For many employees, signing in to Microsoft 365 is familiar: enter a password, wait for a text message or phone call, then type in the code.
That process is changing.
If your employees receive a text message or automated phone call with a code when signing in to Microsoft 365, they may be affected.
- September 1, 2026
Microsoft may prompt users who rely on SMS or voice MFA to set up a passkey.
February 1, 2027,
Microsoft-provided SMS and voice authentication will retire in Microsoft Entra ID.
After that date, users who only have SMS or voice set up for MFA may be unable to continue signing in until they register a passkey or another approved method.
This does not mean Microsoft is removing MFA. It means Microsoft is replacing less secure text-message and phone-call codes with stronger sign-in options.
Video credit: Jonathan Edwards (@bearded365guy)
“Microsoft Is Killing SMS MFA – Your 2027 Deadline” | YouTube
Why is Microsoft making this change?
Microsoft says, “The AI era demands stronger, phishing-resistant authentication.”
In plain language, text-message and phone-call codes are easier for criminals to target. A scammer may try to trick someone into sharing a code, take over a phone number, or use a fake sign-in page to capture credentials.
Text and voice codes still add a layer of protection compared with using a password alone. However, they are not as strong as newer sign-in methods because the code can be intercepted, stolen, or shared.
Microsoft is moving toward phishing-resistant authentication to help organizations better protect business accounts, Microsoft 365 data, and access to systems that employees use every day.
What is a passkey?
A passkey is a safer way to prove it is really you when signing in.
Instead of receiving and entering a code, a user confirms their identity with a trusted method on their device, such as:
- A fingerprint
- Facial recognition
- A device PIN
- Microsoft Authenticator
- A FIDO2 security key
Passkeys are tied to the user’s device or approved credential manager. This means there is no texted code for a scammer to steal and no code for an employee to accidentally share.
For the user, the experience can be simpler: rather than waiting for a message and typing a number, they approve the sign-in using their device.
What exactly is changing?
Microsoft Entra ID is the identity service behind Microsoft 365 sign-ins for many organizations. It helps control who can access services such as Outlook, Teams, OneDrive, SharePoint, and other business applications.
For users who are currently enabled for SMS or voice MFA:
-
September 1, 2026: Passkey prompts may begin
Microsoft will automatically enable passkeys for users who are set up to use SMS or voice authentication. When those users complete MFA during sign-in, they may be prompted to register a passkey.
This gives organizations time to introduce the change and help users enroll before text and voice codes retire.
-
February 1, 2027: Microsoft-provided SMS and voice MFA retire
Microsoft will stop providing SMS text-message and voice-call authentication for Microsoft Entra ID.
Organizations that still have users relying on those methods need to make sure those users have another approved sign-in method.
-
After February 1, 2027: Unprepared users may be stopped during sign-in
If a user only has SMS or voice MFA available, Microsoft can require that person to register a passkey before they continue signing in.
This can create avoidable disruption if employees are not prepared, do not have an approved device available, or do not understand why they are being prompted.
-
Who needs to take action?
Not every organization will be affected.
If no users in your Microsoft Entra ID environment use SMS or voice authentication, this change may not require any action.
However, businesses should not assume they are unaffected. Employees may have selected text messages as an MFA method years ago, and those settings can be easy to overlook.
Organizations should review their Microsoft Entra ID authentication settings and identify users who still rely on SMS or voice codes.
What should businesses do now?
A smooth transition starts before users are forced to change the way they sign in.
1. Identify affected users
Find out which employees use SMS text-message or voice-call codes to complete MFA.
This step helps the business understand the size of the change and prevents unexpected sign-in issues later.
2. Choose an approved replacement method
Passkeys are Microsoft’s recommended option, but the right approach depends on the organization, its users, device policies, and security requirements.
Possible alternatives may include passkeys, Windows Hello for Business, Microsoft Authenticator, or FIDO2 security keys.
3. Prepare and communicate
Employees need clear, simple instructions before they see a new passkey prompt.
Tell users what is changing, why it matters, what they will see when signing in, and who to contact if they need help.
4. Test before rolling out broadly
A pilot group can help identify device limitations, user questions, and policy settings that need attention before the change reaches everyone.
5. Complete the transition before February 1, 2027
Waiting until the retirement date increases the risk of user frustration and sign-in disruption.
Early planning gives organizations time to move at a manageable pace.
Frequently asked questions
Is Microsoft getting rid of MFA?
No. Microsoft is not removing MFA. It is retiring its own SMS text-message and voice-call options in Microsoft Entra ID and moving users toward stronger authentication methods.
Will employees lose access to Microsoft 365?
They can if they only use SMS or voice MFA and do not register another approved method before the retirement date. Planning ahead helps prevent this.
What is the deadline for moving away from SMS and voice MFA?
Microsoft-provided SMS and voice authentication retires on February 1, 2027. Businesses should complete their transition before that date.
Are passkeys safer than text-message codes?
Passkeys are designed to be phishing-resistant. They do not use a code that can be intercepted, shared, or stolen through a fake sign-in page.
Does every business need to do something?
Organizations with no users enabled for SMS or voice MFA may not need to take action. However, every business using Microsoft Entra ID should review its authentication methods to confirm whether users are affected.
Need help preparing for the change?
Ferrum Technology Services helps businesses strengthen Microsoft 365 security, protect user accounts, and plan technology changes before they become an operational problem.
If your organization needs help reviewing its MFA settings, identifying affected users, or preparing for passkeys, contact Ferrum to start the conversation.
Ransomware Response Resources
For additional guidance during a ransomware or data-breach incident, consult these trusted resources:
Every incident is different. Work with your IT provider, cyber insurer, legal counsel, and incident response team to determine the appropriate next steps for your organization.