Rollouts that lock people out
Policy changes pushed to everyone at once leave users stranded and the help desk overwhelmed.
Microsoft Entra Identity Security
MFA and passkey adoption, Conditional Access, administrative access and account recovery need hardening, and legitimate users still need to sign in. We plan the change with you, pilot it with named test users, validate sign-in and recovery, and hand over the plan for everyone else.
Defined scope. Tested changes. Practical handover.
Microsoft sign-in change
Microsoft is retiring its built-in SMS and voice sign-in codes for Entra ID: February 1, 2027 for most users, and July 1, 2027 for Global Administrators and external users. People with a compatible device are being prompted to set up a passkey. Shared devices, admin and emergency access accounts, guests and password reset usually need a plan.
Source: Microsoft Learn, checked September 25, 2026.
Who it’s for
Problems we solve
Policy changes pushed to everyone at once leave users stranded and the help desk overwhelmed.
Standing admin rights and untested emergency accounts are hard to fix once something goes wrong.
Lost devices and reset requests have no tested process, so temporary exceptions become permanent.
What we do
We review your Microsoft Entra ID authentication methods and Conditional Access policies, agree the target state and a controlled rollout plan, and pilot MFA, passkey or passwordless changes with named personas. Where licensed and in scope, we separate administrative roles and set up privileged access. We test real cases (a normal sign-in, a sign-in that should be blocked and recovery from a lost device), document emergency access and recovery procedures, and hand over the plan for the wider rollout.
What you get
Out of scope
Done when
The pilot or scoped rollout passes the agreed test cases, emergency access and recovery are documented and tested, and you sign off on the open exceptions.
What we need from you
Approved admin access for the work, a pilot group and a sponsor, your licensing details, and your current emergency access arrangements.
FAQ
Not automatically. Microsoft says people whose only method is SMS or voice will be asked to register a passkey before they can continue. The people who get stuck are the ones without a device that can hold a passkey, and that is what the pilot plans for.
Not always. Shared devices, people without a compatible phone and some applications need a different method. The pilot finds those cases, and the plan records them as exceptions.
Microsoft lets organizations that still need SMS or voice connect a third-party telephony provider through the Microsoft Security Store. We can help you decide where that is worth it.
This service owns identity policy and rollout work. If an Azure findings list includes identity items, we agree one scope owner, so the same work is never planned or billed twice.
Through named, least-privilege access that you approve and can remove at handover. We never ask for shared passwords.
How it works
01
We review the environment and agree the scope, priorities, acceptance tests and change approach with you.
02
We make the approved changes under your change control, with rollback or recovery plans where appropriate.
03
We test against the agreed acceptance criteria. A failed test is recorded, not hidden.
04
You get the documentation, evidence and runbooks, plus a written list of anything still open.
No pitch · Canada-wide