Microsoft is moving organisations away from SMS and voice MFA due to the growing risk of phishing, SIM-swap and account takeover attacks.
Here are some of the key dates and important milestones organisations need to be aware of.
Users currently enabled for SMS or voice authentication will automatically become eligible for passkeys.
When these users next perform MFA, Microsoft will encourage them to register a passkey.
Organisations that want to control the timing of this experience should start their migration before this date.
Microsoft-provided SMS and voice authentication will be fully retired in Microsoft Entra ID.
After this date, organisations can no longer rely on Microsoft's SMS or voice-based MFA services.
Users whose only available authentication method is SMS or voice will be blocked from continuing sign-in until they register a passkey.
This enforcement applies across all tenants and there is no option to opt out.
Don't wait until 2027 to address a critical security change.
Talk to Codec about building a phishing-resistant identity strategy with Microsoft Entra ID.
Microsoft is retiring its SMS and voice-based authentication services for Microsoft Entra ID on 1st February 2027. Organisations currently using these authentication methods will need to move users to an alternative authentication method, such as passkeys.
SMS and voice-based authentication are move vulnerable to phishing, SIM-swap attacks, account takeover and replay attacks than modern authentication methods. Microsoft is moving towards phishing-resistant authentication by default to help organisations better protect their identities and data.
No. Microsoft provided SMS and voice authentication will continue to work until 1st February 2027. However, organisations should begin planning their migration now to avoid disruption and ensure users are prepared for the change.
After 1st February 2027, users whose only available MFA method is SMS or voice will be required to register a passkey before they can continue signing in. This enforcement applies to all Microsoft Entra ID tenants and cannot be disabled.
No. Microsoft provided SMS and voice authentication will continue to work until 1st February 2027. However, organisations should begin planning their migration now to avoid disruption and ensure users are prepared for the change.