Quick answer

From September 1, 2026, Microsoft makes passkeys the default authentication method in Entra ID, and Custom controls for third-party MFA retires with full end of life in May 2027. Because strong, phishing-resistant authentication sits at the core of the Cybersecurity Act's (NIS2) risk-management requirements, Swedish businesses should audit their MFA usage, plan their passkey rollout, and tie the work to their NIS2 documentation now.

Microsoft is making passkeys the default sign-in method in Entra ID starting September 2026, while Custom controls is phased out. For Swedish businesses already navigating the new Cybersecurity Act, it is a natural opening to strengthen identity protection and demonstrate the "appropriate technical measures" NIS2 requires.

Starting September 1, 2026, Microsoft is rolling out passkeys as the default authentication method in Entra ID. Organizations currently relying on SMS or voice-call MFA will be gradually transitioned, with users prompted to register a passkey the next time they authenticate. At the same time, Custom controls retires on September 30, 2026, reaching full end of life in May 2027 – forcing organizations that depend on third-party MFA to migrate to External MFA.

This lands right as Swedish businesses are already navigating a heavier cybersecurity compliance load. The new Cybersecurity Act (2025:1506), Sweden's implementation of the EU's NIS2 directive, took effect on January 15, 2026, covering companies across 18 sectors – typically those with 50+ employees or revenue above €10 million, though smaller organizations with a critical role can also be in scope. The law requires systematic risk management, incident reporting within set timeframes, and direct accountability from boards and management – including mandatory cybersecurity training for board members. Penalties are steep: up to €10 million or 2% of global turnover.

Why these two things are connected

Strong authentication sits at the core of NIS2's risk-management requirements. Phishing-resistant sign-in methods like passkeys dramatically cut account-takeover risk compared to SMS-based MFA, which remains vulnerable to SIM-swapping and phishing. As Microsoft makes passkeys the Entra ID default, Swedish organizations get a natural opening to both raise their security posture and demonstrate the "appropriate technical measures" NIS2 requires.

What to do now

Five concrete steps help you stay ahead of the rollout and tie identity security to your NIS2 documentation:

  • Audit your current MFA usage – which users and groups still rely on SMS, voice calls, or Custom controls?
  • Plan your passkey rollout proactively, rather than letting Microsoft's timeline dictate when your tenant is affected.
  • If you use third-party MFA via Custom controls, start migrating to External MFA now – support ends completely in May 2027.
  • Tie identity security to your NIS2 documentation. Your risk assessment should explicitly describe how strong authentication reduces identity-related risk.
  • Brief your leadership team. The Cybersecurity Act requires board members to be able to identify and assess risk – identity security is a concrete, easy-to-explain example to start with.
IT SecurityMicrosoft 365M365 Audit

Conclusion

Microsoft is expected to share further technical guidance and pricing for External MFA providers on September 18, 2026. MAQ Techs is tracking this closely and can help you set up an Entra ID and Intune environment that's both secure and ready for NIS2 review.

Sources

Ready to take the next step?

Need help getting started with passkeys or NIS2-ready identity management? Book a free review and we'll walk through your current setup together.

Book a free review