Microsoft Is Retiring SMS Authentication. Here's What Your Business Needs to Know
Microsoft has announced a significant change to how users authenticate into Microsoft 365 and Entra ID. Passkeys will become the default authentication method, while Microsoft-provided SMS and voice authentication will be retired on 1 February 2027.
For businesses currently relying on text message codes for multi-factor authentication (MFA), now is the time to start planning for the transition.
Why Is Microsoft Making This Change?
Cyber threats continue to evolve, and traditional authentication methods such as SMS and voice calls are becoming increasingly vulnerable to phishing, credential theft, social engineering and SIM-swapping attacks.
Passkeys use modern cryptography rather than passwords or SMS codes, making them significantly more resistant to these types of attacks while also improving the user experience.
What Is a Passkey?
A passkey is a passwordless way to sign in using a trusted device and its built-in security features, such as:
- Windows Hello
- Face ID
- Touch ID
- Microsoft Authenticator
- FIDO2 Security Keys
Instead of entering passwords or waiting for a text message, users simply verify their identity using a biometric scan or secure device PIN.
Benefits of Passkeys
- Stronger protection against phishing attacks
- Faster, simpler sign-ins
- Reduced reliance on passwords
- Improved security for Microsoft 365 accounts
- Fewer authentication-related support issues
Important Dates
1 September 2026
Microsoft will begin enabling Passkeys for users currently relying on SMS or voice authentication. Users will be prompted to register a Passkey the next time they complete multi-factor authentication.
30 October 2026
Organisations that still require SMS or voice authentication will be able to configure a third-party telecommunications provider through Microsoft's Security Store.
1 February 2027
Microsoft-provided SMS and voice authentication will be retired.
After 1 February 2027
Users who only have SMS or voice authentication configured will be required to register a Passkey before they can continue signing in.
What This Means for Our Customers
For many organisations, the impact will be minimal if modern authentication methods are already in use. However, businesses that still rely heavily on SMS-based MFA should begin preparing now.
The transition provides an opportunity to strengthen your organisation's security, reduce the risk of account compromise and improve the overall sign-in experience for your team.
The key steps include:
- Identifying users still using SMS or voice authentication
- Planning and testing a Passkey rollout
- Educating staff on upcoming changes
- Ensuring business continuity during migration
- Implementing phishing-resistant authentication methods
How Native Digital Is Helping
We're already helping our customers prepare for Microsoft's move toward phishing-resistant, passwordless authentication.
Our team can assist with:
- Reviewing your current Microsoft 365 security configuration
- Identifying users affected by the upcoming changes
- Implementing and configuring Passkeys
- Supporting Microsoft Authenticator Passkeys
- Deploying FIDO2 security keys where appropriate
- User communication and training
- Rollout planning and testing
- General Microsoft 365 security reviews and best practice recommendations
Don't Wait Until 2027
While the retirement date may seem some distance away, organisations that begin planning now will avoid last-minute disruption and give users time to become familiar with the new sign-in experience.
Microsoft has made it clear that phishing-resistant authentication is the future, and Passkeys are becoming a core component of modern identity security.
If you'd like help understanding how these changes affect your organisation, contact the Native Digital team. We'll help assess your environment, develop a migration plan and ensure you're ready well before SMS and voice authentication are retired.