unsplash-image-j4uuKnN43_M.jpg

IT News from SNH

Weekly Tech Updates

Navigating the complexities of today's IT landscape can be daunting. Whether you're a small business owner grappling with data security, a medium-sized company aiming to streamline its IT infrastructure, or a large corporation looking for custom solutions, we've got you covered. Our team of highly skilled, Santa Rosa Beach-based IT professionals are always on hand to offer the best-in-class IT services that your business deserves.

You can learn more about managing IT services with regular industry updates, best practices, cybersecurity tips, and much more. The goal is to help you make informed decisions about your technology investments. In addition, we highlight how our services can specifically help businesses in Walton County stay competitive and secure.

As your local IT company, we're not just technology experts; we’re experts in understanding the unique IT needs of local businesses like yours. Our knowledge is informed by the area business climate and specific needs of companies on 30A-Santa Rosa Beach-Panama City Beach. Here you’ll find tailored solutions to help you maximize productivity, efficiency, and security, ensuring your technology infrastructure grows with your business.

Be sure to subscribe for regular updates on all things IT. We're excited to be your go-to resource for managed IT services in Santa Rosa Beach. With a wealth of local experience and expertise, you can trust us to keep your business at the cutting edge of technology. As a local company, we're proud to be part of the 30A-Santa Rosa Beach community and are dedicated to helping area businesses like yours thrive in the modern digital world.

At SNH Technologies, we're more than just an IT company - we're your local IT partner. Remember, when it comes to IT consulting in Santa Rosa Beach and the Florida panhandle, think local, think SNH Technologies.

Just When Everyone Got Used to Text MFA, Microsoft Is Changing It

It may feel like everyone has finally gotten used to receiving a text message or phone call to verify a Microsoft 365 sign-in.

Now Microsoft is changing it again.

Microsoft has announced that its SMS and voice authentication methods will retire on February 1, 2027. In their place, Microsoft is moving users toward passkeys and other phishing-resistant authentication methods.

The change may create some short-term frustration, but it is being made for a good reason: text messages and phone calls are no longer considered strong enough protection for modern cyber threats.

Why Text MFA is Going Away

Text-based multifactor authentication is still much safer than using only a password. However, attackers have become increasingly effective at intercepting or tricking users into sharing verification codes.

SMS and voice authentication can be vulnerable to:

  • Phishing attacks

  • SIM swapping

  • Stolen verification codes

  • Call forwarding

  • Social engineering

  • Replay attacks

Passkeys are designed to avoid many of these risks. Instead of typing a code from a text message, users verify their identity through a trusted device using a fingerprint, facial recognition, device PIN, or hardware security key.

Because a passkey is tied to the legitimate website or application, it cannot be entered into a fake Microsoft login page in the same way a password or verification code can.

Important Dates for Microsoft 365 Users

September 1, 2026

Users who are currently enabled for SMS or voice authentication will automatically be enabled for passkeys.

Microsoft will begin prompting those users to register a passkey when they complete multifactor authentication.

Organizations that want a more controlled rollout should begin moving users before this date.

February 1, 2027

Microsoft-provided SMS and voice authentication will be fully retired in Microsoft Entra ID.

After this date, users whose only authentication method is a text message or phone call will receive a blocking prompt and will have to register a passkey before continuing to sign in.

Microsoft has stated that there will be no opt-out from this requirement.

Does Every Organization Need to Act?

Organizations that do not have any users enabled for SMS or voice authentication may not need to make changes.

However, many businesses still have employees, executives, field staff, shared accounts, or legacy users relying on phone-based authentication.

Those users should be identified and transitioned well before the deadline.

Microsoft will allow organizations with a regulatory or operational need to continue using SMS or voice through a customer-managed telecommunications provider available through the Microsoft Security Store. Provider options and pricing are expected beginning September 18, 2026, with configuration available beginning October 30, 2026.

For most organizations, though, moving to passkeys or another phishing-resistant method will be the better long-term approach.

What Businesses Should Do Now

The biggest mistake would be waiting until users are blocked from signing in.

Organizations should begin preparing by:

  1. Identifying affected users and accounts

  2. Enabling passkeys or another approved phishing-resistant method

  3. Testing registration and recovery procedures

  4. Communicating the change clearly to employees

  5. Running a phased registration campaign

  6. Updating onboarding and offboarding procedures

  7. Addressing shared accounts, service accounts, and users without compatible devices

Waiting until February 2027 could result in employees being blocked from Microsoft 365 applications until they complete registration.

Acting before September 1, 2026 gives organizations more control over the timing, communication, and user experience.

What Is a Passkey?

A passkey allows a user to sign in using a trusted device and a secure unlock method such as:

  • Facial recognition

  • A fingerprint

  • A device PIN

  • A hardware security key

The passkey replaces the need to enter a reusable password or a code sent by text message.

Because the credential is linked to the legitimate website or application, it is significantly harder for an attacker to steal through a fake login page.

The Bottom Line on Passkeys

Yes, it may feel like everyone finally learned how to use text-message MFA…and now the process is changing again.

But cybersecurity does not stand still.

Microsoft is retiring SMS and voice authentication because stronger, phishing-resistant options are now available. Organizations that begin preparing before September 1, 2026 will have more time to educate users, resolve compatibility issues, and avoid disruptive sign-in problems.

SNH Technologies can help identify affected users, configure Microsoft Entra authentication policies, roll out passkeys, and guide employees through the transition.