Defined implementation

Keep everyone signing in after Microsoft stops sending phone codes.

The people still signing in with a phone code are found and moved to an approved method. A small group goes first. Take-up is measured against the list, and every exception is written down with an owner.

PricePrice fixed after a short scope call.

DeliveryThe deadline is Microsoft retires its own text-message and phone-call codes on February 1, 2027. The delivery calendar is confirmed against it before anything is signed.

What you receive · illustrative sample

A move is complete when the checks agree.

Illustrative excerpt from a migration acceptance record. The actual checks follow the workloads in your scope.

CheckEvidenceRecorded result
Mailbox reconciliationSource/destination totals and exceptionsSample: checked
Mail flow and sign-inAgreed user and shared-mailbox testsSample: passed
Remaining exceptionArchive item assigned to client ownerSample: accepted exception

Related delivery record

SharePoint migration troubleshooting and reconciliation

Read what changed and how it was checked ↗

Engagement context

When this engagement applies.

Microsoft began enabling passkeys and registration prompts for SMS/voice-enabled users from September 1, 2026. Microsoft-provided SMS and voice delivery retires from February 1, 2027.

Scope considerations

  • One Microsoft 365 tenant
  • Client owns end-user support
  • Hardware keys quoted separately

The defined work

Engagement scope.

  1. 01

    AZ combines registration and usage reports with policy and device checks to build an affected-user list. Registration data alone does not prove that a user will be locked out. The agreed list becomes the rollout checklist.

  2. 02

    The sign-in settings are set to the methods you agreed. The old ones are phased out on a schedule, not switched off underneath people.

  3. 03

    A small test group goes first. The problems that only show up with real people — shared devices, front-desk accounts, field staff with no company phone — are found there, not in the full rollout.

  4. 04

    Registration is driven through the agreed communications and measured against the affected list until the remaining gap is a named set of people, not a percentage.

  5. 05

    Accounts that genuinely cannot hold a passkey get a written exception, with an owner, a second safeguard in place of the missing one, and a date to look at it again.

Acceptance

Completion has an agreed standard.

Done when nobody is left on a phone code, or every account still on one has a written exception with an owner, a second safeguard, and a review date.

  • The affected-user list is produced from the tenant and agreed as the denominator

  • The authentication methods policy is in its approved enforcement state

  • The pilot ring has completed registration and its defects are closed

  • Registration is measured against the affected list, with the remaining gap named person by person

  • Every exception carries an owner, a reason, a second safeguard, and a date to review it

Commercial basis

Price, scope and timing are considered together.

Engagement price

Price fixed after a short scope call.

The price is agreed in writing before any work starts and before anyone is given access. The call itself costs nothing. What moves the number:

What determines the scope

  • How many users are still registered on SMS or voice
  • Number of pilot and rollout rings
  • Whether hardware security keys are procured and enrolled as part of the work
  • Whether external and B2B guest accounts are in scope
  • Number of shared, kiosk, or device-less accounts needing an exception path

Delivery calendar

The deadline is Microsoft retires its own text-message and phone-call codes on February 1, 2027. The delivery calendar is confirmed against it before anything is signed.

How engagements work

Scope & responsibilities

The full engagement boundary.

Review the exclusions, required client participation, change controls and operational handover for this engagement.

Exclusions
  • Hardware security key purchase
  • Help desk and end-user registration support
  • Third-party MFA or identity-provider migration
  • Broad Conditional Access redesign — that is MFA & Conditional Access Hardening
  • Any guarantee about Microsoft’s own timelines, which are Microsoft’s to change
Client responsibilities
  • Distribute the registration communications
  • Own the help desk and end-user support through the rollout
  • Approve the pilot ring and the enforcement date
  • Procure hardware security keys where the design calls for them
  • Nominate an owner for every exception that stays open
Change and rollback method
  • The methods policy is staged: target methods enabled first, legacy methods retired only after the pilot ring is registered.
  • Rollback is the previous policy state, captured before the first change and re-appliable within one change window.
  • Emergency-access accounts are confirmed excluded and alerting before any enforcement date is set.
Operational record and handover
  • The affected-user list, as it stood at kickoff and at handover
  • The authentication methods policy, before and after
  • Take-up measured against the list of people affected
  • The exception register, with owners and review dates
  • The communications actually sent, and when

Before you commit

A clear first step.
You stay in control.

Start with the problem and the result you need. The initial fit conversation is free and does not require access to your systems.

Check client feedback on Upwork ↗

Prefer to contract through Upwork? Contact Alwatheq there. Existing Upwork engagements continue through Upwork.

Who will actually do the work?

Alwatheq Zboun leads the scope, technical work and handover. If a specialist collaborator is needed, their role is agreed with you before work starts. Your proposal names the responsibilities and delivery windows.

What happens before you get access?

We agree the scope, fee and completion checks in writing. Access uses named accounts and only the permissions the work requires. Approved access is reviewed and removed at handover.

How do we know the change worked?

Your scope defines the pilot, test cases and acceptance checks. Results and exceptions are recorded. Recovery options and their limits are agreed before production changes; a failed check is addressed before the next approved stage.

Will we need an ongoing retainer?

A defined project can end at handover. Your team receives the agreed configuration records, runbook and walkthrough. Any limited support period is written into the proposal; ongoing support or additional work is a separate agreement.

Discuss the fit ↗Read the delivery process ↗

Discuss this engagement

Put the scope in context.

Describe the problem, systems and deadline. Alwatheq will review the fit and the scope questions before preparing a written proposal.

Plan the Passkey Rollout