Microsoft has announced an important change in Microsoft Entra ID (the authentication system behind Microsoft 365): Microsoft-provided SMS and voice authentication will retire on February 1, 2027. Microsoft is also moving toward passkeys as the default, phishing-resistant sign-in experience.
This matters because organizations that still rely on SMS/voice for MFA can run into user friction and sign-in blocks if they wait too long.
Why Microsoft is making the change
SMS and voice MFA are among the most vulnerable options available today. They provide weaker protection against common attacks such as:
- phishing designed to capture MFA codes in real time
- SIM-swap/number porting that can hijack phone numbers
- replay/social engineering that makes one-time codes easier to misuse
Microsoft’s direction is to make phishing-resistant authentication the standard rather than the exception.
Key dates
- September 1, 2026: Users enabled for SMS/voice will be automatically enabled for passkeys and prompted to register when they next complete MFA.
- February 1, 2027: Microsoft-provided SMS and voice MFA retire in Entra ID.
- After February 1, 2027: Users with only SMS/voice available will receive a blocking prompt to register a passkey before they can continue signing in.
What we recommend
If any users in your environment still use SMS or voice MFA:
- Identify the affected users
- Move them to passkeys (recommended) or another phishing-resistant methods.
How IT Voice can help
We can review your Entra authentication methods, identify who is still using SMS/voice MFA, and create a migration plan that reduces disruption while improving account security.
If you’d like us to assess your current MFA methods, let us know and we’ll schedule a quick review.