Microsoft retiring SMS/voice-based MFA
Posted on | August 11, 2026 | No Comments
Here’s a simplified summary of this Microsoft Entra ID authentication change, with the key action items broken out clearly.
Executive summary
Microsoft is retiring SMS/voice-based MFA (multi-factor authentication) in Entra ID on February 1, 2027, replacing it with passkeys as the default, phishing-resistant sign-in method. This affects only tenants with users currently using SMS or voice codes to sign in — organizations that already use apps, hardware keys, or passkeys for MFA are unaffected.
Who this actually applies to
- No action needed: If no users in your tenant are enabled for SMS or voice MFA, you can disregard this entirely.
- Action required: If even one user is enabled for SMS or voice MFA, that user (and your organization) must transition them to passkeys or another phishing-resistant method before February 1, 2027.
- Special case: Organizations with a regulatory or operational need to keep SMS/voice must configure a customer-managed telecom provider through the Microsoft Security Store — this is a separate workaround, not the default path.
Key dates
| Date | What happens |
|---|---|
| September 1, 2026 | Users still on SMS/voice are auto-enrolled for passkeys and nudged to register one at their next MFA prompt. You can opt out of this specific nudge by moving users off SMS/voice beforehand. |
| February 1, 2027 | Microsoft-provided SMS/voice authentication is fully retired — no exceptions, no opt-out. |
| After February 1, 2027 | Any user whose only MFA method is SMS/voice gets a blocking prompt and cannot sign in until they register a passkey. |
| Sept 18 – Oct 30, 2026 | Window for reviewing/configuring a third-party (customer-managed) telecom provider, if that’s needed instead. |
Why it’s changing
SMS and voice codes are the weakest MFA methods available, vulnerable to phishing, SIM-swapping, and replay attacks. Passkeys resist these attacks because they’re tied to a device and can’t be intercepted or phished the same way.
Recommended action steps (for affected tenants only)
- Identify which users are currently enabled for SMS or voice MFA in the Authentication Methods Policy.
- Enable passkeys and run a registration push to get those users switched over before September 1, 2026 (this avoids the auto-enrollment nudge and later blocking prompts).
- Communicate the change directly to affected users — what’s changing, when, and what they need to do.
- Only if there’s a genuine regulatory/operational requirement to keep SMS/voice: evaluate a customer-managed telecom provider via the Microsoft Security Store before the Feb 1, 2027 cutoff.
The bottom line for your clients: check if anyone is using SMS/voice for MFA — if not, ignore this notice; if so, get them onto passkeys well before September 2026 to stay in control of the timeline rather than being forced into it.