Microsoft Is Retiring SMS and Voice MFA

Why Your Business Should Move to Phishing-Resistant Authentication Now

Microsoft is making a major change to Microsoft Entra ID authentication—and businesses using SMS or voice calls for multifactor authentication (MFA) need to start planning now.

Beginning February 1, 2027, Microsoft will retire Microsoft-provided SMS and voice authentication for Microsoft Entra ID. Microsoft is also making passkeys the default authentication experience for users who currently rely on SMS or voice MFA.

For organizations that have not yet moved to phishing-resistant authentication, this is more than a technology change. It is an opportunity to significantly improve your organization’s security.

Why Is Microsoft Moving Away From SMS and Voice Authentication?

SMS and voice-based MFA have been widely used because they are simple and familiar. However, they are no longer considered strong enough to protect organizations against today’s increasingly sophisticated attacks.

Attackers can use techniques such as:

  • Phishing to trick users into providing verification codes
  • SIM swapping to redirect a victim’s phone number to an attacker’s device
  • Social engineering to convince cellular providers or users to reveal information
  • Replay attacks involving intercepted authentication codes
  • Adversary-in-the-middle attacks that can capture credentials and MFA codes

The problem is that an SMS code can prove that someone has access to a phone number—but it does not necessarily prove that the person authenticating is the legitimate user.

Phishing-resistant authentication works differently. Rather than simply providing a code that can potentially be captured, the authentication process cryptographically links the credential to the legitimate website or service.

That’s why Microsoft is recommending passkeys and other phishing-resistant authentication methods.

What Is Changing in Microsoft Entra ID?

Microsoft has established several important dates.

September 1, 2026: Passkeys Begin Becoming the Default

Users who are currently enabled for SMS or voice authentication will automatically be enabled for passkeys and will be encouraged to register a passkey the next time they complete MFA.

Organizations that want to control this transition should begin moving users away from SMS and voice before September 1, 2026.

February 1, 2027: Microsoft-Provided SMS and Voice Retire

Microsoft-provided SMS and voice authentication will be fully retired for Microsoft Entra ID.

There is an important exception: organizations that use a customer-managed telecommunications provider configured through Microsoft’s Security Store are not affected by this particular retirement.

After February 1, 2027: Users May Be Blocked

Users whose only available MFA method is SMS or voice will be required to register a passkey before they can continue signing in.

Microsoft has indicated that there will be no opt-out from this enforcement.

That makes waiting until 2027 a risky strategy.

What Should Your Organization Do?

If your organization uses Microsoft Entra ID, now is a good time to review your authentication methods.

1. Identify Users Still Using SMS or Voice

Start by determining which users in your Microsoft Entra tenant still rely on SMS or voice authentication.

Don’t assume that because your organization has MFA enabled, you’re protected against modern phishing attacks. The type of MFA matters.

2. Begin Moving Users to Passkeys

Microsoft recommends passkeys as its default phishing-resistant credential.

Depending on your environment, passkeys can provide users with a much more secure and convenient authentication experience while reducing dependence on passwords and one-time codes.

Organizations should consider implementing a registration campaign rather than waiting for Microsoft to begin automatically prompting users.

3. Communicate With Your Employees

Authentication changes can create confusion if users aren’t prepared.

Employees should understand:

  • Why the organization is changing MFA
  • What a passkey is
  • What they need to do when prompted
  • Which devices they can use
  • Why SMS codes are being phased out
  • How the change protects both the employee and the organization

A short communication campaign before deployment can prevent a significant number of help-desk calls.

4. Review Your Conditional Access Policies

Moving to phishing-resistant authentication should also be an opportunity to review your Microsoft Entra Conditional Access configuration.

Organizations should consider policies that require stronger authentication for:

  • Administrators
  • Remote access
  • Cloud applications containing sensitive information
  • Financial and business-critical applications
  • Privileged operations
  • High-risk sign-ins

Not every user and application necessarily requires the same authentication policy. A risk-based approach can provide stronger security without creating unnecessary friction.

What About Organizations That Still Need SMS or Voice?

Microsoft recognizes that some organizations may have regulatory or operational reasons for continuing to use SMS or voice authentication.

In those cases, Microsoft says organizations can configure a customer-managed telecommunications provider through the Microsoft Security Store.

However, for most organizations, continuing to depend on SMS should be viewed as a temporary exception rather than the long-term security strategy.

Don’t Wait Until Users Are Locked Out

The biggest mistake organizations can make is treating February 1, 2027 as the date they need to start.

The better approach is to use the time before the deadline to:

  1. Audit your current MFA configuration.
  2. Identify users relying on SMS or voice.
  3. Deploy passkeys or another phishing-resistant authentication method.
  4. Test the authentication experience.
  5. Educate your employees.
  6. Update Conditional Access policies.
  7. Remove legacy authentication methods where appropriate.

Starting early also gives your IT team an opportunity to deal with exceptions, older devices, shared accounts, service accounts, and applications that may require special consideration.

MFA Is No Longer Enough—The Type of MFA Matters

For years, the advice was simple: “Turn on MFA.”

That advice is still important, but it isn’t the whole story anymore.

Modern attackers have become much better at defeating traditional MFA through phishing and social engineering. Organizations should now be asking:

“Are we using phishing-resistant MFA?”

That’s the security standard businesses should be moving toward.

Passkeys, security keys, and other phishing-resistant authentication technologies can provide substantially stronger protection than SMS-based verification.

How MC Services Can Help

At MC Services, we help organizations evaluate and improve their Microsoft 365 and Microsoft Entra ID security.

Our security assessments can help identify:

  • Users still relying on weak authentication methods
  • Risky MFA configurations
  • Conditional Access gaps
  • Legacy authentication
  • Privileged accounts that need stronger protection
  • Security policies that aren’t aligned with current threats

We can also help develop a phased migration plan to phishing-resistant authentication so your organization can make the transition without unnecessarily disrupting employees.

This will close in 0 seconds