Where supported, yes. Passkeys remove the message-send path for returning users, and silent network authentication verifies some users without an SMS at all. The right sequencing is to remove routine SMS exposure first, then reserve it for fallback and recovery.
Why the first replacement should target routine SMS use
When an organisation is trying to move off SMS, the first job is to remove SMS from the common path, not to preserve it as a default convenience layer. Passkeys are stronger for returning users because they shift sign-in to phishing-resistant cryptographic authentication, while silent authentication can reduce repeated prompts where a trusted device or network signal already exists.
The sequencing matters because routine SMS use creates an unnecessary exposure surface for users who log in often. The Passwordless and Passkeys Guide is the clearest place to see why passkeys are usually the better first step for those users: they remove OTP dependence rather than just narrowing where SMS appears.
How passkeys and silent authentication differ in practice
Passkeys change the authenticator model. Instead of sending a code that can be intercepted, relayed, or socially engineered, the user proves possession of a private key with local device binding and platform or security-key support. Silent authentication is different: it does not replace the primary factor so much as reduce friction when the environment already has enough trust signals to complete sign-in without re-prompting.
That difference affects rollout. Passkeys are usually the better choice for broad user populations because they improve both security and user experience at the same time. Silent authentication is narrower, because it depends on a trusted session, device posture, network context, or existing identity provider state. The Workforce Identity Security Guide covers the surrounding sign-in and recovery controls that make passkey adoption safer at scale.
For most organisations, the decision is not “which is more modern?” but “which one removes the most SMS dependence without creating a new failure path?” Passkeys reduce the attack surface on the user side. Silent authentication reduces prompts, but it does not automatically remove the need for fallback, recovery, or step-up when trust is uncertain.
What to sequence first in a real migration
The sensible order is to replace routine SMS sign-in first where the user journey can support it, then use silent authentication to cut repeated prompts and improve flow for trusted contexts. That lets you reduce message-based exposure quickly while you keep SMS only as a constrained fallback for recovery, edge cases, and unsupported devices.
- Prioritise high-frequency users first, because that is where SMS exposure accumulates fastest.
- Keep fallback and account recovery explicit, time-bound, and monitored instead of leaving SMS as an evergreen default.
- Use silent authentication only where the trust model is strong enough to justify it, because convenience does not equal equivalent assurance.
In practice, this is why MFA Guide is useful as a sequencing reference: it shows how SMS, passkeys, and phishing-resistant methods differ in resistance to relay, fatigue, and token theft, which is exactly the trade-off behind the migration order.
Risk and Threat Considerations
SMS is not just lower assurance, it is also a recurring abuse path when attackers target users at scale. Code interception, SIM swap, smishing, and OTP relay all become easier to exploit when SMS remains a routine factor rather than an exception path. Silent authentication has different risk: if the trust signal is over-permissive, it can create an easy route to unattended access on compromised devices or weak sessions.
Failure mechanism: Routine SMS keeps a reusable recovery and login path available to attackers who can phish codes, hijack a number, or pressure support into reissuing access; overly broad silent-auth rules can also let a compromised trusted context sign in too easily.
Impact: The organisation retains a weak fallback that attackers can target repeatedly, while users may mistake convenience for assurance and underinvest in stronger sign-in options and recovery controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST SP 800-53 Rev 5, OWASP ASVS and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Passkeys and phishing-resistant sign-in are central to the question. |
| Recommendation — Prefer phishing-resistant authenticators for primary sign-in and keep SMS only as limited fallback. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The question is about replacing and limiting authenticator use across sign-in paths. |
| Recommendation — Govern authenticator issuance, replacement, and fallback so SMS is not the routine default. | ||
| OWASP ASVS | V6 — Authentication | Passkeys versus SMS is an authentication design choice affecting sign-in assurance. |
| Recommendation — Require phishing-resistant authentication for primary login and constrain weaker methods to exceptions. | ||
| ISO/IEC 27001:2022 | A.5.17 — Authentication information | Auth factors and recovery paths must be controlled as sensitive authentication information. |
| Recommendation — Protect authentication factors and recovery processes so weaker fallback paths stay tightly governed. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Sequencing SMS retirement and fallback control is an access management decision. |
| Recommendation — Reduce reliance on weak access paths and limit fallback authentication to approved exceptions. | ||
Practitioner Guidance
Decision rule: If the user population can support passkeys, remove SMS from the normal sign-in path first and keep it only for tightly governed recovery. Use silent authentication as a usability layer for trusted sessions, not as the main substitute for a weak authenticator.
What to verify: Confirm that recovery flows, help desk resets, and device loss handling still work when SMS is no longer the default path. If those paths are weak, the migration will merely move risk instead of reducing it.
What practitioners underestimate: The hardest part is usually not enrolling passkeys, it is deciding which edge cases still deserve SMS and which should be forced through stronger recovery or step-up. The cleaner the exception policy, the faster the organisation can retire SMS safely.
Practitioner takeaway: Replace routine SMS first, then constrain it to recovery and unsupported cases; silent authentication is best treated as a friction-reduction control, not a full security replacement for phishing-resistant sign-in.
Related resources from NHI Mgmt Group
- How should organisations replace legacy email-and-password authentication in mobile-first environments?
- Should organisations replace SMS and OTP MFA first, or focus on privileged access first?
- Why is it crucial to adopt new authentication methods in MCP usage?
- Should organisations replace passwords everywhere with passkeys immediately?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org