Passkey Rollout: 9 Essential Steps to Stronger Security

Every managed service provider supporting UK and EU clients is running out of road on SMS codes, and a well-planned passkey rollout is the only credible replacement. Microsoft has made passkeys the default authentication experience in Entra ID from September 2026, and the telecom delivery behind SMS and voice codes is being retired in early 2027. That turns a passkey rollout from a security-maturity nice-to-have into a migration with a date attached — repeated across every tenant on your books.

Why passkey rollout moved up the queue in 2026

For most of the last five years, passwordless authentication sat in the “we should look at that” column. Two things changed that. First, Microsoft announced that passkeys become the default authentication method in Entra ID, with users already enabled for SMS or voice being enabled for passkeys automatically and prompted to register at their next multifactor prompt. Second, Microsoft-provided telecom delivery for SMS and voice codes is scheduled to retire on 1 February 2027, after which organisations still leaning on those factors need their own telecom arrangement.

The security case was already strong. Passkeys are bound to the site or tenant they were created for, so the credential simply does not present itself on a lookalike domain. That removes the single most productive attack against your clients: the adversary-in-the-middle phishing kit that harvests a password and relays a one-time code within seconds. The FIDO Alliance reported roughly five billion passkeys in active use worldwide in its April 2026 research, which tells you the consumer-side plumbing is mature. The enterprise side is where the work sits.

For an MSP, the deadline arithmetic is unforgiving. A passkey rollout for one tenant is a fortnight of steady effort. A passkey rollout across forty tenants, each with its own conditional access baseline, device estate and tolerance for disruption, is a programme. Nobody has that programme in this quarter’s capacity plan, which is precisely why it needs naming, sizing and staffing now rather than in January.

What a passkey rollout actually involves

Fingerprint sensor on a laptop, the device biometric that unlocks a passkey rollout for end users
Platform authenticators — the fingerprint sensor or face unlock already built into the laptop — carry most of the enrolment load in a passkey rollout. Photo by Repat, licensed CC BY-SA 3.0, via Wikimedia Commons.

It helps to be precise about scope, because “turn on passkeys” hides at least four separate workstreams. A passkey rollout covers the authentication method policy in the tenant, the enrolment journey for every user, the hardware provisioning for anyone without a suitable device, and the eventual removal of the weaker factors that passkeys replace. Skip the last one and you have added a method rather than improved security.

There is also a choice to make between synced passkeys, which live in a platform or password-manager credential store and follow the user across devices, and device-bound passkeys on a security key or the machine’s own hardware. Synced passkeys are far easier to roll out at scale and are appropriate for most staff. Device-bound keys belong on privileged accounts, shared operational logins and anywhere a client’s regulator will ask how the credential is protected. Most MSP tenants end up with both, and a rollout plan that pretends otherwise gets rewritten in week three.

Finally, a passkey rollout touches the service desk more than any other identity change. Enrolment questions, lost devices, new starters, people who upgrade a phone on a Saturday — all of it arrives as tickets. Budgeting for that support load is part of the project, not an afterthought.

Passkey rollout steps 1-3: inventory, pilot, policy

Step 1: Inventory the factors and the devices you actually have

Start with the awkward truth: you do not know which of your users are on SMS until you pull the report. Export registered authentication methods per tenant, then cross-reference against the device estate. You are looking for three populations — users with a modern platform authenticator, users on hardware too old or too locked down to enrol, and users with no company-managed device at all. The third group is small and will consume a disproportionate share of the passkey rollout effort.

Step 2: Pilot with a group that will tell you the truth

Pick twenty to thirty users spanning a mix of roles and device types, not just the IT team. The IT team enrols flawlessly and teaches you nothing. What you want from the pilot is the list of small frictions — the browser that prompts oddly, the line-of-business app that still forces a password, the meeting room PC nobody can enrol. Every one of those becomes a known-issue entry before the wider passkey rollout begins.

Step 3: Write the authentication method policy before you scale

Decide, per tenant, which methods are enabled, which are the default, and which are on notice. Document the intended end state — typically passkeys plus a device-bound fallback for break-glass — and get the client to sign it. A passkey rollout without an agreed target state drifts, because every exception request looks reasonable in isolation.

Passkey rollout steps 4-6: enrolment, spares, shared devices

Step 4: Drive enrolment with campaigns, not emails

Registration campaigns that nudge users at sign-in outperform any amount of internal comms, because they meet people at the moment they are already authenticating. Set a realistic snooze allowance, watch the enrolment curve weekly, and chase the tail by exception. In practice a passkey rollout gets to about 70% on the campaign alone; the last 30% needs a named person working a list.

Step 5: Sort out spare-key logistics early

Anyone whose passkey lives only on one device is one dropped phone away from a lockout. Decide who gets a spare security key, who holds the stock, how keys are shipped to remote staff, and what the replacement SLA is. This is dull logistics, and it is the part of a passkey rollout most likely to be discovered late — usually by a director on a Friday afternoon.

Step 6: Handle shared and kiosk devices deliberately

Shop floors, wards, warehouses and reception desks do not fit the one-user-one-device model. Options include device-bound keys held by a supervisor, per-shift sign-in with a security key, or leaving those workflows on a documented exception with compensating controls. Whatever you choose, write it down; the exception list is the part of the passkey rollout an auditor will ask about first.

Passkey rollout steps 7-9: retire weak factors and prove it

Step 7: Remove SMS and voice once coverage is real

Removing weak factors is where the security benefit actually lands, and it is the step most often deferred indefinitely. Set a coverage threshold — say, 95% of users enrolled with at least two passkeys or a passkey plus a hardware key — and disable SMS and voice for everyone past it. Given the 2027 telecom retirement, a passkey rollout that stops short of this step simply defers the same work into a worse window.

Step 8: Re-check conditional access and legacy authentication

Strong factors do nothing if a legacy protocol lets an attacker skip them. Review sign-in logs for basic authentication, app passwords and any bypass built during a past incident. Align conditional access with the new method policy so that phishing-resistant authentication is genuinely required, not merely available. Guidance from the UK National Cyber Security Centre on multi-factor authentication is a useful reference point when explaining the change to a client board.

Step 9: Produce the evidence pack

Enrolment percentages per tenant, methods disabled and when, exception register, break-glass test results. Clients renewing cyber insurance or answering a supply-chain questionnaire will need this, and assembling it retrospectively costs three times as much. Treat the evidence pack as a deliverable of the passkey rollout rather than a favour you do later.

Where a passkey rollout usually stalls

Three patterns account for most stalled programmes. The first is the pilot that never ends: enrolment reaches a comfortable majority, the urgency fades, and SMS stays enabled for another year. The second is the exception queue with no owner — twenty users who could not enrol on day one become a permanent parallel estate. The third is the multi-tenant tax. Doing tenant one is interesting; doing tenants twelve through forty is repetitive, and repetitive work loses to inbound tickets every single time.

The common thread is not technical difficulty. The Entra configuration for a passkey rollout is genuinely straightforward and well documented. What is scarce is uninterrupted hours from someone who knows identity, can talk to end users patiently, and will still be working the same list in six weeks. Senior engineers get pulled onto escalations; it is exactly the kind of work that gets pushed to next sprint without anyone deciding to push it.

Staffing a passkey rollout without pausing BAU

This is the shape of work outstaffing suits best: defined, repeatable, evidence-generating, and needing continuity rather than heroics. OutsourceZA places skilled South African engineers and security analysts into UK and EU teams as dedicated capacity, typically at 40-60% of the cost of an equivalent local hire. South Africa sits in the UK/EU timezone band, so an outstaffed engineer running your passkey rollout is on the same calls, in the same ticket queue and available for the same end-user enrolment clinics as your in-house team — not handing over notes at midnight.

In practice that means one person owning tenant-by-tenant progress: running the reports, driving the campaign, working the exception list, shipping the spare keys and assembling the evidence pack, while your senior engineers stay on escalations and project work. Our engineers are MSP-ready and familiar with the Microsoft 365 and Entra tooling most UK MSPs run, so the ramp is measured in days rather than months. Outstaffing also flexes: the programme is finite, and the same engineer can move onto the next programme when it completes.

If you want to see the calibre of people we place, our current IT roles give a sense of the talent pool, and you can talk to us about scoping a passkey rollout across your client base.

Passkey rollout FAQ

How long does a passkey rollout take for one tenant?

For a 100-200 seat tenant, plan on two weeks of concentrated work to reach majority enrolment, then four to six weeks of tail-chasing and exception handling before you can safely disable SMS. Larger or more fragmented estates take longer, mostly because of shared devices and non-standard hardware.

Do users need a hardware security key?

Most do not. The fingerprint sensor or face unlock already in a modern laptop or phone acts as the authenticator, with the passkey synced through the platform account. Hardware keys are worth the cost for administrators, break-glass accounts, shared operational logins and users on unsupported devices.

What happens to break-glass accounts during a passkey rollout?

They need their own plan. Emergency access accounts are usually excluded from conditional access and cannot depend on a single user’s device. The usual pattern is two device-bound hardware keys stored separately, tested quarterly, with the test result recorded in the evidence pack.

Can we keep SMS as a backup method?

You can, but it undermines the point — an attacker will simply target the weakest enabled method. Given that Microsoft-provided telecom delivery for SMS and voice retires in February 2027, keeping it as a permanent fallback is also a plan with an expiry date. Better to move the fallback to a second passkey or a hardware key.

How do we handle staff without a company device?

Either issue a hardware security key, which works from any machine, or provision a managed device. Both cost money, and a passkey rollout is the moment that cost becomes visible. Identify this group during the inventory step so the budget conversation happens before the deadline, not during it.

Is a passkey rollout worth it for a small client?

Yes, and it is often easier. A 25-seat client can be fully enrolled in a fortnight with far fewer exceptions, and the credential-phishing risk that passkeys remove does not scale down with headcount. Small clients are frequently the ones targeted precisely because their controls are assumed to be weaker.

The deadline is the useful part of all this. A passkey rollout has been the right thing to do for years; it now has a date, a default and a retirement notice behind it. Decide who owns it before the enrolment prompts start appearing in your clients’ tenants without warning — and make sure that owner has the hours to finish what they start.

Book your consultation

Book a chat with Niel or Johan so we can understand exactly what (and who) you need for your business to succeed. It’s also a great time to ask any questions you may have. See you soon!