The upcoming SMS MFA retirement announced by Microsoft could affect many organisations currently using text messages or phone calls to secure Microsoft 365 accounts. For many businesses, receiving a text message containing a security code has become a normal part of signing into Microsoft 365. It’s simple, familiar and a huge improvement over relying on a password alone.
However, Microsoft has announced that it is retiring its native SMS and voice-based authentication services within Microsoft Entra ID, marking another step towards a more secure, passwordless future.
If your organisation currently uses text messages or phone calls as part of Multi-Factor Authentication (MFA), here’s what you need to know.
What’s Changing With SMS MFA Retirement?
Microsoft is making passkeys the default authentication method within Microsoft Entra ID.
From 1 September 2026, users who currently rely on SMS or voice authentication will begin receiving prompts to register a passkey when they complete MFA. Microsoft will automatically start encouraging organisations to move towards phishing-resistant authentication methods.
The bigger change arrives on 1 February 2027, when Microsoft-provided SMS and voice authentication services will be retired. Organisations that still require these methods will need to use a third-party telecom provider through Microsoft’s Security Store.
Read more from Microsoft Learn here: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication – Microsoft Entra ID | Microsoft Learn
For most businesses, Microsoft’s recommendation is clear: move to passkeys or other phishing-resistant authentication methods instead.
Why Is Microsoft Doing This?
Cyber criminals are becoming increasingly sophisticated, and traditional authentication methods are struggling to keep pace.
While SMS-based MFA is significantly safer than using a password alone, it is not considered phishing-resistant. Attackers can target users through phishing websites, social engineering techniques and even SIM-swapping attacks in certain circumstances. Microsoft states that passkeys provide far stronger protection because they use public-key cryptography rather than shared secrets or one-time codes.
In simple terms, Microsoft believes the future of authentication should be both more secure and easier for users.
How Does SMS MFA Retirement Affect My Business?
Potentially, yes.
Many Microsoft 365 tenants still have users authenticating via text message codes or automated phone calls, particularly among smaller organisations that adopted MFA several years ago.
If your users currently receive a text message containing a verification code when signing in, they may be affected by these changes.
The good news is that there is plenty of time to prepare.
What Should Businesses Do Now?
There’s no need to panic, but this is a sensible time to review your authentication policies.
We recommend:
- Identifying users who currently rely on SMS or voice authentication.
- Reviewing your Microsoft Entra authentication settings.
- Beginning discussions around passkey adoption.
- Educating staff about upcoming changes to the sign-in experience.
- Ensuring your organisation continues to follow Microsoft’s security best practices.
For many organisations, this transition could actually improve the user experience by reducing the number of passwords and security codes employees need to manage.
Looking Ahead
Passwords have been with us for decades, but the industry is gradually moving towards stronger and more user-friendly methods of authentication.
Microsoft’s decision to retire native SMS and voice authentication is another sign that passwordless technologies are becoming mainstream. Over the coming months, businesses will hear much more about passkeys and phishing-resistant authentication as the Microsoft ecosystem continues to evolve.
The key message is simple: now is the ideal time to understand how your users sign in and start planning for the future.
How Core Team One Can Help
If you’re unsure how your users currently authenticate to Microsoft 365, Core Team One can help. We can review your existing security configuration, identify users affected by the SMS authentication retirement, and guide your business towards a secure, user-friendly authentication strategy.
Get in touch with our team today for a friendly, no-obligation discussion.