valence

the capacity of one person or thing to react with or affect another in some special way, as by attraction or the facilitation of a function or activity.

Microsoft retiring SMS/voice-based MFA

Posted on | August 11, 2026 | No Comments

Here’s a simplified summary of this Microsoft Entra ID authentication change, with the key action items broken out clearly.

Executive summary

Microsoft is retiring SMS/voice-based MFA (multi-factor authentication) in Entra ID on February 1, 2027, replacing it with passkeys as the default, phishing-resistant sign-in method. This affects only tenants with users currently using SMS or voice codes to sign in — organizations that already use apps, hardware keys, or passkeys for MFA are unaffected.

Who this actually applies to

  • No action needed: If no users in your tenant are enabled for SMS or voice MFA, you can disregard this entirely.
  • Action required: If even one user is enabled for SMS or voice MFA, that user (and your organization) must transition them to passkeys or another phishing-resistant method before February 1, 2027.
  • Special case: Organizations with a regulatory or operational need to keep SMS/voice must configure a customer-managed telecom provider through the Microsoft Security Store — this is a separate workaround, not the default path.

Key dates

DateWhat happens
September 1, 2026Users still on SMS/voice are auto-enrolled for passkeys and nudged to register one at their next MFA prompt. You can opt out of this specific nudge by moving users off SMS/voice beforehand.
February 1, 2027Microsoft-provided SMS/voice authentication is fully retired — no exceptions, no opt-out.
After February 1, 2027Any user whose only MFA method is SMS/voice gets a blocking prompt and cannot sign in until they register a passkey.
Sept 18 – Oct 30, 2026Window for reviewing/configuring a third-party (customer-managed) telecom provider, if that’s needed instead.

Why it’s changing

SMS and voice codes are the weakest MFA methods available, vulnerable to phishing, SIM-swapping, and replay attacks. Passkeys resist these attacks because they’re tied to a device and can’t be intercepted or phished the same way.

Recommended action steps (for affected tenants only)

  • Identify which users are currently enabled for SMS or voice MFA in the Authentication Methods Policy.
  • Enable passkeys and run a registration push to get those users switched over before September 1, 2026 (this avoids the auto-enrollment nudge and later blocking prompts).
  • Communicate the change directly to affected users — what’s changing, when, and what they need to do.
  • Only if there’s a genuine regulatory/operational requirement to keep SMS/voice: evaluate a customer-managed telecom provider via the Microsoft Security Store before the Feb 1, 2027 cutoff.

The bottom line for your clients: check if anyone is using SMS/voice for MFA — if not, ignore this notice; if so, get them onto passkeys well before September 2026 to stay in control of the timeline rather than being forced into it.

Comments

Comments are closed.

  • About

    This website is supported by Ken Lombardi @ analogman consulting.
    phone: 253.two.two.two-7626
    email: ken@analogman'dot'org
    tweet: analogmanorg

  • Admin