20/08/2026
Author
One partner, wherever you operate
We support UK & European businesses with international operations.
Directly employed engineers across EMEA, APAC and the Americas. One contract, consistent support across every region.
Microsoft's SMS authentication retirement has no opt-out: Here's what businesses should do
From 1 February 2027, Microsoft Entra ID users will no longer be able to log in to their accounts using existing SMS or voice authentication services provided by Microsoft.
According to the Microsoft Digital Defense Report 2025, AI has made phishing 50 times more profitable and 4.5 times more dangerous. This greatly increases the risk to businesses.
Both SMS and voice authentication are vulnerable to phishing. For this reason, Microsoft is retiring them and moving users to more secure authentication methods.
In this article, we explain what this means for users with Microsoft Entra ID business accounts and what you should do to prepare for the end of Microsoft-native SMS and voice authentication.
Table of contents
-
The full SMS-phase-out timeline (and what happens if you don't act)
-
Is passwordless authentication actually more secure than SMS?
The full SMS-phase-out timeline (and what happens if you don't act)
Microsoft has decided on a three-stage phasing out of SMS and voice authentication for Entra ID users.
The goal of the process is to move the user to a more secure form of authentication, usually a passkey. A passkey is a cryptographic credential associated with the user’s account and stored on a hardware security key or in a credential manager on one or more of the user’s devices.
The key dates are as follows:
-
1 September 2026: SMS and voice users’ accounts are auto-enabled for passkeys, nudged to register a passkey at next MFA sign-in.
-
1 February 2027: Microsoft retires its own SMS and voice authentication service, making these options unavailable for most users.
-
From 1 February 2027: Microsoft-provided SMS and voice authentication will stop. Users must switch to a passkey or use an approved voice or SMS third-party provider.
It’s important to understand that there is no opt-out. Once 1 February 2027 passes, anyone still relying solely on SMS or voice will be blocked at their next sign-in. To regain access to their account, they must register a passkey. There's no way to skip it, postpone it, or dismiss it.
If a user has not migrated to an approved authentication method by this time, the system will serve them a blocking prompt when they try to sign in.
Users will have no choice but to register or create a passkey. They won’t be able to skip this task or leave it incomplete. And they won’t be able to complete the sign-in until they do it.
If you have a lot of users who need to do this at the last minute, helpdesk volumes will spike, and productivity will drop.
Is passwordless authentication actually more secure than SMS?
Superficially, an SMS message might seem like a secure means of multifactor authentication (MFA). But this has not been the case for some time.
Criminals can intercept text messages. They can trick a phone provider into moving a target telephone number to their own SIM (known as a SIM-swap attack). They can even send a victim a fake MFA login page, enabling the cybercriminal to steal the SMS code in real time.
Passwordless authentication uses something called a passkey. A passkey solves this problem because it doesn’t need to send anything which can be intercepted and misused, such as a password or SMS code, over the Internet.
Instead, the user authenticates on their device, which then uses cryptography to prove their identity to Entra ID. The private key used to do this is never sent to Entra ID. This makes passwordless authentication inherently more secure than old-fashioned passwords.
The threat to SMS and voice-based authentication has increased significantly with the advent of AI, which allows authentication attacks at a scale and speed that would previously have been impossible.
Your pre-deadline action plan
What you must do to prepare is simple. However, you must execute your plan thoroughly, ensuring that no one is left out and that you discover any potential issues in plenty of time.
Before 1 February 2027, your organisation should:
-
Audit all Entra ID users to discover any who still use SMS or voice authentication.
-
Identify any users who genuinely need to continue using these authentication methods.
-
Communicate what is changing and when, before the passkey roll-out begins.
-
The roll-out — move users to passkeys in phases, starting with low-risk groups.
-
Confirm that all users have successfully made the switch before February 2027.
Most users will already have the Microsoft Authenticator app installed for existing MFA. If anyone on your team hasn't set it up yet, this step-by-step guide covers installing and connecting the app to their account, the starting point before they register a passkey.
A small number of businesses must authenticate via SMS or voice for contractual, regulatory or other reasons. Microsoft does have an option for these users (see the section How to keep SMS or voice, via a telecom provider below).
Choosing the right type of Microsoft Entra ID passkey
There are three main alternatives to SMS or voice authentication: hardware keys, authenticator apps and synced passkeys:
-
Hardware key: a hardware security key, such as a YubiKey, is a small physical device that stores a passkey. Users plug it into a USB port or connect using NFC, then unlock it to authenticate. Hardware keys are particularly suitable for privileged users, shared computers and kiosks. However, businesses must buy and manage the keys and need a process for replacing lost or damaged devices.
-
Microsoft Authenticator app: an iOS and Android app that can store a passkey securely on the user's smartphone. The user authenticates using their phone, without needing separate hardware. This makes it a natural choice for most Microsoft 365 users. However, users need a suitable smartphone and businesses need a recovery process for phones that are lost, damaged or replaced.
- Synced passkeys: stored through a credential manager such as iCloud Keychain or 1Password, and made available across all of a user's devices automatically. They suit people who regularly move between devices but create some dependence on the chosen platform ecosystem.
-
Windows Hello: stores a passkey locally on a single Windows device, unlocked using a PIN, fingerprint or facial recognition. Unlike synced passkeys, it's device-bound rather than shared across devices, so it suits users who consistently work from the same Windows machine.
| Authentication methods | Best for | Consideration |
| YubiKey (hardware key) | Shared devices and the highest-security roles | There’s a physical device to issue and manage |
| Microsoft Authenticator app | Most users | Requires a smartphone |
| Synced passkeys | Users who move across devices | Tied to a platform credential manager |
| Windows Hello | Users who work consistently from one Windows device | Device-bound, doesn't follow the user elsewhere |
How to keep SMS or voice, via a telecom provider
Most businesses should move to a newer form of authentication. Trying to remain on SMS or voice authentication will leave them insecure and involve extra effort, complexity and cost.
However, a small number of businesses do need to use these authentication methods for a range of contractual or regulatory reasons.
For these companies, Microsoft's Security Store telecom-provider route will be available from 30 October 2026, with details of specific providers published from 18 September 2026.
Businesses should only choose this route if there is a real regulatory, compliance or business need that compels it. If there is, important considerations include:
-
Choosing a telecoms provider that operates in the countries and regions where the business has users.
-
Checking factors such as the ongoing per-message costs, which vary by provider, before making a decision.
-
Ensuring that this exception is set up before 1 February 2027 to ensure that there is no disruption when the Microsoft-provided SMS and voice services stop.
Before deciding to take this route and choosing a telecom provider, have your compliance team first audit your needs and the available options.
If you would value a second opinion from specialists in secure authentication, Texaport’s experts are available to help.
Get your passkey rollout sorted before September
You don't need to work out your passkey rollout alone or work it out twice.
As a Microsoft Solutions Partner, Texaport can help you integrate the new authentication methods into Entra ID as part of a holistic Microsoft 365 strategy for productivity and security.
Our experts will quickly surface who is still on SMS or voice. They will then build you a rollout plan that migrates everyone to new authentication methods before the deadline hits.