If your employees currently use text messages or phone calls to complete Multi-Factor Authentication (MFA), Microsoft has announced an important change you’ll want to prepare for now. Microsoft will begin retiring its built-in SMS and voice authentication services in Microsoft Entra ID and encouraging organizations to move to passkeys and other phishing-resistant authentication methods.
Key Dates to Know
September 1, 2026 Microsoft will begin enabling passkeys for users who currently use SMS or voice authentication. Those users will be prompted to register a passkey the next time they complete MFA.
February 1, 2027 Microsoft-provided SMS and voice authentication services will officially retire in Microsoft Entra ID. Organizations still using these methods will need to explore alternative options.
After February 1, 2027 Users whose only authentication method is SMS or voice will be required to register a passkey before they can continue signing in. Microsoft has stated there will be no opt-out from this requirement.
What Should Businesses Do Now?
To ensure a smooth transition, we recommend:
Identify users still using SMS or voice authentication – Understanding who is affected is the first step toward planning a successful migration.
Begin adopting passkeys – Moving users to passkeys before Microsoft’s deadlines helps avoid last-minute disruptions and gives employees time to become comfortable with the new sign-in process.
Communicate the change – Educating users ahead of time helps reduce confusion and support requests when passkey registration prompts begin appearing.
The Bottom Line
The transition away from SMS authentication is coming, but there is plenty of time to prepare. Taking proactive steps now will help improve security, reduce future sign-in disruptions, and ensure your employees are ready before Microsoft’s February 2027 retirement deadline.
We can help review your current authentication methods, identify affected users, and develop a plan to make the transition as seamless as possible.

