Microsoft office building representing changes to SMS authentication and passkey security

Microsoft Is Retiring SMS Authentication: What Businesses Need to Know

Microsoft is changing how businesses protect user sign-ins. The announcement of Microsoft retiring SMS authentication marks a major shift toward phishing-resistant authentication. Microsoft-provided SMS and voice authentication will retire in Microsoft Entra ID on February 1, 2027. Before then, Microsoft will begin moving affected users toward passkeys.

Businesses still using text messages or voice calls for multi-factor authentication should prepare now. Early planning can reduce user disruption and last-minute support requests. It also gives IT teams more time to test policies and support employees. A phased transition is easier than a rushed migration near the deadline.

SMS and voice authentication improved security compared with passwords alone. However, these methods still rely on information attackers can intercept or manipulate. SMS codes can be targeted through phishing, SIM-swapping, social engineering, and replay attacks. Microsoft now recommends phishing-resistant authentication methods for stronger identity protection.

The move toward Microsoft retiring SMS authentication is part of Microsoft’s broader shift toward passkeys. Passkeys use cryptographic credentials instead of shared verification codes. Microsoft says passkeys resist phishing, SIM-swapping, and replay attacks. They also remove the need to wait for a text message.

User signing in with a passkey on a smartphone

A passkey is a passwordless credential used to verify a user’s identity. It can remain on one device or sync across supported devices. Users can unlock passkeys through fingerprints, facial recognition, or a device PIN. FIDO2 security keys can also provide passkey authentication.

Unlike SMS codes, passkeys are not reusable secrets sent across a telecommunications network. Each credential is connected to the legitimate website or application. Microsoft explains that passkeys use public-key cryptography. This design helps protect users from common remote phishing attacks.

Microsoft is introducing this transition in stages. Businesses should understand both major dates because each creates different requirements. For businesses, Microsoft retiring SMS authentication creates a clear migration deadline. Waiting until early 2027 leaves less time for testing and employee education.

Date What Changes What Businesses Should Do
September 1, 2026 Users enabled for SMS or voice authentication are automatically enabled for passkeys. Microsoft will begin prompting eligible users to register. Notify employees, review authentication policies, and begin passkey registration.
February 1, 2027 Microsoft-provided SMS and voice authentication services will retire in Microsoft Entra ID. Move affected users to passkeys or another supported phishing-resistant authentication method.
After February 1, 2027 Users relying only on Microsoft-provided SMS or voice authentication cannot continue using those methods for MFA. Ensure affected users have another authentication method or an approved customer-managed telecom option.

Microsoft states there is no opt-out from the February 1, 2027 retirement. Organizations needing SMS or voice can use customer-managed telecom providers. Those providers will operate through the Microsoft Security Store. Businesses should review Microsoft’s retirement guidance before planning exceptions.

Organizations should review their Microsoft Entra authentication methods before assuming they are prepared. Some employees may still depend on SMS without administrators realizing it. Businesses are most affected when employees use text messages or voice calls as their primary MFA method. Those users will need another supported authentication method.

Organizations should treat Microsoft retiring SMS authentication as an identity-management project, not simply a user preference change. Authentication policies, devices, training, and support processes may require review. Businesses already using passkeys or Windows Hello for Business are in a stronger position. Administrators should still identify users enabled for SMS or voice.

Preparing for Microsoft retiring SMS authentication should begin with an inventory of current authentication methods. The goal is identifying affected users before deadlines create pressure. Administrators should also identify users with only one authentication option. Those accounts deserve priority because they face the greatest disruption risk.

Review your Microsoft Entra authentication policies and determine who still uses SMS or voice. This provides a clear starting point for migration planning. Administrators should also identify users who lack another authentication method. These accounts may require additional support during the transition.

Microsoft provides guidance for identifying users enabled for SMS or voice authentication. Reviewing this information early can reveal how large the migration will be. It also helps organizations create a more realistic rollout schedule. Larger user groups may require a phased approach.

Begin enabling passkeys for appropriate users before the retirement date. Start with a controlled group before expanding the rollout. Microsoft recommends passkeys as the primary migration path where possible. Testing can reveal device limitations, application issues, or employee questions.

Microsoft provides detailed guidance for deploying phishing-resistant passwordless authentication. Organizations should review device compatibility and authentication policies before wider deployment. Early testing can reduce unexpected problems during the final rollout. It also gives IT teams time to adjust their procedures.

Authentication changes affect every employee who signs in. Communication should explain what is changing, why it matters, and required employee actions. Provide clear registration instructions before employees receive unexpected prompts. Users should also know where to request help.

Training can also explain why stronger authentication methods matter. Employees remain frequent targets for phishing and other credential attacks. Our guide to social engineering attacks explains how criminals manipulate users and credentials. Connecting the change to real security risks can improve employee understanding.

Some organizations may have regulatory or operational reasons to continue using SMS or voice. Microsoft plans to support customer-managed telecommunications providers through the Microsoft Security Store. Businesses with legitimate telecom requirements should identify those specific users. Most users should still move toward phishing-resistant authentication.

Organizations should avoid treating an exception as the default for every employee. Continuing SMS may make sense for specific business or technical requirements. Those cases should be documented and reviewed individually. Microsoft still recommends passkeys for most users where deployment is practical.

Is Your Business Ready for Microsoft’s MFA Changes?

Microsoft-provided SMS and voice authentication will be retired in 2027. Businesses that wait too long may face rushed migrations, support issues, and employee sign-in disruptions. Onsite Computing can help review your Microsoft environment, identify affected users, and create a phased transition plan for passkeys and stronger authentication methods.

The deadline for Microsoft retiring SMS authentication may appear distant. However, authentication changes become harder when many employees need assistance simultaneously. An early rollout gives IT teams time to test policies and prepare instructions. It also provides time to resolve unusual user situations.

Waiting creates a different problem. A rushed migration can increase support requests and create avoidable sign-in interruptions. Businesses using outside IT support should coordinate the migration with their provider. Managed IT services can provide additional resources for planning, deployment, and employee support.

The objective is not simply meeting Microsoft’s deadline. Businesses can use this transition to strengthen their overall identity security. Removing weaker authentication methods can reduce exposure to credential-based attacks. Planning early gives organizations greater control over how that transition happens.

Ultimately, Microsoft retiring SMS authentication gives businesses a defined deadline to modernize identity security. Waiting until 2027 can create unnecessary pressure and support demand. Start by reviewing your Microsoft Entra environment and identifying affected users. Then create a phased plan for passkey registration and employee communication.

Onsite Computing can help assess your existing authentication policies and identify users who still depend on SMS or voice. Our team can also assist with passkey planning, deployment, and employee support. This approach can reduce disruption while improving the security of your Microsoft environment. Contact Onsite Computing to begin preparing for Microsoft’s February 2027 deadline.


Microsoft is retiring its own SMS and voice delivery within Microsoft Entra ID on February 1, 2027. This change does not ban telecommunications authentication everywhere. Organizations with valid requirements may use customer-managed telecom providers. Microsoft still recommends phishing-resistant methods for most users.

Microsoft-provided SMS and voice authentication will retire on February 1, 2027. Eligible users will also be enabled for passkeys beginning September 1, 2026. Microsoft will begin prompting those users to register. Businesses should complete their migration before the final retirement date.

Microsoft is making passkeys the default authentication experience for affected users. Other supported options include Windows Hello for Business and FIDO2 security keys. The right method depends on devices, policies, user needs, and security requirements. Businesses should test their chosen approach before wider deployment.

Passkeys are designed to resist phishing through cryptographic credentials tied to the legitimate service. They are not transmitted as reusable verification codes. Microsoft also states that passkeys resist SIM-swap and replay attacks. These protections make passkeys stronger than SMS-based verification.

Businesses should first identify employees who still use SMS or voice authentication. Next, choose supported replacement methods and begin a controlled rollout. Communicate the change early and provide clear registration instructions. Test the new process before deploying it across the organization.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses cookies to offer you a better browsing experience. By browsing this website, you agree to our use of cookies.