Microsoft-managed SMS and voice MFA will stop working on February 1, 2027. That deadline makes passkey planning urgent, but enabling a new authentication method is only the first milestone.
In this episode of Entra.Chat, Merill speaks with Jai Maharaj, Product Manager at Microsoft, about the practical journey from legacy MFA to a passwordless Microsoft Entra environment. Jai explains what is actually being retired, why organizations can still use a customer-managed telecom provider, and how passkey profiles support synced and device-bound passkeys for different user personas.
The user-experience case is compelling: Microsoft reports roughly 69 seconds for password plus traditional MFA compared with about three seconds for a synced passkey. The security case is stronger still. Passkeys resist phishing by design, but Jai stresses that deploying them does not make an organization phishing-resistant until it enforces the right authentication strength and addresses the passwords and legacy applications still in the environment.
The conversation then follows the complete identity lifecycle. How do you ensure the right person receives a passkey during onboarding? How do you verify someone requesting a sensitive role? How do you recover an account without relying on knowledge-based help-desk questions? Jai connects those scenarios to Microsoft Entra Verified ID, verifiable credentials, Face Check, identity verification partners, and self-service account recovery.
Sponsored by
Scan, Score, and Secure Your Applications in Entra
Application identities represent one of the largest attack surfaces in Entra and are often among the least consistently governed. ENow AppGov Score helps IT and identity teams understand where risk exists. Its 25-check assessment evaluates Entra ID application integrations against Microsoft-recommended governance practices, analyzing:
App registrations and enterprise apps for excessive permissions
Expired or unmanaged secrets and certificates
Risky consent grants
Privileged service principals
Results are delivered as a clear, defensible risk score with actionable findings. No scripts. No manual inventory. Just a fast, read-only scan that reveals app sprawl, identity misconfigurations, and blast radius so you can prioritize remediation and strengthen your security posture.
Subscribe with your favorite podcast player or watch on YouTube 👇
About Jai Maharaj
Jai Maharaj is a Senior Product Manager at Microsoft. He works with customers and engineering teams across Microsoft Entra, with experience spanning ID Governance, Verified ID, External ID, and passkeys. He helps enterprise and public-sector organizations move from legacy authentication methods to phishing-resistant authentication.
Related Links
Microsoft-managed SMS and voice retirement timeline (discussed at 02:19 and 06:31) - https://learn.microsoft.com/entra/identity/authentication/concept-sms-voice-retirement
Customer-managed telecom provider FAQ (mentioned at 03:41 and 07:13) - https://learn.microsoft.com/entra/identity/authentication/phone-providers-faq
Passkey profiles, synced passkeys, and device-bound passkeys (discussed at 09:44) - https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-passkeys-fido2#passkey-profiles
Passkey concepts and Microsoft performance figures (mentioned at 14:22) - https://learn.microsoft.com/entra/identity/authentication/concept-authentication-passkeys-fido2#what-are-passkeys
Microsoft Entra Verified ID Face Check (introduced at 31:57) - https://learn.microsoft.com/entra/verified-id/using-facecheck
ASD/ACSC Essential Eight maturity model (mentioned at 33:41) - https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model
Microsoft Entra account recovery overview (discussed at 36:59) - https://learn.microsoft.com/entra/identity/authentication/concept-account-recovery-overview
Verified ID identity verification partners (discussed at 37:12) - https://learn.microsoft.com/entra/verified-id/idv-partners
Microsoft Entra licensing (discussed at 39:27) - https://learn.microsoft.com/entra/fundamentals/licensing
Verified ID and Face Check pricing model (discussed at 39:27) - https://learn.microsoft.com/entra/verified-id/verified-id-pricing
Deploy phishing-resistant passwordless authentication (mentioned at 52:34) - https://learn.microsoft.com/entra/identity/authentication/how-to-deploy-phishing-resistant-passwordless-authentication
Related Entra.Chat Episodes
Microsoft Is Auto-Enabling Passkeys in March 2026 - https://entra.news/p/microsoft-is-auto-enabling-passkeys
Mastering Microsoft Entra ID: Real-World Passkey Deployment Tips - https://entra.news/p/mastering-microsoft-entra-id-real
Entra Ignite Recap: Synced Passkeys, Agent ID & The Future of Identity - https://entra.news/p/entra-ignite-recap-synced-passkeys
Chapters
00:00 Intro
02:19 Why Microsoft Is Retiring Managed SMS and Voice
03:32 What the February 2027 Deadline Means
09:27 Synced vs Device-Bound Passkeys
14:22 From 69 Seconds to Three
19:02 Making Passkeys Easier for Users
23:14 Customer Passkey Deployment Lessons
28:41 The Secure Bootstrapping Problem
31:57 Verified ID and Face Check
33:41 Essential Eight and High-Value Access
36:24 Self-Service Account Recovery
39:27 Licensing and Recovery Economics
44:45 Why Face Check Augments Passkeys
49:40 Enforce Phishing Resistance and Build a Roadmap
Podcast Apps
Apple Podcast - https://entra.chat/apple
YouTube - https://entra.chat/youtube
Spotify - https://entra.chat/spotify
Overcast - https://entra.chat/overcast
Pocketcast - https://entra.chat/pocketcast
Others - https://entra.chat/rss
Merill’s socials
YouTube - youtube.com/@merillx
LinkedIn - linkedin.com/in/merill
Twitter - twitter.com/merill
TikTok - tiktok.com/@merillf
Bluesky - bsky.app/profile/merill.net
Mastodon - infosec.exchange/@merill
Threads - threads.net/@merillf
GitHub - github.com/merill












