Cyber threats are evolving rapidly, and traditional authentication methods are struggling to keep pace. Microsoft has announced a significant change that will affect organisations still replying on SMS or voice based multi-factor authentication (MFA): Microsoft provided SMS and voice authentication in Microsoft Entra ID will be retired on 1 February 2027.
While this may seem like another platform update, it's really part of a wider shift towards stronger, phishing-resistant security. For organisations using Microsoft Entra ID, now is the time to start planning the transition.
Why is Microsoft retiring SMS MFA?
SMS and voice MFA have helped organisations strengthen security for many years, but they were never designed to defend against today's sophisticated threats.
Cybercriminals can exploit these methods through:
- Phishing attacks that trick users into revealing authentication codes
- SIM-swap attacks where a mobile number is transferred to a fraudulent device
- Replay attacks that intercept and reuse one-time passcodes
As AI-powered attacks become more convincing and scalable, organisations need authentication methods that provide stronger protection by design.
Microsoft's response is clear: move users towards phishing-resistant authentication, with passkeys becoming the default authentication experience in Microsoft Entra ID.
What are passkeys?
Passkeys are a modern authentication method that replaces passwords and vulnerable one-time codes with secure, cryptographic credentials.
Rather than entering a password and waiting for a text message, users authenticate using a trusted device and a biometric factor such as:
- Fingerprint recognition
- Facial recognition
- Device PIN
Because passkeys are tied to a specific device and cannot be shared, intercepted or replayed, they offer significantly stronger protection against phishing attacks.
The result is a login experience that is both more secure and easier for users.
What changes are coming?
Microsoft has outlined several important milestones that organisations need to be aware of.
1 September 2026: Automatic passkey enablement
Users currently enabled for SMS or voice authentication will automatically become eligible for passkeys.
When these users next perform MFA, Microsoft will encourage them to register a passkey.
Organisations that want to control the timing of this experience should start their migration before this date.
1 February 2027: SMS and voice MFA retirement
Microsoft-provided SMS and voice authentication will be fully retired in Microsoft Entra ID.
After this date, organisations can no longer rely on Microsoft's SMS or voice-based MFA services.
After 1 February 2027: Enforcement begins
Users whose only available authentication method is SMS or voice will be blocked from continuing sign-in until they register a passkey.
This enforcement applies across all tenants and there is no option to opt out.
What does this mean for your organisation?
If your users already authenticate with phishing-resistant methods such as passkeys, little action may be required.
However, if any users still depend on SMS or voice MFA, Microsoft recommends beginning the transition as soon as possible.
Early action provides several benefits:
- Avoid disruption to users closer to the retirement date
- Control communications and onboarding on your own timeline
- Improve security posture immediately
- Reduce the risk of authentication-related support issues
A practical approach to migration
Identify affected users
The first step is understanding how many users are still relying on SMS or voice authentication.
Review your authentication methods and identify users who need to move to a more secure alternative.
Enable passkeys
Passkeys are Microsoft's recommended replacement for SMS and voice MFA.
Introducing passkeys ahead of the automatic enablement date allows users to become familiar with the new experience before it becomes the default.
Communicate early
User adoption is key to a successful migration.
Explain:
-
Why the change is happening
-
The security benefits of passkeys
-
Key deadlines
-
What users need to do
Organisations that communicate proactively are more likely to see smooth adoption and fewer support tickets.
Consider alternative SMS providers only if necessary
Some organisations may have regulatory, operational or business requirements that still demand SMS or voice authentication.
In these situations, Microsoft will allow organisations to configure a customer-managed telecom provider through the Microsoft Security Store.
However, for most organisations, Microsoft's recommendation remains the same: move users to phishing-resistant authentication wherever possible.
Don't wait until the deadline
The retirement of Microsoft-provided SMS and voice authentication isn't just a technology change—it's an opportunity to strengthen identity security and reduce exposure to increasingly sophisticated attacks.
By migrating users to passkeys now, organisations can improve security, simplify the sign-in experience and avoid disruption when enforcement begins in 2027.
The earlier you start, the easier the transition will be.
Need help planning your migration?
Codec can help you assess your current authentication methods, identify affected users, build a passkey adoption strategy and prepare your organisation for the retirement of SMS and voice MFA.
Talk to our security experts about building a phishing-resistant identity strategy with Microsoft Entra ID.
FAQ
What is changing about SMS and voice MFA?
Microsoft is retiring its SMS and voice-based authentication services for Microsoft Entra ID on 1 February 2027. Organisations currently using these authentication methods will need to move users to an alternative authentication method, such as passkeys.
Why is Microsoft retiring SMS and voice MFA?
SMS and voice-based authentication are move vulnerable to phishing, SIM-swap attacks, account takeover and replay attacks than modern authentication methods. Microsoft is moving towards phishing-resistant authentication by default to help organisations better protect their identities and data.
What are passkeys?
Passkeys are a phishing-resistant authentication method that allows users to sign in using biometrics, devise PINs or security keys instead of passwords and one-time passcodes. They provide a more secure and seamless sign in experience.
Will SMS MFA stop working immediately?
No. Microsoft provided SMS and voice authentication will continue to work until 1 February 2027. However, organisations should begin planning their migration now to avoid disruption and ensure users are prepared for the change.
What happens on 1 September 2026?
Users currently enabled for SMS and voice authentication will automatically become eligible for passkeys. Microsoft will begin prompting these users to register a passkey the next time they complete MFA.
What happens if we do nothing?
After 1 February 2027, users whose only available MFA method is SMS or voice will be required to register a passkey before they can continue signing in. This enforcement applies to all Microsoft Entra ID tenants and cannot be disabled.
Can we continue using SMS or voice authentication after February 2027?
No. Microsoft provided SMS and voice authentication will continue to work until 1 February 2027. However, organisations should begin planning their migration now to avoid disruption and ensure users are prepared for the change.