Microsoft Retiring SMS Authentication: What It Means for Your Business

Microsoft SMS authentication

Microsoft is retiring its own delivery of the SMS and voice login codes it once recommended. From 1 September 2026, Microsoft began automatically enabling passkeys and prompting users currently enabled for SMS or voice to register one.

Microsoft-provided SMS and voice authentication will be retired on 1 February 2027, although organisations with a genuine requirement may be able to use a customer-managed telecom provider.

Here’s what’s changing, why Microsoft is doing it, and what it means if no one has looked at your login settings in a while.

For years, the advice was simple. Turn on multi-factor authentication and use a text message for the login code.

Now Microsoft is retiring its own SMS and voice authentication service and moving users towards passkeys.

This is a change to how your team gets into their accounts every morning, and it’s coming whether you’ve planned for it or not.

For many organisations, MFA was configured years ago and then forgotten about. This change is a good reason to take another look.

What’s Actually Changing

There are two key dates that matter.

The first has already passed. Since 1 September 2026, users currently enabled for SMS or voice authentication have been automatically enabled for passkeys and may be prompted to register one. For the moment, that prompt can be skipped, so most people won’t have noticed anything has changed.

The second date is the point where organisations need to be ready. On 1 February 2027, Microsoft will retire its own SMS and voice authentication delivery. Organisations with a genuine operational or regulatory requirement to retain SMS or voice will need to configure a customer-managed telecom provider through the Microsoft Security Store.

Users whose only available MFA method is SMS or voice will receive a blocking prompt to register a passkey before they can continue signing in.

The change applies across all Microsoft Entra ID tenants, but the immediate impact will be on organisations with users still relying on Microsoft-provided SMS or voice authentication. If that’s still happening anywhere in your environment, now is the time to plan the transition.

Why Microsoft Is Walking Away From a Method It Used to Recommend

Microsoft’s reasoning is fairly simple. SMS and voice authentication rely on a shared secret: a code sent to a user that can be intercepted, stolen or disclosed. Attackers have spent years finding ways to do exactly that.

A passkey works differently. The authentication happens using credentials stored on a trusted device, removing the text code that attackers are typically trying to intercept or trick users into revealing.

Phishing is now the most common type of attack on UK businesses, experienced by 38%, and it’s rated the single most disruptive kind of attack by 69% of those hit. Text codes are precisely what these attacks are designed to capture.

Then there’s SIM-swapping, where a criminal hijacks your mobile number to receive your codes for you. Reported UK cases rose by 1,055% in 2024, with nearly 3,000 filed to the National Fraud Database. Intercepting authentication codes is the entire point of the exercise.

Put simply, Microsoft is retiring the method because attackers have spent years finding ways around it.

 

What This Means If No One’s Touched Your MFA Settings

Here’s where that skippable prompt comes back to bite. Plenty of businesses turned on multi-factor authentication years ago, chose the text-message option because it was the quickest to set up and haven’t looked at it since. If that sounds familiar, the clock is already ticking.

The reason it’s easy to miss is that nothing appears to be wrong. Your team can still skip the passkey prompt each morning, so the change feels optional right up until the moment it is not. Then 1st February arrives, the prompt stops being skippable, and anyone whose only MFA method is SMS or voice will be unable to continue signing in until they register a passkey.

Picture that landing across a department on an ordinary Monday, with no one having been told to expect it. This is why the change is worth treating as a continuity issue rather than a purely technical one. It tends to sort businesses into two camps:

  • The ones who sail through: they knew where they stood in good time and moved their people across before the deadline forced it.
  • The ones caught out: they assumed someone had it in hand, only to find out on 1 February that nobody did.

Phishing-Resistant Authentication Is Becoming the New Baseline

When the vendor that recommended a security method is the one switching it off, that’s the clearest signal you’ll get that the ground has moved. Microsoft is retiring an approach it spent years recommending because it no longer provides the level of protection organisations need.

Microsoft is making phishing-resistant authentication the new baseline, with passkeys positioned as the primary migration route for users currently relying on SMS or voice.

Many businesses only become aware of changes like this when an automated prompt lands in front of their staff. By then, the decision has been made for them and the clock is already running. The better position to be in is the one where someone was watching for it, understood what it meant, and told you while there was still time to plan. That’s the difference between reacting to your technology and being ahead of it.

Passkeys are one example and they won’t be the last.

Not Sure Where Your Business Stands?

Whether your team is still signing in with text codes is a simple question with a clear answer. The only trouble is that most businesses don’t know it off the top of their heads and 1 February is a bad time to find out.

That’s the sort of thing we’re here for: just a straight conversation about where your business currently stands, whether anyone’s still on SMS or voice, and what moving them across actually involves. It’s a short chat now that saves a scramble later.

If you’d like to know where you stand before the deadline forces the issue, talk to Outbound Group today.

FAQs

Is Microsoft getting rid of SMS authentication?

Microsoft is retiring its own delivery of SMS and voice authentication in Entra ID. Organisations that still have a genuine operational or regulatory requirement may be able to use a customer-managed telecom provider, but Microsoft recommends moving users to phishing-resistant methods such as passkeys.

What is a passkey, and why is it more secure than a text code?


A passkey uses cryptographic credentials stored on a device or within a supported credential manager rather than a code sent to your phone. Passkeys are resistant to phishing, SIM-swapping and replay attacks because there is no text code for an attacker to intercept, steal or persuade a user to disclose it.

What happens on 1 February 2027 if my team still uses text codes?

From that date, anyone whose only available MFA method is SMS or voice will need to register a passkey before they can continue signing in. There is no gentle transition period after this point, so it’s worth knowing now whether anyone in your business is still relying on SMS.

Does this affect every business using Microsoft 365?

The enforcement applies across Microsoft Entra ID tenants. The users most directly affected will be those whose only available MFA method is Microsoft-provided SMS or voice. If anyone in your organisation still relies on Microsoft-provided SMS or voice authentication, this change reaches you.

What should we do to prepare?

The first step is simply knowing where you stand: whether anyone is still on SMS or voice, and what moving them to passkeys involves. We have covered the practical steps in a companion piece, and if you’d rather talk it through for your own setup, Outbound can help you get ahead of the February deadline.

Looking for something specific?