Table of Contents
What Is Changing
Who Is Affected
Action Required: Register a Passkey
Available Passkey Options
Important Setup Information
Support and Questions
This article is to inform Baker College account holders of changes to the SMS text message and voice call methods used for Multi-Factor Authentication (MFA). This transition is a direct result of Microsoft making passkeys the default authentication experience and retiring Microsoft-provided SMS and voice verification.
A passkey is a sign-in credential stored on a compatible device, in a password manager, or on a compatible physical security key. Passkeys provide stronger protection against phishing and other attempts to gain unauthorized access to your account.
Beginning September 1, 2026, Microsoft may prompt users who have SMS or voice authentication enabled to register a passkey after they complete their normal MFA verification.
During the transition period, the passkey registration prompt can be temporarily skipped by selecting Skip for now. If you skip the prompt, it may appear again during a future sign-in.
Beginning Monday, February 1, 2027, SMS text messages and voice calls will no longer be available as authentication methods for Baker College accounts. Account holders whose only available MFA method is SMS or voice will receive a blocking registration prompt and must register a passkey before they can continue signing in.
Return to top.
This change primarily affects Baker College account holders who have SMS text messages or voice calls enabled for MFA.
If SMS or voice is your only registered MFA method, you must register a passkey before Monday, February 1, 2027.
If you have another working authentication method, Microsoft may still prompt you to register a passkey. You should complete the registration from an appropriate device or select Skip for now when that option is available.
Return to top.
Account holders who rely on SMS or voice as their only MFA method must register a passkey before Monday, February 1, 2027.
Register your passkey only on a personal device or an individually assigned Baker College device. Do not register a passkey on a shared, public, or lab computer.
If the prompt appears on a shared or public device and Skip for now is available, select it and complete the process later from an appropriate device. Beginning February 1, 2027, account holders whose only MFA method is SMS or voice may receive a blocking prompt that cannot be skipped. Contact the IT Help Desk if this occurs while you are using a shared or public device.
For setup instructions, review the Multi-Factor Authentication (MFA) article.
If you cannot use any of the available passkey options, contact the IT Help Desk before February 1, 2027.
Return to top.
Baker College supports the following passkey options:
- Microsoft Authenticator: A device-bound passkey stored in the Microsoft Authenticator app on a compatible mobile device.
- Apple Passwords/iCloud Keychain: A synced passkey stored in Apple Passwords/iCloud Keychain that can sync across compatible Apple devices.
- FIDO2 security key: A device-bound passkey stored on a compatible physical security key that connects through USB or another supported connection method.
- Google Password Manager: A synced passkey stored in Google Password Manager that can sync across compatible devices.
Traditional code-generating hardware tokens are not supported as a Baker College MFA method. FIDO2-compatible security keys are supported passkeys and are configured differently from code-generating hardware tokens.
Return to top.
- Do not register a passkey on a shared, public, or lab device.
- Most passkey providers require a device screen lock, such as a PIN, fingerprint, or facial recognition.
- Passkeys stored in Apple Passwords/iCloud Keychain or Google Password Manager can sync through the Apple or Google account connected to that service. Confirm that you are using the intended account before saving the passkey.
- A passkey stored in Microsoft Authenticator is tied to that mobile device and does not automatically transfer to a replacement device. Register another working authentication method before replacing or resetting the device.
- A FIDO2 passkey remains stored on the physical security key, not on the computer used to register it. Store the security key safely and register another working method before replacing or discarding it.
- Bluetooth and an active internet connection must be enabled on both devices when you use a phone-based passkey to sign in on another device. The devices must also be near one another.
- Do not remove an existing working authentication method until you have successfully registered and tested your passkey.
- Microsoft may display the passkey registration prompt again when you use a different device or browser. This does not necessarily mean that your original passkey registration failed.
- If your device or security key is lost, replaced, or no longer available, use another registered authentication method if one is available or contact the IT Help Desk.
- Microsoft’s retirement of SMS and voice verification also applies to Self-Service Password Reset. Review the Setting Up Recovery Methods for Self-Service Password Reset article for current information about managing your recovery methods. Baker College will update those instructions as this transition progresses.
Return to top.
Account holders who have questions about this transition or need help registering a passkey may contact the Baker College IT Help Desk (ITSC).
Email: ITSC@baker.edu
Phone: (800) 645-8350
Return to top.