Just When Everyone Got Used to Text MFA, Microsoft Is Changing It
It may feel like everyone has finally gotten used to receiving a text message or phone call to verify a Microsoft 365 sign-in.
Now Microsoft is changing it again.
Microsoft has announced that its SMS and voice authentication methods will retire on February 1, 2027. In their place, Microsoft is moving users toward passkeys and other phishing-resistant authentication methods.
The change may create some short-term frustration, but it is being made for a good reason: text messages and phone calls are no longer considered strong enough protection for modern cyber threats.
Why Text MFA is Going Away
Text-based multifactor authentication is still much safer than using only a password. However, attackers have become increasingly effective at intercepting or tricking users into sharing verification codes.
SMS and voice authentication can be vulnerable to:
Phishing attacks
SIM swapping
Stolen verification codes
Call forwarding
Social engineering
Replay attacks
Passkeys are designed to avoid many of these risks. Instead of typing a code from a text message, users verify their identity through a trusted device using a fingerprint, facial recognition, device PIN, or hardware security key.
Because a passkey is tied to the legitimate website or application, it cannot be entered into a fake Microsoft login page in the same way a password or verification code can.
Important Dates for Microsoft 365 Users
September 1, 2026
Users who are currently enabled for SMS or voice authentication will automatically be enabled for passkeys.
Microsoft will begin prompting those users to register a passkey when they complete multifactor authentication.
Organizations that want a more controlled rollout should begin moving users before this date.
February 1, 2027
Microsoft-provided SMS and voice authentication will be fully retired in Microsoft Entra ID.
After this date, users whose only authentication method is a text message or phone call will receive a blocking prompt and will have to register a passkey before continuing to sign in.
Microsoft has stated that there will be no opt-out from this requirement.
Does Every Organization Need to Act?
Organizations that do not have any users enabled for SMS or voice authentication may not need to make changes.
However, many businesses still have employees, executives, field staff, shared accounts, or legacy users relying on phone-based authentication.
Those users should be identified and transitioned well before the deadline.
Microsoft will allow organizations with a regulatory or operational need to continue using SMS or voice through a customer-managed telecommunications provider available through the Microsoft Security Store. Provider options and pricing are expected beginning September 18, 2026, with configuration available beginning October 30, 2026.
For most organizations, though, moving to passkeys or another phishing-resistant method will be the better long-term approach.
What Businesses Should Do Now
The biggest mistake would be waiting until users are blocked from signing in.
Organizations should begin preparing by:
Identifying affected users and accounts
Enabling passkeys or another approved phishing-resistant method
Testing registration and recovery procedures
Communicating the change clearly to employees
Running a phased registration campaign
Updating onboarding and offboarding procedures
Addressing shared accounts, service accounts, and users without compatible devices
Waiting until February 2027 could result in employees being blocked from Microsoft 365 applications until they complete registration.
Acting before September 1, 2026 gives organizations more control over the timing, communication, and user experience.
What Is a Passkey?
A passkey allows a user to sign in using a trusted device and a secure unlock method such as:
Facial recognition
A fingerprint
A device PIN
A hardware security key
The passkey replaces the need to enter a reusable password or a code sent by text message.
Because the credential is linked to the legitimate website or application, it is significantly harder for an attacker to steal through a fake login page.
The Bottom Line on Passkeys
Yes, it may feel like everyone finally learned how to use text-message MFA…and now the process is changing again.
But cybersecurity does not stand still.
Microsoft is retiring SMS and voice authentication because stronger, phishing-resistant options are now available. Organizations that begin preparing before September 1, 2026 will have more time to educate users, resolve compatibility issues, and avoid disruptive sign-in problems.
SNH Technologies can help identify affected users, configure Microsoft Entra authentication policies, roll out passkeys, and guide employees through the transition.