GTconsult

Entra ID is retiring SMS and voice MFA

19.08.26 11:47 AM Comment(s) By Boitumelo

Here's how to move to passkeys before 1 February 2027

Microsoft is retiring SMS and voice authentication in Microsoft Entra ID. From 1 February 2027, it's gone for good, and passkeys are now the default sign-in method for every tenant.


If your business still relies on text message or phone call codes for multi-factor authentication (MFA), this isn't a setting you can quietly ignore. It's a change to how every user in your organisation logs in, and it starts landing in tenants from 1 September 2026.

Why is Microsoft retiring SMS and voice MFA?

Text message codes feel secure because they're familiar. They're not secure. SMS and voice are among the weakest MFA methods still in wide use today, and Microsoft has said as much directly.


Here's why:

  • Phishing. Attackers can trick users into handing over an SMS code just as easily as a password.
  • SIM-swap fraud. A criminal who convinces your mobile provider to port your number can intercept your codes without touching your phone.
  • Replay attacks. Codes sent over SMS or voice can be captured and reused before they expire.


None of these attacks take much sophistication. That's exactly why Microsoft is moving away from anything routed through a phone number and making passkeys the default authentication experience in Entra ID instead.

What are passkeys, and why are they phishing-resistant?

Passkeys replace a code you type with a credential tied to your device or biometric, like a fingerprint, face scan, or security key. There's no code to intercept, no number to SIM-swap, and nothing that can be phished over a call or text.


This is what "phishing-resistant authentication" actually means in practice: the credential itself can't be tricked out of a user, because there's nothing to hand over.

Key dates for the Entra ID SMS and voice retirement

1 September 2026

Every user still enabled for SMS or voice MFA is automatically enabled for passkeys and nudged to register one at their next login. If you want to manage this transition on your own terms rather than have Microsoft manage it for you, move users out of SMS or voice in your Authentication Methods Policy before this date.

1 February 2027

Microsoft-provided SMS and voice authentication retires completely in Microsoft Entra ID. This is a hard cutoff, not a gradual wind-down. If your organisation uses a customer-managed telecom provider configured through the Microsoft Security Store, this deadline doesn't apply to you.

After 1 February 2027

Any user whose only available MFA method is SMS or voice will hit a blocking prompt at sign-in and won't be able to continue until they register a passkey. There's no opt-out. This applies to every Microsoft Entra ID tenant, with no exceptions.

What your business needs to do before the deadline

If no users in your tenant are enabled for SMS or voice, you can disregard the rest of this. If you do have users on these methods, here's the order to work through it in.


1. Find out who's affected Check your Authentication Methods Policy in Microsoft Entra ID to identify every user still enabled for SMS or voice MFA. You can't run a rollout until you know the scope.


2. Move users to passkeys before September 2026 Enable passkeys in your tenant and run a registration campaign to drive adoption at scale. Doing this on your own schedule, before auto-enablement kicks in, means fewer support tickets and a smoother experience for your team.


3. Communicate the change to your users early Let people know what's changing, when, and what they need to do, well before it becomes a login interruption. A blocking prompt that catches someone off guard is a support ticket generator and a frustrating way to learn about a security policy change.


4. Only evaluate a telecom provider if you genuinely need one If you have a regulatory or operational reason to keep SMS or voice authentication, a customer-managed telecom provider can be configured through the Microsoft Security Store. Provider options and pricing are published from 18 September 2026, with configuration available from 30 October 2026.


The bottom line on Entra ID's move to passkeys

Every user still on SMS or voice MFA needs to move to a phishing-resistant method, and Microsoft recommends passkeys, before Microsoft-provided SMS and voice retire on 1 February 2027. Acting before 1 September 2026 means your organisation controls the rollout. Waiting means Entra ID controls it for you, one blocking prompt at a time.

If you need help auditing who's affected in your tenant and running a passkey adoption campaign before the deadline or any of your MS365 security related needs, look no further, we can help you navigate these waters smoothly. 

Keep Reading

Check out our other blogs below:

Boitumelo

Share -