phishing-resistant MFA has gone mainstream isn't a marketing claim — it's a platform default. Microsoft has confirmed that passkeys become the default authentication experience in Entra ID from 1 September 2026, and that users currently enabled for SMS or voice authentication will be automatically switched over to passkeys. Microsoft-provided SMS and voice authentication is then retired outright on 1 February 2027.

For UK organisations that have spent the last decade treating MFA as a single tick-box control, this is a hard deadline dressed up as a feature update. Every tenant still leaning on text-message codes or automated voice calls for second-factor authentication now has a fixed window — roughly five months from the default switch to full retirement — to have a working alternative in place.

The pressure isn't coming from Microsoft alone. The UK National Cyber Security Centre's own comparison of passkeys against traditional MFA concludes that passkeys outperform traditional MFA against the attacks currently seen in the wild, specifically adversary-in-the-middle phishing and session theft — the two attack types that continue to defeat SMS one-time passcodes, TOTP apps, push approval, and email-based verification links.

Illustration: Phishing-Resistant MFA 2026: Passkeys vs OTP Data Study

What "phishing-resistant" actually means

The term gets used loosely, so it's worth being precise. Microsoft's Secure Future Initiative guidance defines phishing-resistant MFA as any method that binds the authentication event to the legitimate site or app, rather than relying on a secret — a code, a link, a push approval — that a phisher can intercept and relay to the real service in real time.

On that definition, Microsoft names three methods that qualify: passkeys, Windows Hello, and FIDO2. Everything else in common use — SMS OTP, voice OTP, TOTP authenticator apps, push notifications, and email-based magic links — falls outside the phishing-resistant category, because in each case the user is handing over something a well-positioned attacker can capture and reuse before it expires.

This is the distinction UK security teams need when a vendor claims to offer "MFA" without qualifying it. A push notification is still MFA. It is not phishing-resistant MFA. If you want to understand the basics of multi-factor authentication before deciding where your organisation sits on this spectrum, that's the right starting point — but the 2026 conversation has moved past "do you have MFA" to "which category of MFA are you running."

The Entra ID deadline UK IT teams can't ignore

Two dates matter for any UK business running Microsoft 365 or Entra ID. The first is 1 September 2026, when passkeys become the platform default and users currently set up for SMS or voice are auto-enabled for passkeys. The second is 1 February 2027, when Microsoft-provided SMS and voice authentication is retired completely.

The practical implication is that the migration isn't optional and isn't distant — it starts this quarter. UK IT teams should be checking now whether their identity platform, device estate, and conditional access policies actually support passkeys, Windows Hello, and FIDO2 hardware keys, rather than assuming the auto-enablement will handle everything cleanly. Staff who currently rely on a personal mobile number as their MFA fallback are the group most exposed to disruption if migration isn't planned ahead of the retirement date.

Regulated UK sectors that still depend on smart cards or equivalent hardware-bound credentials will need to confirm those methods sit comfortably alongside the new Entra ID defaults, rather than being treated as a legacy exception. This is squarely an explore identity and access management solutions problem, not a helpdesk one — it touches procurement, device lifecycle budgets, and recovery processes, not just a login screen.

Adoption by the numbers: global reach vs enterprise reality

The scale of passkey adoption globally is now substantial. Industry tracking cited in 2026 puts active passkeys worldwide at 5 billion, with 49% of consumers saying they use passkeys regularly when the option is available to them. Those two figures describe consumer-facing adoption and usage behaviour — they are not a measure of enterprise authentication coverage.

The enterprise picture, drawn from Okta's own user base, tells a more measured story: adoption of phishing-resistant authenticators rose from 8.6% of users to 14.0% over the course of a year — a 63% increase, but still a minority of the total user base. That combination — rapid percentage growth from a small starting point — is exactly the pattern that fuels the "adoption is stalling" narrative currently circulating. The growth rate is real and fast; the absolute coverage is still early.

Read together, the two data sets say different things and shouldn't be merged into a single adoption claim. Consumer passkey usage is running well ahead of enterprise phishing-resistant authenticator coverage — which is precisely why platform-level defaults like Entra ID's September 2026 switch matter: they force enterprise coverage to catch up to consumer behaviour rather than waiting for organic uptake.

For UK organisations running mixed identity environments — not every enterprise sits solely on Microsoft Entra ID — the same direction of travel shows up across vendors. Okta's own enterprise adoption data, tracked independently of Microsoft's Entra ID changes, confirms that the move toward phishing-resistant authenticators is a cross-platform trend rather than a single-vendor mandate. Both Microsoft and Okta build their passkey and FIDO2 support on the same underlying FIDO2/WebAuthn standard overseen by the FIDO Alliance, whose figures also underpin the 5 billion global active-passkey count cited above — meaning organisations with mixed Microsoft, Okta, or other FIDO2-compliant identity estates can expect consistent phishing-resistant behaviour across providers, rather than needing a separate strategy per platform.

Passkeys vs OTP vs hardware keys: what UK buyers need to weigh

The security case for passkeys and FIDO2 hardware keys over OTP and push approval comes down to how the credential behaves during an attack. A passkey or FIDO2 key is cryptographically bound to the legitimate origin it was registered against — it simply will not authenticate against a lookalike phishing site, because the cryptographic handshake fails before any secret changes hands. An OTP code or a push approval, by contrast, is a value the user can be tricked into handing to an attacker-controlled relay, which then passes it to the real service in real time.

This is why the NCSC's live-attack comparison singles out adversary-in-the-middle phishing and session theft as the scenarios where passkeys separate themselves from traditional MFA — these are exactly the attack types built to exploit the weakness in OTP and push-based flows.

For UK organisations choosing between synced passkeys and dedicated FIDO2 hardware keys, the decision usually tracks organisation size and regulatory exposure: consumer-facing and general staff populations tend to fit naturally with platform passkeys tied to existing devices, while regulated environments that already depend on smart cards or dedicated hardware tokens will look to FIDO2 hardware keys as the equivalent phishing-resistant option that fits existing procurement and issuance processes. Either route satisfies Microsoft's phishing-resistant definition; the right choice depends on device management maturity and recovery-process design, and it sits alongside broader delve into the principles of Zero Trust thinking about how identity is verified across every access request.

Comparing authentication methods against live attack data
PasskeysFIDO2 Hardware…SMS OTP & PushResists live AiTM…YesYesNoResists session theftYesYesNoCredential modelBound to originBound to originShared secretEntra ID status from…Default from Sep 2026Supported alternativeRetiring Feb 2027
View the data behind this chart
Comparing authentication methods against live attack data
PasskeysFIDO2 Hardware…SMS OTP & Push
Resists live AiTM…YesYesNo
Resists session theftYesYesNo
Credential modelBound to originBound to originShared secret
Entra ID status from…Default from Sep 2026Supported alternativeRetiring Feb 2027

Attack data and the "stalling" narrative

Some 2026 commentary has framed passkey adoption as stalling, pointing to slow enterprise uptake relative to consumer buzz. The Okta figures support part of that framing — 14.0% enterprise adoption is still a minority position even after a 63% year-on-year increase. But the attack data doesn't support waiting: the NCSC's comparison is explicit that passkeys outperform traditional MFA specifically against attacks already happening in the wild, not against a hypothetical future threat.

The residual risk in any 2026 migration isn't the passkey technology itself — it's the transition period. Until Microsoft's SMS/voice retirement date on 1 February 2027, fallback authentication paths remain available, and fallback paths are exactly what adversary-in-the-middle phishing is built to exploit. Every account still permitted to fall back to SMS or voice during the transition window is effectively still running the phishable configuration the retirement is designed to remove.

UK security teams should treat the transition window as the highest-risk phase, not a grace period. Tightening conditional access to disable fallback wherever passkeys are already provisioned, rather than leaving both options live until the forced deadline, closes that gap early rather than at the last possible moment — a point worth weighing against the broader shift toward automated, AI-assisted phishing campaigns covered in our analysis of how understand the threat of AI-powered attacks is changing the threat landscape this year.

What this means for UK procurement and risk management

For UK IT buyers, phishing-resistant MFA has shifted from a security preference to a roadmap dependency. Microsoft's 2026 Entra ID changes and the NCSC's public position are pulling procurement in the same direction: away from SMS, voice, and simple push approval, and toward passkeys and FIDO2 as the baseline expectation for any Microsoft-centric identity estate.

Budget conversations should shift accordingly — away from recurring OTP delivery costs and toward one-time onboarding, device lifecycle management, and account recovery process design. Where cloud identity is already standard practice, phishing-resistant methods are also expected to reduce helpdesk load tied to MFA fatigue prompts and interception-based phishing incidents, since there is no code or push approval left for an attacker to relay.

Buying criteria for UK organisations should now explicitly include compatibility with NCSC guidance, support for regulated-sector hardware equivalents such as smart cards where SMS/voice retirement doesn't fit the risk profile, and a concrete migration plan for staff currently dependent on phone-number fallback before that fallback disappears in February 2027. Organisations that haven't mapped this yet should treat it as a 2026 planning item, not a 2027 one — the default switch happens first, the retirement follows five months later, and both dates are now fixed.

Methodology

This study compiles figures from vendor platform documentation, national cyber authority guidance, and independent MFA adoption tracking published between November 2025 and July 2026. Sources include Microsoft Learn's Entra ID authentication documentation, Microsoft's Secure Future Initiative guidance defining phishing-resistant MFA, a Forrester analyst briefing on the Entra ID passkey default announcement, a summary of NCSC-based passkey-versus-MFA attack comparisons published by NHIMG, and a 2026 MFA statistics roundup citing FIDO Alliance and Okta adoption data.

Each figure retains the exact scope and date given by its source: consumer passkey usage figures, global active-passkey counts, and enterprise authenticator adoption shares from Okta are treated as three separate metrics rather than merged into a single adoption rate, since they measure different populations and different behaviours. Vendor migration dates — the 1 September 2026 default switch and the 1 February 2027 retirement — are drawn directly from Microsoft's own published documentation and cross-checked against Forrester's independent analyst summary of the same announcement.

Where competing commentary discusses adoption "stalling" or new attack vectors without citing verifiable, dated figures, this study has not repeated those claims unless they were independently supported by the sourced data above. No figure, percentage, or date in this piece has been estimated, averaged, or extrapolated beyond what its original source states.

Sources

Every figure in this article traces to the sources below.

  • Microsoft Learn — Entra ID SMS/voice retirement and passkey default dates
  • Microsoft Learn — Secure Future Initiative definition of phishing-resistant MFA
  • Forrester — analysis of Microsoft's Entra ID passkey default announcement
  • NHIMG — summary of NCSC passkey vs traditional MFA live-attack comparison
  • SWIF.AI — 2026 MFA statistics roundup citing FIDO Alliance and Okta data
The 2026 passkey adoption funnel, by data scope
35 billion active passkeysWorldwide count, per FIDO Alliance data cited…249% regular use when availableShare of consumers choosing passkeys over other…114.0% enterprise adoptionOkta phishing-resistant authenticator share, up…
View the data behind this chart
The 2026 passkey adoption funnel, by data scope
LayerDetail
5 billion active passkeysWorldwide count, per FIDO Alliance data cited…
49% regular use when availableShare of consumers choosing passkeys over other…
14.0% enterprise adoptionOkta phishing-resistant authenticator share, up…
Open data

The 9 verified data points behind this study are free to download and reuse with attribution (CC BY 4.0).

Cite as: Servnet Research, “Phishing-Resistant MFA 2026: Passkeys vs OTP Data Study”, servnetuk.com, 2026.

Share
Key takeaways
  • Microsoft Entra ID makes passkeys the default from 1 September 2026, auto-enabling anyone currently on SMS or voice authentication.
  • Microsoft-provided SMS and voice authentication is retired completely on 1 February 2027 — a fixed, five-month transition window.
  • The UK NCSC concludes passkeys outperform traditional MFA specifically against adversary-in-the-middle phishing and session theft attacks seen in the wild.
  • 5 billion passkeys are active worldwide, and 49% of consumers use them regularly when offered — but this is a consumer metric, not enterprise coverage.
  • Enterprise phishing-resistant authenticator adoption at Okta grew 63% in a year (8.6% to 14.0% of users), showing fast growth from a small base.
  • Passkeys, Windows Hello, and FIDO2 are the only methods Microsoft classifies as phishing-resistant — SMS OTP, TOTP, push approval, and email links are explicitly excluded.
Frequently asked

FAQs — Phishing-Resistant MFA 2026

What does "phishing-resistant MFA" actually mean?

Per Microsoft's Secure Future Initiative guidance, it means the authentication is cryptographically bound to the legitimate site or app rather than relying on a secret — a code, link, or approval — that a phisher can intercept and relay. Passkeys, Windows Hello, and FIDO2 qualify; SMS OTP, TOTP, push approval, and email links do not.

When does Microsoft retire SMS and voice MFA in Entra ID?

Microsoft-provided SMS and voice authentication is fully retired on 1 February 2027. Before that, from 1 September 2026, passkeys become the Entra ID default and users currently on SMS or voice are auto-enabled for passkeys, starting the transition.

Are passkeys actually safer than SMS OTP and push approval?

According to the UK NCSC's comparison of passkeys against traditional MFA, passkeys outperform traditional MFA against attacks currently seen in the wild — particularly adversary-in-the-middle phishing and session theft, both of which continue to defeat SMS OTP, TOTP, and push approval.

How widely are passkeys used right now?

Industry tracking cited in 2026 puts active passkeys worldwide at 5 billion, with 49% of consumers saying they use passkeys regularly when the option is offered to them. These are consumer usage figures, distinct from enterprise authentication coverage.

Is enterprise adoption of phishing-resistant MFA keeping pace with consumer use?

Not yet on absolute terms. Okta's own user data shows phishing-resistant authenticator adoption rising from 8.6% to 14.0% of users over a year — a 63% increase, but still a minority share, which is why platform defaults like Entra ID's 2026 switch matter.

Do UK regulated organisations still need hardware keys instead of passkeys?

Many do. Organisations already using smart cards or hardware-bound credentials for regulatory reasons can use FIDO2 hardware keys as the equivalent phishing-resistant method, since it satisfies the same origin-binding definition as passkeys without changing existing issuance processes.

Related

Continue reading

More in Research

Got a question this study didn't answer?

One conversation with an engineer who's done this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111