top of page

Microsoft Is Phasing Out SMS MFA: What Businesses Need to Know Before 2027

For years, businesses have been told to enable multifactor authentication to make Microsoft 365 accounts harder to compromise.


Split-screen: worried man enters phone code, smiling man signs in with passkey at laptop in modern offices.

That advice is still correct. But Microsoft is now making an important distinction: not all MFA methods provide the same level of protection.


Microsoft has announced that it is moving Microsoft Entra ID users away from SMS text messages and voice calls and toward phishing-resistant authentication methods such as passkeys, Windows Hello for Business, and FIDO2 security keys.

And there are now two important dates businesses need to know:

  • September 1, 2026: Microsoft begins automatically enabling passkeys and prompting eligible SMS and voice MFA users to register them.

  • February 1, 2027: Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID.


For businesses using Microsoft 365, this is something worth preparing for now rather than waiting for employees to encounter a new sign-in prompt.


What Is Microsoft Changing?

Beginning September 1, 2026, Microsoft says users who are enabled for SMS or voice authentication will automatically be enabled for passkeys.


When those users complete MFA during a sign-in, Microsoft may prompt them to register a passkey.


Microsoft describes this as part of its effort to make phishing-resistant authentication the default experience in Microsoft Entra ID.


The bigger deadline comes a few months later.


Beginning February 1, 2027, Microsoft will retire the telecommunications service it currently provides for SMS and voice authentication.


Businesses that still have employees whose only MFA option is a text message or phone call could experience sign-in disruption if they have not prepared for the change. Microsoft says that users in this situation will be required to register a passkey before they can continue signing in.


Importantly, Microsoft says there will be no opt-out from the February 1, 2027 enforcement date.


Infographic titled Prepare for the MFA Change with five steps, dates, icons, and a shield; notes passkeys, SMS MFA, and device review.

Does This Mean Microsoft Is Eliminating MFA by Text Message Completely?

Not exactly.


Microsoft is eliminating Microsoft-provided SMS and voice delivery in Entra ID.

Organizations with a legitimate operational, regulatory, or technical requirement to continue using SMS or voice will have another option: they can use a customer-managed telecommunications provider.


Microsoft says information about supported providers will begin becoming available on September 18, 2026, with configuration becoming available beginning October 30, 2026.


For most businesses, however, Microsoft recommends moving users toward stronger authentication methods rather than simply replacing one SMS provider with another.


Why Is Microsoft Moving Away From SMS MFA?

The issue is not that SMS MFA provides no protection.


It is generally much better than protecting an account with a password alone.

The problem is that attackers have become much better at defeating traditional forms of MFA.


Text messages and phone calls can be vulnerable to techniques such as phishing, social engineering, SIM-related attacks, and attacks in which users are tricked into approving or revealing authentication information.


Microsoft now describes SMS and voice authentication as comparatively weak authentication methods and is steering organizations toward phishing-resistant authentication.


TA traditional phishing attack might attempt to steal both your password and the temporary code sent to your phone.


A properly implemented passkey works differently. Authentication is cryptographically tied to the legitimate service, making it far more difficult for a fake Microsoft login page to capture credentials that an attacker can reuse.


The security conversation is therefore changing from:

“Do we have MFA?”

to:

“What kind of MFA are we using?”


What Is a Passkey?

A passkey is a passwordless authentication credential based on public-key cryptography.


Instead of typing a password and then entering a six-digit code sent through SMS, a user can authenticate using a trusted device combined with something such as a fingerprint, face recognition, or device PIN.


Microsoft Entra ID supports passkey-based authentication along with other phishing-resistant methods such as Windows Hello for Business and FIDO2 security keys.


For employees, the experience can eventually be easier than passwords and text-message codes.


For IT administrators, however, moving an organization to passkeys still requires planning.


What Should Businesses Do Before September 1?

The first step is simply understanding your current environment.


Microsoft specifically recommends identifying users who are still actively using SMS or voice authentication.


Businesses should review:

  • Which employees still rely on text-message or voice-call MFA

  • Whether passkeys are enabled in Microsoft Entra ID

  • Which devices employees use to authenticate

  • Whether Windows Hello for Business or FIDO2 authentication is already deployed

  • Whether any employees have unusual accessibility, device, regulatory, or operational requirements

  • How employees will be informed about upcoming registration prompts


Organizations can also proactively launch a Microsoft Entra registration campaign that prompts users to register passkeys rather than waiting for Microsoft's September rollout.


There is also a temporary opt-out available for the automatic passkey enablement taking place between September 2026 and February 2027. That option may be useful for organizations that need more time to complete their migration.


It does not, however, eliminate the February 1, 2027 deadline.


Don't Wait Until Employees Cannot Sign In

Microsoft 365 authentication changes can sound like an IT department issue until dozens of employees encounter an unfamiliar prompt Monday morning.


That is why businesses should treat this as a change-management project as much as a cybersecurity project.


A well-managed transition should include:

  1. Identifying affected users.

  2. Selecting appropriate phishing-resistant authentication methods.

  3. Testing those methods with a smaller group.

  4. Communicating the change to employees.

  5. Migrating users well before the February deadline.

  6. Confirming that fallback and recovery processes are appropriate.


Businesses with managed Microsoft 365 environments should also confirm that their IT provider is already planning for the transition.


MFA Isn't Going Away. It's Getting Stronger.

Microsoft's move away from SMS authentication reflects a broader change taking place across cybersecurity.


Attackers increasingly target identities rather than simply trying to infect computers.


Passwords alone are not enough, and increasingly, basic MFA is not enough either.


Microsoft's September 2026 passkey rollout and February 2027 SMS/voice retirement give businesses a clear opportunity to review how employees authenticate before the change becomes urgent.


For most organizations, the goal should not simply be to satisfy Microsoft's deadline.


It should be to use the deadline as an opportunity to move toward authentication that is both easier for employees and significantly more resistant to modern phishing attacks.


At Kosh Solutions, we manage Microsoft 365 environments and cybersecurity for businesses that don't want major platform changes to become last-minute emergencies. If you're unsure how your organization currently uses MFA or whether your Microsoft 365 environment is ready for Microsoft's passkey transition, this is a good time to review it.

Glossary

FIDO2: An open authentication standard that lets users sign in securely without relying on passwords, using methods such as passkeys, security keys, biometrics, or device PINs. It is designed to resist phishing because the authentication credential is tied to the legitimate website or service.

Sources

Disclaimer


The information contained in this communication is intended for limited use for informational purposes only. It is not considered professional advice, and instead, is general information that may or may not apply to specific situations. Each case is unique and should be evaluated on its own by a professional qualified to provide advice specifically intended to protect your individual situation. Kosh is not liable for improper use of this information.


Comments


bottom of page