
Microsoft is retiring SMS and voice authentication: what SMEs need to know
Microsoft has announced an important change to how users authenticate with Microsoft 365 and other services protected by Microsoft Entra ID.
From 1 February 2027, Microsoft-provided SMS codes and voice calls will no longer be available as authentication methods. Microsoft is moving users towards passkeys and other phishing-resistant methods, which provide significantly stronger protection against account compromise.
For businesses still relying on text messages or phone calls for multi-factor authentication (MFA), preparation should begin well before the deadline.
Why is Microsoft making this change?
SMS and voice authentication are safer than relying on a password alone, but they are increasingly vulnerable to attacks such as:
- Phishing and social engineering
- SIM-swap fraud
- Interception or redirection of authentication codes
- Code replay attacks
Passkeys are designed to resist phishing because they are tied to the legitimate website or service. Users do not receive a code that can be copied, intercepted or handed to an attacker.
In practical terms, this change should make Microsoft accounts harder to compromise while also giving users a simpler sign-in experience.
The key dates
1 September 2026
Users who are enabled for SMS or voice authentication will also be automatically enabled for passkeys.
When these users next complete MFA, Microsoft will begin prompting them to register a passkey. Businesses that want to control how and when users are migrated should complete their planning and begin registration before this date.
1 February 2027
Microsoft-provided SMS and voice authentication will be fully retired in Microsoft Entra ID.
After this date, users whose only available MFA method is SMS or voice will be blocked during sign-in and required to register a passkey before they can continue. Microsoft has advised that there will be no option to disable this enforcement.
Customer-managed telecommunications providers configured through the Microsoft Security Store will not be affected. However, this option is primarily intended for organisations with a specific regulatory or operational requirement to retain SMS or voice authentication.
What does this mean for your business?
If nobody in your organisation uses SMS or voice authentication, you may not need to take any action.
If employees, contractors, administrators or other users still receive MFA codes by text message or automated phone call, they will need to move to a supported phishing-resistant authentication method before 1 February 2027.
Although the final deadline may seem some distance away, waiting until the last minute could result in disrupted access, additional support calls and users encountering blocking prompts at inconvenient times.
Acting before 1 September 2026 will allow your business to manage the transition on its own schedule.
What is a passkey?
A passkey is a modern replacement for passwords and one-time authentication codes. Depending on the device and configuration, a user may sign in using:
- Facial recognition
- A fingerprint
- A device PIN
- A compatible physical security key
The passkey confirms both the user’s identity and that they are signing in to the legitimate service. This makes it far more resistant to phishing than a code delivered by SMS or voice call.
What should SMEs do now?
We recommend taking the following steps:
- Identify affected users. Review your Microsoft Entra authentication settings and determine who is currently enabled for SMS or voice authentication.
- Confirm device and application readiness. Check that users have compatible devices and that any business-critical or legacy workflows will support the planned authentication method.
- Enable passkeys. Configure the appropriate policies and test the experience with a small group before rolling it out across the business.
- Run a registration campaign. Give users clear instructions and sufficient time to register their passkeys before Microsoft begins automatically prompting them.
- Prioritise privileged accounts. Administrators and users with access to sensitive business systems should be moved to phishing-resistant authentication as early as possible.
- Keep recovery arrangements up to date. Confirm that account recovery and emergency-access procedures will still work if a device is lost, replaced or unavailable.
- Communicate the change. Explain what users will see, why the change is happening and where they can obtain assistance.
- Avoid switching methods off prematurely. Make sure users have successfully registered and tested their replacement method before removing SMS or voice access.
What if your business must retain SMS or voice?
Microsoft plans to make customer-managed telecommunications providers available through the Microsoft Security Store. Provider options and pricing are expected from 18 September 2026, with configuration becoming available from 30 October 2026.
This route should generally be considered only where there is a genuine regulatory or operational requirement. SMS and voice will remain less resistant to phishing and account takeover than passkeys.
Our recommendation
Do not treat February 2027 as the date to start this project.
Businesses should identify affected accounts now, test passkeys with a pilot group and plan to complete their migration before 1 September 2026. This provides time to resolve device, access and user-support issues before Microsoft’s automatic prompts begin.
If you need assistance reviewing your Microsoft Entra environment, identifying affected users or planning a controlled passkey rollout, contact our team. We can help make the transition secure and straightforward while minimising disruption to your business.
