Microsoft Entra Identity Security

Harden access and roll out identity changes with a tested recovery path.

MFA and passkey adoption, Conditional Access, administrative access and account recovery need hardening, and legitimate users still need to sign in. We plan the change with you, pilot it with named test users, validate sign-in and recovery, and hand over the plan for everyone else.

Defined scope. Tested changes. Practical handover.

Microsoft sign-in change

Microsoft is retiring its built-in SMS and voice sign-in codes for Entra ID: February 1, 2027 for most users, and July 1, 2027 for Global Administrators and external users. People with a compatible device are being prompted to set up a passkey. Shared devices, admin and emergency access accounts, guests and password reset usually need a plan.

Source: Microsoft Learn, checked September 25, 2026.

Who it’s for

Is this service right for you?

  • Some of your people still sign in with SMS or voice codes
  • Conditional Access policies have grown inconsistent or untested
  • Admin and emergency access accounts need their own plan
  • You have shared devices, frontline staff or people without a compatible phone
  • Guests or external users sign in to your tenant
  • A customer or insurer is asking for phishing-resistant MFA

Problems we solve

What’s getting in the way

Rollouts that lock people out

Policy changes pushed to everyone at once leave users stranded and the help desk overwhelmed.

Admin access left wide open

Standing admin rights and untested emergency accounts are hard to fix once something goes wrong.

Recovery as an afterthought

Lost devices and reset requests have no tested process, so temporary exceptions become permanent.

What we do

What’s included

We review your Microsoft Entra ID authentication methods and Conditional Access policies, agree the target state and a controlled rollout plan, and pilot MFA, passkey or passwordless changes with named personas. Where licensed and in scope, we separate administrative roles and set up privileged access. We test real cases (a normal sign-in, a sign-in that should be blocked and recovery from a lost device), document emergency access and recovery procedures, and hand over the plan for the wider rollout.

What you get

What we hand over

Agreed policy and rollout plan
Implemented pilot or scoped rollout
Test matrix and results for sign-in, blocked access and recovery
Emergency access, recovery and rollback guidance
Open exceptions list
Handover to your team

Out of scope

What this doesn’t cover

  • A full tenant transformation by default
  • Replacing your identity provider or federation setup
  • Buying or deploying new devices or security keys
  • Tenant mergers and active incident response
  • Ongoing 24/7 support

Done when

The pilot or scoped rollout passes the agreed test cases, emergency access and recovery are documented and tested, and you sign off on the open exceptions.

What we need from you

Approved admin access for the work, a pilot group and a sponsor, your licensing details, and your current emergency access arrangements.

FAQ

Common questions

Will our users be locked out when Microsoft's SMS and voice codes stop?

Not automatically. Microsoft says people whose only method is SMS or voice will be asked to register a passkey before they can continue. The people who get stuck are the ones without a device that can hold a passkey, and that is what the pilot plans for.

Can everyone move to passkeys?

Not always. Shared devices, people without a compatible phone and some applications need a different method. The pilot finds those cases, and the plan records them as exceptions.

Can we keep SMS for some people?

Microsoft lets organizations that still need SMS or voice connect a third-party telephony provider through the Microsoft Security Store. We can help you decide where that is worth it.

How is this different from Azure Security Remediation?

This service owns identity policy and rollout work. If an Azure findings list includes identity items, we agree one scope owner, so the same work is never planned or billed twice.

How do you get into our tenant?

Through named, least-privilege access that you approve and can remove at handover. We never ask for shared passwords.

How it works

A typical engagement

01

Scope

We review the environment and agree the scope, priorities, acceptance tests and change approach with you.

02

Implement

We make the approved changes under your change control, with rollback or recovery plans where appropriate.

03

Validate

We test against the agreed acceptance criteria. A failed test is recorded, not hidden.

04

Hand over

You get the documentation, evidence and runbooks, plus a written list of anything still open.

Ready to get started? Discuss your project.

No pitch · Canada-wide