On 13 July, Microsoft announced that passkeys will become the default authentication method in Microsoft Entra ID, and that it will retire SMS- and voice-based multi-factor authentication (MFA) altogether. The enterprise security debate is now settled: the future is phishing-resistant and passwordless. The only open question is how to get there. And that is where most organisations discover that buying a hardware security key was always the easy part. The hard part is deployment: getting the key to every staff member across the country and the world, then keeping the whole fleet running. That is the problem the Trust Panda Enterprise portal was built to solve.
What Microsoft's change means
The timeline is short. From 1 September 2026, passkeys become the default sign-in in Entra ID, and anyone still on SMS or voice is prompted to register one. On 1 February 2027, Microsoft switches off its native SMS and voice authentication for good. After that there is no opt-out. Organisations that insist on keeping SMS must contract a third-party carrier through the Microsoft Security Store and pay the ongoing per-message fees themselves.
The reason is simple: SMS and voice are now the weak link. Microsoft's threat intelligence reports AI-driven phishing campaigns hitting click-through rates as high as 54 percent, against roughly 12 percent for traditional ones. Passkeys use public-key cryptography instead of shared secrets, so they are phishing-resistant by design.
Australian regulation already points the same way. The ACSC's Essential Eight requires phishing-resistant MFA at Maturity Levels Two and Three, and it explicitly counts FIDO2 hardware keys like YubiKeys as meeting the bar while ruling out SMS codes and standard push notifications. The Microsoft deadline and the compliance path now line up.
The hardware key is the fastest way there
Here is the detail most organisations miss: a hardware security key is a passkey. Microsoft lists FIDO2 security keys as a supported, device-bound passkey type in Entra ID. A YubiKey is not an alternative to passkeys; it is one of their strongest forms. Our Australian buyer's guide to FIDO2 security keys explains how they work.
SMS survived this long largely because many staff refused to put an authenticator app on their personal phone. A hardware key removes that objection entirely: no personal phone, no app, no setup friction. The user taps or plugs in the key and is signed in within seconds. It is a one-off device cost against recurring SMS carrier fees, and it is far more secure. In the Forrester Total Economic Impact™ study commissioned by Yubico, users authenticated 80 percent faster, in about five seconds.
The real challenge: distributed teams
The technology is settled and the clock is running, but a hardware key is a physical object. It cannot be emailed or pushed remotely. Someone has to order it, ship it, activate it and replace it, and today's teams are spread across states, time zones and countries, with new starters arriving every week.
A Sydney head office, a contractor in Perth and a sales rep in Singapore all need the same key, on different shipping routes and from different stock. When a key is lost or fails, that person is locked out of work until a replacement lands. Phishing-resistant MFA delivers nothing if onboarding slips by weeks, or if IT is tracking who holds which key in a spreadsheet.
Issue two keys and the lockouts stop
The single biggest recurring headache has a simple fix: give every staff member two keys. Yubico's own best practice is a primary plus an enrolled backup. When each person already holds a spare, a lost or damaged key stops being an emergency, because the backup just works. The employee keeps going, and IT swaps the missing key on a normal schedule. The Trust Panda Enterprise portal is built for this, ordering and tracking keys in pairs and showing at a glance who still needs a spare.
The help desk maths
This is where the cost lands. Forrester puts the average identity-related help desk ticket at around US$30, with each user generating at least one password-reset call a year. Move to passwordless and those calls all but vanish: in the modelled organisation, password-reset tickets fell 100 percent, worth about US$476,000 over three years, inside a 265 percent return and an eight-month payback. As one security leader in the study put it, "password-related calls are down to zero now." But the saving only lands if the keys reach everyone and replacements don't create fresh tickets.
One pane of glass, including for IT providers
The Trust Panda Enterprise portal is the layer that makes all of this hold together, and it is not new. Trust Panda has shipped YubiKeys globally since 2018 and run a portal since 2022; the current version builds on that track record. From one screen, teams manage the full lifecycle: order and reorder, ship direct to employees in Australia and worldwide, and see the status of every shipment. IT and procurement see what is in progress, what arrived where, and what needs replacing, instead of reconstructing it from spreadsheets. Consolidated invoicing and volume pricing simplify buying, and direct-to-employee delivery takes internal repackaging off IT's plate.
There is no size threshold: the same portal serves an organisation deploying ten keys or ten thousand. Businesses can shop YubiKeys for business or the government and FIPS range, and for FIDO2-only deployments the lower-cost Security Key series keeps the per-user cost down. Larger rollouts can request a volume quote.
Access now extends to IT providers and managed service providers too. An MSP can manage every client from a single pane of glass, deploying, reordering and replacing keys on their behalf rather than juggling separate logins and spreadsheets. For a provider rolling out phishing-resistant MFA across dozens of client environments before the Microsoft deadline, that is the difference between a scalable service and a manual grind.
"The hardware key is the easy part. Our customers don't struggle with which key to choose, but with getting it to staff across the country and the world and keeping the fleet running. The Enterprise portal answers that hard part."
Allan Dall, Enterprise & Government Sales, Trust Panda
The network behind it
A portal is only as good as the logistics behind it. Trust Panda ships from five fulfilment centres, in Australia, New Zealand, Hungary, India and California, reaching fifty-two countries. Australian orders leave the Sydney fulfilment centre same-day via Australia Post, from genuine stock. As a Yubico Gold-certified authorised reseller, every device is genuine and carries the manufacturer's warranty. That network is what turns an order on the dashboard into a key on a desk in Brisbane, Perth or Singapore.
The key was always the easy part
With the February 2027 deadline set, the question is not whether organisations move to passkeys. Microsoft has decided that. The question is whether they can get keys into every pair of hands quickly and cleanly. The security is solved: the hardware key is strong, phishing-resistant and standards-based. What has been missing is a reliable way to deploy it at scale, across borders, with a backup for everyone. That is the hard part, and it is the part the Trust Panda Enterprise portal was built for.
The February 2027 deadline is closer than it looks, and passkey rollouts take planning. Whether you are securing ten staff or ten thousand, or you are an IT provider rolling out across your client base, the time to map it out is now. Talk to the Trust Panda enterprise team to scope your deployment and get access to the portal.
