Skip to content
StateFile.

What changed in your Microsoft 365 tenant without you pressing save?

Microsoft started moving users away from SMS and voice today. We are also checking the sign-in changes that reached tenants over the past few months and what staff may now notice.

10 minute read

Microsoft can change a security setting without an administrator opening the tenant and pressing save. Some settings stay under Microsoft-managed control, while others arrive through a staged rollout or a new enforcement model.

On 1 September 2026, Microsoft began automatically enabling passkeys for users who are enabled for SMS or voice authentication. This doesn't switch SMS off today. It puts those users into the passkey registration campaign before Microsoft retires its own SMS and voice delivery on 1 February 2027.

We have also included three changes from June to August. September is the first clean point to check whether they reached your tenant. These are Microsoft-managed Conditional Access policies, baseline-scope enforcement and system-preferred authentication.

Microsoft started moving SMS and voice users to passkeys today

From 1 September, users enabled for SMS or voice are automatically enabled for passkeys in the Entra Authentication Methods Policy. Microsoft also moves the Registration Campaign to its Microsoft-managed state for those users.

The next time an affected user signs in and completes MFA, Microsoft can ask them to register a passkey. The prompt allows unlimited snoozes for now, so this is not an immediate sign-in block. It is the start of the migration.

Microsoft plans to retire its own SMS and voice delivery on 1 February 2027. A user who still relies on one of those methods will need a passkey or another supported method before then. Organisations that still need SMS or voice will be able to choose a telecom provider through the Microsoft Security Store.

  • Find the users currently enabled for SMS or voice.
  • Decide which passkey type works for each site and device model.
  • Tell affected staff what the registration prompt means before they see it.
  • Confirm passkeys are enabled in the Authentication Methods Policy.
  • Plan the migration before 1 February 2027 rather than waiting for a blocking prompt.

System-preferred authentication may change the first prompt

Microsoft rolled its managed state for system-preferred authentication through tenants during August. The managed state can now choose the strongest registered method for both the first and second authentication step.

A person with a passkey and password may now see the passkey first. They can still choose another allowed method. Conditional Access and Authentication Strengths still decide which methods are accepted for the resource.

Check Entra ID, Authentication methods, Settings, then System-preferred authentication. Microsoft managed applies the ranking to both authentication steps. Enabled applies it to the second step only. Disabled keeps the earlier sign-in order.

Microsoft-managed policies can move from report-only to on

Microsoft creates some Conditional Access policies directly in eligible tenants. They begin in report-only, but Microsoft can turn them on after at least 30 days if an administrator leaves them there. Microsoft says it gives two weeks notice through email and the Microsoft 365 Message center.

Open Conditional Access and check the Created by column for Microsoft. Review the policy impact, sign-in results and exclusions before choosing whether to turn each policy on or off. Make sure the two break-glass accounts are excluded where a policy could block emergency access.

The licence depends on the policy. Standard Conditional Access needs Entra ID P1, which is included in Microsoft 365 Business Premium. Policies using user or sign-in risk need P2.

A June Conditional Access change may now be affecting excluded apps

Microsoft began changing how Conditional Access handles baseline scopes on 15 June. The change affects an All resources policy with a resource exclusion. It only applies when an application requests basic sign-in or directory permissions.

Before the change, those basic scopes could fall outside enforcement when the policy contained a resource exclusion. They can now receive the same MFA or device-compliance challenge as other access. Microsoft is rolling the change through all tenants over several weeks.

Most businesses will never need to name each scope. The practical check is whether an excluded application has started receiving a Conditional Access challenge. Review the All resources policies with exclusions, then check the sign-in logs for the application. If it cannot handle the challenge, confirm whether the exclusion is still needed before retaining the earlier behaviour.

The separate Defender Endpoint investigation experience ended today

From 1 September, Microsoft Defender for Endpoint no longer offers a separate Automated Investigation and Response screen. Administrators also cannot trigger one manually. Automatic detection and response remains inside the normal Defender for Endpoint protection stack.

For an on-demand endpoint investigation, Microsoft now directs administrators to run a full antivirus scan. This change only applies to Defender for Endpoint. Defender for Office 365 automated investigations remain available.

Older Entra Connect Sync servers stop working on 30 September

This only affects businesses that synchronise an on-premises Active Directory through Microsoft Entra Connect Sync. Microsoft says every sync service below version 2.5.79.0 will stop working on 30 September 2026.

Check the version on the Entra Connect server now and upgrade it before the deadline. Microsoft recommends moving to the latest release because it includes current security fixes. Test the upgrade and confirm that users, groups and password changes still synchronise afterwards.

Microsoft Cloud Sync is not part of this deadline. If you are unsure which service you use, check the Microsoft Entra admin centre before changing the server.

The incident: a real Microsoft sign-in page still helped the attacker

Microsoft published its CaptiveCrunch investigation on 31 July. The campaign manipulated traffic on shared networks used by hotels and other venues. Some travellers were redirected into device-code phishing and fake update prompts.

In the device-code path, the victim opened a legitimate Microsoft sign-in page and entered a code supplied by the attacker. The page was real. The code connected the successful sign-in back to the attacker. Microsoft observed the campaign leading to Entra device registration and Microsoft 365 data collection.

The direct control is to block device-code flow unless a documented device or application needs it. Microsoft now includes a block-device-code-flow policy in its managed Conditional Access set. Staff should also know that a real Microsoft page does not make an unexpected code safe to enter.

The September check should take less than an hour

We would use the hour to record the live state before changing anything. This gives you a list of affected users and policies before the change becomes a support call.

  • List users enabled for SMS or voice and count how many have another method.
  • Record the System-preferred authentication state and who is in scope.
  • Filter Conditional Access by policies created by Microsoft and record each state.
  • Check All resources policies for application exclusions.
  • If you use Entra Connect Sync, record its version and upgrade it before 30 September if required.
  • Confirm device-code flow is blocked or document the exact system that still needs it.

Record what Microsoft changed before changing it again

Start with the people still using SMS or voice because Microsoft began moving them into passkey registration today. Then record the system-preferred authentication state and every Conditional Access policy created by Microsoft.

The September check shows what is live in your tenant. You can then plan the passkey migration, remove unnecessary exclusions and test the sign-in paths that need attention.

Questions people ask

Did Microsoft turn SMS and voice off on 1 September 2026?
No. Microsoft began enabling passkeys and its passkey registration campaign for users enabled for SMS or voice. Microsoft plans to retire its own SMS and voice delivery on 1 February 2027.
Will staff be locked out if they dismiss the passkey prompt?
Not during the current registration campaign. Microsoft says the prompt allows unlimited snoozes. The blocking change is planned for 1 February 2027 if SMS or voice is still the only available method.
Does system-preferred authentication override Conditional Access?
No. It chooses which registered method to offer first. Conditional Access and Authentication Strengths still decide which methods satisfy the rule.
Can we edit a Microsoft-managed Conditional Access policy?
You can change its state and exclusions. Microsoft does not let you rename or delete it. Duplicate the policy if you need to change more of its configuration.
Does blocking device-code flow break Microsoft 365?
Most users do not need it. Some Teams Rooms, printers, command-line tools and other limited-input devices may use it. Check the sign-in logs and document the required workflow before making an exception.

Sources

All posts

Know where your risks are.

See where your risks are, and get simple advice on what to fix first.

Free, and no obligation. If an audit is not right for you, we will say so.