Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Should organisations prioritise passkey adoption or remove SMS…
Governance, Ownership & Risk

Should organisations prioritise passkey adoption or remove SMS first?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

Remove SMS first for high-value accounts, because it preserves a weak recovery and verification path even when stronger options exist. Then expand passkeys and hardware security keys as the default, since adoption works best when the insecure alternative is no longer the easy choice.

Why This Matters for Security Teams

passkey reduce phishing and credential replay, but they do not fix a broken fallback path. If SMS remains available for enrolment, recovery, or step-up verification, it becomes the easiest way back into high-value accounts after an attacker has already pressured support or intercepted a number. That is why the real question is not adoption versus removal, but which control removes the most exploitable weakness first.

For organisations managing sensitive identities, the weak link is often recovery logic, not the primary authenticator. NHI Management Group notes that 79% of organisations have experienced secrets leaks, with 77% causing tangible damage, which illustrates how often convenience paths turn into breach paths. The same pattern appears in human identity systems: insecure fallback options survive because they are operationally familiar. Ultimate Guide to NHIs shows how often exposed credentials persist far longer than teams expect, and the lesson transfers directly to account recovery design.

The practical priority is to remove SMS where it can be abused to regain privileged access, then make passkeys the default for everyday login. That sequencing aligns better with the NIST Cybersecurity Framework 2.0 emphasis on reducing identity risk at the control point, not just hardening the first factor. In practice, many security teams discover SMS was their real recovery vulnerability only after an account takeover has already bypassed the stronger factor.

How It Works in Practice

The most effective rollout treats authentication and recovery as separate decisions. Passkeys should become the preferred sign-in method because they are resistant to phishing and far easier to standardise than one-time codes. SMS, however, should be removed first from any account where compromise would cause financial loss, privileged access exposure, or data exfiltration. If SMS must remain during transition, it should be constrained to low-risk use cases and never serve as the sole recovery channel.

A practical sequence looks like this:

  • Identify high-value accounts, administrative users, and support workflows that can reset identity state.
  • Disable SMS as a recovery or second-factor option where stronger methods already exist.
  • Offer passkeys and hardware security keys as the default, with documented fallback to a phishing-resistant method.
  • Review enrolment, lost-device handling, and help-desk identity proofing so the backup process is not weaker than the login process.
  • Monitor for bypass paths such as alternate email resets, carrier-based number porting, or service desk overrides.

This approach matches the direction of current guidance from NIST Cybersecurity Framework 2.0, which pushes organisations to reduce authentication risk through stronger identity assurance and better recovery governance. It also fits the broader NHI lesson from Ultimate Guide to NHIs: credentials and fallback paths must be governed as lifecycle assets, not treated as one-time configuration choices. These controls tend to break down when service desks are allowed to override identity policy during urgent resets because the exception path becomes the easiest attack path.

Common Variations and Edge Cases

Tighter recovery controls often increase support load, requiring organisations to balance phishing resistance against account-recovery friction. That tradeoff is real, especially for consumer-facing services, shared devices, or workforces that cannot immediately use passkeys on every endpoint. Current guidance suggests there is no universal standard for when SMS should be removed everywhere, but there is broad agreement that SMS should not remain the default for privileged or high-impact accounts.

Some environments need a staged migration. For example, regulated enterprises may keep SMS temporarily for lower-risk users while forcing passkeys for administrators and finance teams. Others may use passkeys for primary sign-in but retain hardware security keys as the recovery option. The key distinction is that the fallback must be at least as resistant to phishing and SIM-swap abuse as the primary method.

Edge cases also include shared devices, international phone coverage issues, and users who cannot store passkeys on managed hardware. In those cases, best practice is evolving toward device-bound recovery, identity proofing, and help-desk controls that are auditable and time-limited. NHI Management Group’s Ultimate Guide to NHIs highlights how weak lifecycle controls create enduring exposure, and that same lifecycle thinking should govern user authentication transitions too.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-01Identity assurance and recovery design are central to this auth migration question.
NIST SP 800-63AAL2Passkeys and SMS replacement map directly to authenticator assurance choices.
NIST Zero Trust (SP 800-207)5.2Zero Trust requires stronger verification and reduced trust in legacy channels.
OWASP Non-Human Identity Top 10NHI-03Fallback credentials and weak recovery paths mirror poor lifecycle control in identity systems.
NIST AI RMFGOVERNIdentity recovery decisions need accountable governance and risk ownership.

Strengthen identity assurance by replacing weak fallback paths with phishing-resistant recovery methods.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org