Defined implementation
Keep everyone signing in after Microsoft stops sending phone codes.
The people still signing in with a phone code are found and moved to an approved method. A small group goes first. Take-up is measured against the list, and every exception is written down with an owner.
PricePrice fixed after a short scope call.
DeliveryThe deadline is Microsoft retires its own text-message and phone-call codes on February 1, 2027. The delivery calendar is confirmed against it before anything is signed.
What you receive · illustrative sample
A move is complete when the checks agree.
Illustrative excerpt from a migration acceptance record. The actual checks follow the workloads in your scope.
| Check | Evidence | Recorded result |
|---|---|---|
| Mailbox reconciliation | Source/destination totals and exceptions | Sample: checked |
| Mail flow and sign-in | Agreed user and shared-mailbox tests | Sample: passed |
| Remaining exception | Archive item assigned to client owner | Sample: accepted exception |
Related delivery record
SharePoint migration troubleshooting and reconciliation
Read what changed and how it was checked ↗Engagement context
When this engagement applies.
Microsoft began enabling passkeys and registration prompts for SMS/voice-enabled users from September 1, 2026. Microsoft-provided SMS and voice delivery retires from February 1, 2027.
Related source documentation
Microsoft Entra: SMS and voice authentication retirementScope considerations
- One Microsoft 365 tenant
- Client owns end-user support
- Hardware keys quoted separately
The defined work
Engagement scope.
- 01
AZ combines registration and usage reports with policy and device checks to build an affected-user list. Registration data alone does not prove that a user will be locked out. The agreed list becomes the rollout checklist.
- 02
The sign-in settings are set to the methods you agreed. The old ones are phased out on a schedule, not switched off underneath people.
- 03
A small test group goes first. The problems that only show up with real people — shared devices, front-desk accounts, field staff with no company phone — are found there, not in the full rollout.
- 04
Registration is driven through the agreed communications and measured against the affected list until the remaining gap is a named set of people, not a percentage.
- 05
Accounts that genuinely cannot hold a passkey get a written exception, with an owner, a second safeguard in place of the missing one, and a date to look at it again.
Acceptance
Completion has an agreed standard.
Done when nobody is left on a phone code, or every account still on one has a written exception with an owner, a second safeguard, and a review date.
The affected-user list is produced from the tenant and agreed as the denominator
The authentication methods policy is in its approved enforcement state
The pilot ring has completed registration and its defects are closed
Registration is measured against the affected list, with the remaining gap named person by person
Every exception carries an owner, a reason, a second safeguard, and a date to review it
Commercial basis
Price, scope and timing are considered together.
Engagement price
Price fixed after a short scope call.
The price is agreed in writing before any work starts and before anyone is given access. The call itself costs nothing. What moves the number:
What determines the scope
- How many users are still registered on SMS or voice
- Number of pilot and rollout rings
- Whether hardware security keys are procured and enrolled as part of the work
- Whether external and B2B guest accounts are in scope
- Number of shared, kiosk, or device-less accounts needing an exception path
Delivery calendar
The deadline is Microsoft retires its own text-message and phone-call codes on February 1, 2027. The delivery calendar is confirmed against it before anything is signed.
How engagements workScope & responsibilities
The full engagement boundary.
Review the exclusions, required client participation, change controls and operational handover for this engagement.
Exclusions
- Hardware security key purchase
- Help desk and end-user registration support
- Third-party MFA or identity-provider migration
- Broad Conditional Access redesign — that is MFA & Conditional Access Hardening
- Any guarantee about Microsoft’s own timelines, which are Microsoft’s to change
Client responsibilities
- Distribute the registration communications
- Own the help desk and end-user support through the rollout
- Approve the pilot ring and the enforcement date
- Procure hardware security keys where the design calls for them
- Nominate an owner for every exception that stays open
Change and rollback method
- The methods policy is staged: target methods enabled first, legacy methods retired only after the pilot ring is registered.
- Rollback is the previous policy state, captured before the first change and re-appliable within one change window.
- Emergency-access accounts are confirmed excluded and alerting before any enforcement date is set.
Operational record and handover
- The affected-user list, as it stood at kickoff and at handover
- The authentication methods policy, before and after
- Take-up measured against the list of people affected
- The exception register, with owners and review dates
- The communications actually sent, and when
Before you commit
A clear first step.
You stay in control.
Start with the problem and the result you need. The initial fit conversation is free and does not require access to your systems.
Check client feedback on Upwork ↗Prefer to contract through Upwork? Contact Alwatheq there. Existing Upwork engagements continue through Upwork.
Who will actually do the work?
Alwatheq Zboun leads the scope, technical work and handover. If a specialist collaborator is needed, their role is agreed with you before work starts. Your proposal names the responsibilities and delivery windows.
What happens before you get access?
We agree the scope, fee and completion checks in writing. Access uses named accounts and only the permissions the work requires. Approved access is reviewed and removed at handover.
How do we know the change worked?
Your scope defines the pilot, test cases and acceptance checks. Results and exceptions are recorded. Recovery options and their limits are agreed before production changes; a failed check is addressed before the next approved stage.
Will we need an ongoing retainer?
A defined project can end at handover. Your team receives the agreed configuration records, runbook and walkthrough. Any limited support period is written into the proposal; ongoing support or additional work is a separate agreement.
Discuss this engagement
Put the scope in context.
Describe the problem, systems and deadline. Alwatheq will review the fit and the scope questions before preparing a written proposal.
Plan the Passkey Rollout