Security

Microsoft Is Retiring SMS & Voice MFA: What to Do

Andrew Wienen

Microsoft Is Retiring SMS & Voice MFA: What to Do

Microsoft just put a hard deadline on one of the most common ways people log in to work: the code texted to your phone. Microsoft Entra ID (the identity system behind Microsoft 365) is making passkeys the default sign-in experience and retiring Microsoft-provided SMS and voice as authentication methods. If your team still signs in with a texted or called-in code, this affects you, and the clock is already running.

Here is what is changing, the dates that matter, and exactly what to do before they arrive.

The short version

Two dates carry the whole change:

  • September 1, 2026: passkeys become the default. Anyone still on SMS or voice gets automatically enabled for passkeys and nudged to register one.
  • February 1, 2027: Microsoft-provided SMS and voice are fully retired. Users whose only method is a text or call get a blocking prompt to set up a passkey before they can sign in again.

Everything else is detail on how to get from here to there without your team hitting that blocking prompt cold.

Why Microsoft is doing this

The driver is security, plainly stated. SMS and voice codes were a real improvement over passwords alone, but attackers caught up. A texted code can be stolen by SIM-swapping your number, intercepted in transit, or relayed to an attacker in real time through a fake login page. None of that takes sophisticated tooling anymore.

Passkeys close those doors. Instead of a shared secret that can be phished or forwarded, a passkey uses a cryptographic key tied to your device or a synced credential store. There is no code to read out, intercept, or hand to the wrong site. That is why Microsoft, and the security industry broadly, now treats SMS and voice as among the weakest options available and passkeys as the default.

The timeline that matters

Mark these dates. They apply to public cloud tenants; other Microsoft cloud environments follow later on a schedule Microsoft says it will announce separately.

  • August 1, 2026: Microsoft publishes the API and guidance for a temporary opt-out, in case you need to delay the interim changes while you finish a migration.
  • September 1, 2026: Passkeys become the default. Users still enabled for SMS or voice are automatically enabled for passkeys and, at their next MFA sign-in, nudged to register one through a registration campaign. By default the nudge can be snoozed without limit, so a nudge alone will not move everyone.
  • September 18, 2026: Microsoft publishes the options and terms for customer-managed telecom providers in the Microsoft Security Store, for organizations that must keep SMS or voice.
  • October 30, 2026: You can actually select and configure a telecom provider from the Security Store.
  • February 1, 2027: Microsoft-provided SMS and voice are fully retired. This deadline has no opt-out and applies to every tenant.

What actually happens on February 1, 2027

This is the part worth being precise about, because it is easy to over-read. It is not a mass lockout. Nobody’s account is deleted or disabled.

What happens is this: if a user’s only available MFA method is SMS or voice, the next sign-in shows a blocking prompt to register a passkey. They can no longer snooze it. They must complete passkey registration before they can continue. For a prepared team, that is a minor speed bump. For an unprepared one, it is a wave of confused users and help-desk tickets all landing on the same morning. The whole point of preparing early is to make sure that prompt never surprises anyone.

What you should do now

You have time, but not so much that it can wait for next year’s planning cycle. Five steps, in order:

  1. Find out who is exposed. Microsoft provides a “Find users still using SMS or Voice” PowerShell script; running it needs a Global Reader, Authentication Policy Administrator, or Security Reader role. Any non-zero result means you are in scope.
  2. Turn on passkeys. Enable passkey (FIDO2) as an authentication method in the Entra authentication methods policy and plan which passkey types fit your environment: synced passkeys for people who already use a credential manager, and device-bound options like a passkey in Microsoft Authenticator, Windows Hello for Business, or a FIDO2 security key for everyone else.
  3. Run a registration campaign early. Rather than wait for the automatic September nudge, prompt your SMS and voice users to set up a passkey at sign-in now. It is the most effective way to move people off phone-based codes at scale without piling work on the help desk.
  4. Communicate in phases. Announce what is changing and why, then direct people to register with device-specific steps, then remind the stragglers. Coordinated communication is the single biggest predictor of a smooth rollout.
  5. Handle the genuine exceptions. If a specific team has a real regulatory or operational need for SMS or voice, plan to contract a customer-managed telecom provider through the Security Store (available to configure from October 30, 2026). For everyone else, passkeys are the destination, and moving to them costs nothing extra.

Who is and isn’t affected

A few clarifications that save a lot of second-guessing:

  • Scope: public cloud tenants, and users enabled for SMS or voice in the authentication methods policy or legacy MFA settings.
  • Self-service password reset is included. The retirement applies across Entra, so SMS and voice go away for password reset too, unless you use a Security Store telecom provider.
  • Third-party and external MFA methods are not affected, unless the same user is also enabled for SMS or voice.
  • B2B and guest users: passkey support for them is planned by the end of 2026, and they are included in the retirement’s scope.

How Prevvi handles this for clients

This is exactly the kind of change managed IT exists to absorb quietly. As part of our managed IT and cybersecurity services, we run the whole play for clients on Microsoft 365: audit who is still on SMS or voice, enable passkeys, drive a registration campaign on a schedule that does not interrupt anyone’s workday, communicate the change in plain language, and stand up a compliant telecom provider for the rare team that genuinely needs one. Phishing-resistant MFA and a real security baseline come standard with us, never as an upsell.

The organizations that will feel February 1, 2027 as a non-event are the ones that started in 2026. If you are not sure where your tenant stands, or you just want the exposure report without the project, book a free assessment and we will show you exactly which accounts still need to move, and by when.

Frequently asked questions

Yes, for the codes Microsoft delivers itself. On February 1, 2027, Microsoft-provided SMS and voice delivery is fully retired in Microsoft Entra ID. Organizations with a genuine regulatory or operational need can keep SMS or voice by contracting a customer-managed telecom provider through the Microsoft Security Store, but the built-in Microsoft option goes away.

It is not an account lockout. Users whose only MFA method is SMS or voice will get a blocking prompt to register a passkey the next time they sign in. They cannot skip it, and must complete passkey registration before they can continue. There is no opt-out from this enforcement, and it applies to all tenants.

Passkeys become the default. That includes synced passkeys saved to a credential manager like iCloud Keychain or Google Password Manager, and device-bound passkeys such as a passkey in Microsoft Authenticator, Windows Hello for Business, or a FIDO2 hardware security key. All of these are phishing-resistant, unlike a texted code.

Migrating users from Microsoft-provided SMS or voice to passkeys carries no additional cost. If you keep SMS or voice through a customer-managed telecom provider in the Security Store, that provider bills per message and pricing varies by region and volume.

This timeline applies to public cloud tenants. It covers users enabled for SMS or voice in the authentication methods policy or legacy MFA settings, and it applies across Entra including self-service password reset. Third-party or external MFA methods are not affected unless the user is also enabled for SMS or voice. Passkey support for B2B and guest users is planned by the end of 2026.

Microsoft provides a PowerShell script, 'Find users still using SMS or Voice,' that lists everyone in your tenant still enabled for those methods. You need a Global Reader, Authentication Policy Administrator, or Security Reader role to run it. Any non-zero result means you are in scope and should start planning your passkey rollout.

Want this handled for you?

Talk to a real engineer about your environment: no sales script, just straight answers.