Microsoft retires SMS and voice MFA on 1 February 2027. What actually qualifies

IronSightsStore

The best key combination for Entra ID

Which keys to buy for which staff in a Microsoft tenant, how the cohorts break down, and the one check to do before you order anything.

IronSights Editorial ·

This is a buying guide, not a configuration guide. It answers which keys to order and for whom. What to do with them inside the tenant is a separate piece of work, and a larger one than most people expect.

Break the staff list into four groups

Almost every Microsoft tenant sorts into the same four cohorts, and each one gets a different answer.

Global and privileged administrators. Hardware keys, two each, no exceptions. These accounts can change the identity configuration itself, which makes them the accounts an attacker wants and the accounts an assessor looks at first. A passkey in an app on a personal phone is not the right credential for someone who can turn off your Conditional Access policies.

Break-glass accounts. Their own dedicated hardware keys, two per account, stored separately from everyone's personal keys and excluded from the Conditional Access policies that could lock them out. These keys must work when the person who normally does this is unreachable, which means they cannot belong to that person.

General staff with a work phone. Passkeys in Microsoft Authenticator. Free, fast to deploy, and phishing-resistant. Buying keys for this group is usually money spent for no additional security.

Everyone the passkey route does not reach. Staff without a work phone, staff who decline a work app on a personal device, shared workstations, field and clinical roles. Hardware keys, two each. This group is why key orders exist, and it is nearly always smaller than people fear.

Which models

For the administrators and the staff on modern laptops, the 5C NFC. USB-C for the machine, NFC for the phone, one model covering both.

For anyone on USB-A desktops or docks, the 5 NFC.

For the second key of a desk-based person, the 5C Nano. It lives in the machine, does not occupy pocket space, and is the backup that never gets left at home.

For break-glass keys, use an NFC model rather than a Nano. A key in a safe that you can hand to someone is more useful in an emergency than one wedged in a computer.

Two models across the fleet is supportable. More than that becomes a support burden that outlasts the project.

The check to do before you order

Entra ID can restrict which security keys are permitted, by AAGUID, which is a model identifier the key presents when it registers. If that restriction is enabled and your chosen model is not on the list, registration fails and the keys are useless until someone changes the policy.

Check this first. It takes minutes and it is the most common reason a key order sits in a drawer for a fortnight.

What the keys do not do on their own

Ordering keys changes nothing until Conditional Access requires a phishing-resistant method for the accounts in scope.

That configuration is where the real work is, and where the real risk is. A Conditional Access policy applied too broadly, or without the break-glass exclusions in place, locks administrators out of their own tenant. It is a recoverable situation and it is not a pleasant one, and it is why we recommend that the policy change is planned rather than improvised.

We cover that as a Conditional Access review, and it usually sits alongside a broader Microsoft 365 review.

Frequently asked questions

  1. Do all Entra ID users need a hardware key?

    No. Most organisations use passkeys for general staff and hardware keys for administrators, break-glass accounts and staff the passkey route cannot reach.

  2. Can we mix passkeys and hardware keys in one tenant?

    Yes. Authentication strengths require a phishing-resistant method without dictating which one, so different cohorts can carry different credentials under one policy.

  3. What licence do we need?

    Conditional Access requires a licence tier above the base one. Confirm what your tenant currently holds before planning the work, because this is a common mid-project surprise.

  4. Should break-glass accounts be excluded from Conditional Access?

    Yes, and that exclusion is what stops a policy mistake from locking you out permanently. It should be deliberate, documented and tested.