Friday, August 7, 2026
HomeMicrosoftMicrosoft 365 SecurityMicrosoft Entra SMS & Voice MFA Retirement: What to Do Before 2027

Microsoft Entra SMS & Voice MFA Retirement: What to Do Before 2027

TL;DR

  • September 1, 2026: Microsoft Entra ID will automatically enable passkeys for users who are enabled for SMS or voice authentication and will begin prompting them to register a passkey.
  • February 1, 2027: Microsoft-provided SMS and voice authentication delivery will be retired in Microsoft Entra ID.
  • Organisations that still have a legitimate need for SMS or voice can use a customer-managed telecom provider through the Microsoft Security Store instead.
  • If SMS or voice is a user’s only available MFA method after the deadline, the user will face a blocking passkey registration prompt before being allowed to continue signing in.
  • The best strategy is not to wait for 2027. Organisations should identify affected users now, prepare compatible devices, roll out phishing-resistant authentication and monitor adoption before enforcement becomes unavoidable.

Microsoft Is Changing How Entra ID Authentication Works

Microsoft is taking another major step toward passwordless and phishing-resistant authentication.

Microsoft Entra ID is making passkeys the default authentication experience while retiring Microsoft-provided SMS and voice authentication delivery.

This is more than a minor MFA configuration change.

For organisations that still rely heavily on text messages or phone calls for multifactor authentication, the announcement creates a firm migration deadline — and potentially a significant user-support challenge if the transition is left until the last minute.

Microsoft says the primary reason for the change is security. SMS and voice authentication are considered substantially weaker than phishing-resistant methods such as passkeys because telephone-based authentication can be exposed to threats including phishing, SIM-swapping and other account-compromise techniques. Passkeys instead rely on cryptographic credentials tied to a device or credential manager.

The direction is clear:

Microsoft wants organisations to move from “MFA” to phishing-resistant authentication.

And there are two dates every Microsoft Entra administrator should know.

September 1, 2026: Passkeys Become the Default Direction

The first major change begins on September 1, 2026.

Users who are enabled for SMS or voice authentication through the Entra Authentication Methods Policy or applicable legacy MFA settings will be automatically brought into scope for passkeys.

Microsoft will also place affected users into its passkey registration experience. When those users next sign in and complete MFA, they can be prompted to register a passkey.

Initially, the prompt is not necessarily blocking. Microsoft says users will have unlimited opportunities to snooze the registration prompt by default.

That may make September sound relatively harmless.

It shouldn’t.

September 1 is effectively the beginning of Microsoft’s migration window. Organisations have roughly five months between this change and the final retirement of Microsoft-provided SMS and voice delivery.

There is a temporary opt-out mechanism for the automatic passkey enablement and registration campaign during the transition period, but that does not remove the February 2027 deadline. Microsoft states that the final enforcement cannot be opted out of.

February 1, 2027: Microsoft-Provided SMS and Voice Authentication Ends

The critical date is February 1, 2027.

From this date, Microsoft-provided telecom delivery for SMS and voice authentication will be retired in Microsoft Entra ID.

If an organisation has not migrated affected users or configured a customer-managed telecom provider, those users will no longer be able to rely on Microsoft’s native SMS or voice delivery to satisfy their authentication requirements.

This does not mean Microsoft intends to instantly lock those users out.

Instead, users whose only available MFA method is SMS or voice will receive a blocking passkey registration experience. They must register a passkey before continuing to access their account.

Unlike the earlier registration prompts, this one cannot simply be dismissed.

Microsoft explicitly states that there is no opt-out from the February 1, 2027 enforcement.

For IT departments, that creates an obvious operational risk.

If hundreds or thousands of employees reach the deadline without being prepared for passkeys, the migration project effectively moves from the IT planning team to the help desk overnight.

Is Microsoft Completely Removing SMS and Voice MFA?

No — and this is an important distinction.

Microsoft is retiring Microsoft-provided SMS and voice telecom delivery, rather than declaring that organisations can never use SMS or voice authentication again.

Organisations with a legitimate regulatory, business or operational requirement can continue using these channels by selecting a customer-managed telecom provider through the Microsoft Security Store.

Microsoft says information about available telecom providers is scheduled to become available from September 18, 2026, with customers able to select and configure a telecom provider beginning October 30, 2026.

This option is likely to matter for industries or operational environments where another authentication method cannot easily replace a telephone channel.

However, Microsoft is clearly positioning this as the exception rather than the preferred migration strategy.

Its recommended direction for the majority of users is passkeys and other phishing-resistant authentication methods.

What Exactly Is a Passkey?

A passkey replaces a shared secret such as a password or one-time SMS code with a cryptographic credential.

Instead of typing a security code sent to a telephone number, the user proves possession of the credential and normally unlocks it using a device mechanism such as a PIN, fingerprint or facial recognition.

Microsoft Entra ID supports both synced passkeys and device-bound passkeys.

Synced passkeys can be stored in supported credential managers and synchronised across a user’s devices. Microsoft specifically identifies platform credential managers such as iCloud Keychain and Google Password Manager as examples.

Device-bound options include credentials such as a passkey in Microsoft Authenticator, Microsoft Entra passkey on Windows and FIDO2 hardware security keys.

Unlike SMS authentication, these methods are designed to resist phishing because authentication is cryptographically associated with the legitimate service rather than relying on a code that a user can accidentally disclose to an attacker.

Why Microsoft Is Moving Away From SMS and Voice

For many years, organisations treated almost any form of MFA as a substantial improvement over passwords alone.

That remains broadly true, but the threat landscape has evolved.

Attackers have become increasingly effective at stealing or bypassing traditional MFA through phishing, social engineering and adversary-in-the-middle techniques. A one-time code is still a secret that can potentially be captured and replayed.

The emerging security standard is therefore no longer simply:

“Does this account have MFA?”

A better question is:

“Is the authentication method resistant to phishing?”

Microsoft’s retirement announcement reflects this shift.

Passkeys, Windows Hello for Business and FIDO2 security keys are examples of phishing-resistant approaches that Microsoft is encouraging organisations to deploy.

Don’t Forget Self-Service Password Reset

One easily missed part of Microsoft’s announcement is that this change is not limited to the MFA prompt users see during normal sign-in.

Microsoft’s FAQ confirms that retirement of native SMS and voice also applies across Entra to self-service password reset (SSPR).

That makes an authentication inventory particularly important.

An organisation might review its Conditional Access policies and conclude that few employees actively use SMS for MFA, while overlooking the fact that telephone methods remain registered or relied upon for password recovery.

Authentication migration therefore needs to examine registration, sign-in usage and recovery workflows, not simply MFA policy configuration.

How Should Organisations Prepare?

The first priority is visibility.

Microsoft recommends identifying users who are still enabled for SMS or voice before designing the migration. Microsoft provides a PowerShell-based method for identifying affected users, while the Entra Authentication Methods Activity reporting can also help administrators understand which authentication methods users have registered and which methods are actually being used.

Once affected users are identified, organisations should segment them by role and device environment rather than forcing every employee through an identical rollout.

Microsoft’s deployment guidance recommends a persona-based approach. Privileged administrators and highly regulated users, for example, may justify different authentication choices from general information workers. Microsoft also recommends that most users have at least two authentication methods available so that the loss or failure of one credential does not immediately create an account-recovery problem.

Device readiness also matters.

Passkey adoption is not purely an identity configuration project. Operating systems, managed devices, shared PCs, mobile devices, VDI environments, frontline-worker scenarios and hardware security keys may all affect which phishing-resistant credential works best for a particular user.

Microsoft therefore recommends piloting the deployment with representative users, monitoring registrations and sign-ins, and gradually expanding enforcement instead of attempting one organisation-wide switch.

Finally, communication should begin before registration becomes mandatory.

Microsoft describes coordinated end-user communication as a major factor in a smooth rollout and recommends repeated communications leading up to enforcement rather than relying on a single announcement email.

Deep Insights: What This Change Really Means

MFA Is Becoming a Security Baseline, Not the Finish Line

Perhaps the biggest lesson from Microsoft’s announcement is that simply having MFA enabled is no longer sufficient as a long-term identity strategy.

For years, security programmes measured progress by MFA adoption percentages.

The next maturity metric will increasingly be phishing-resistant authentication adoption.

A tenant where 100% of users have MFA but most rely on phishable methods can represent a very different risk profile from a tenant where users authenticate with passkeys, Windows Hello or hardware-backed FIDO2 credentials.

This announcement effectively pushes organisations to start measuring authentication quality, not merely authentication quantity.

This Is an Identity Project and an Endpoint Project

Passkeys sound like an Entra ID configuration change, but successful deployment depends heavily on endpoints.

Which devices do employees use?

Which operating systems are deployed?

Do employees use shared workstations?

Can employees use mobile credential managers?

Do privileged users require hardware-bound credentials?

What happens when someone loses a device?

These questions make passkey migration a combined identity, endpoint-management, security and user-experience programme.

Organisations that treat it as one checkbox in the Entra admin centre are likely to discover edge cases late in the rollout.

The February Deadline Is Really a Help-Desk Deadline

Microsoft’s blocking registration behaviour reduces the likelihood that an unprepared user will simply continue using weak authentication indefinitely.

But it transfers the problem somewhere else.

If an employee reaches February 2027 without an appropriate credential and cannot successfully complete passkey registration, the immediate escalation point is likely to be IT support.

That means one of the most useful migration KPIs may not be “Passkeys Enabled.”

It may be:

“Percentage of active users who have successfully used a phishing-resistant credential.”

Registration alone does not prove that the employee’s everyday devices and workflows are ready.

Microsoft’s Authentication Methods Activity and sign-in reporting provide useful data for measuring both registration and actual usage.

Keeping SMS Could Become a Business Decision

Until now, many organisations used Microsoft’s SMS MFA because the delivery infrastructure was simply part of the platform.

After the retirement, an organisation that wants to retain SMS or voice may need to select a telecom provider, establish a commercial relationship and account for message charges, regional coverage and compliance considerations.

Microsoft’s FAQ states that telecom-provider pricing will vary by provider, geography and message volume.

That changes the conversation.

Continuing to use SMS becomes less of an inherited technical default and more of an explicit business decision that should have a documented reason.

Passkeys Need a Recovery Strategy Too

Phishing resistance does not eliminate operational failure.

Devices can be lost. Employees replace phones. Hardware keys can disappear. Users work from temporary or shared devices.

Microsoft recommends registering at least two authentication methods so users have a backup when something happens to their primary credential.

Therefore, a mature passkey project should not ask only:

“How do we enrol everyone?”

It should also ask:

“How do we securely recover someone who loses their credential?”

That recovery workflow deserves to be tested before SMS disappears as the familiar fallback.

Who Is Affected — and Who Isn’t?

The announced timeline currently applies to Microsoft Entra public cloud environments.

Microsoft says Azure AD B2C is outside the scope of this announcement, while Microsoft Entra External ID will follow a separate timeline. External MFA methods are also not directly retired by this change unless those users are additionally enabled for SMS or voice through the affected policies.

Organisations with B2B and guest-user scenarios should pay particular attention to Microsoft’s evolving guidance. Microsoft states that passkey support for B2B users and internal guest users is planned by the end of calendar year 2026, while those users remain within scope of the SMS and voice retirement.

This is another reason administrators should continue reviewing Microsoft’s documentation as the deadline approaches rather than treating today’s implementation details as frozen.

Conclusion: Don’t Treat February 2027 as the Migration Date

The biggest mistake an organisation can make is reading “February 1, 2027” and treating that as the date to start taking action.

It is the deadline, not the project start date.

From September 1, 2026, Microsoft begins actively moving SMS- and voice-enabled users toward passkeys. Five months later, Microsoft-provided SMS and voice delivery ends, and users who depend on those methods can face mandatory passkey registration.

The organisations best positioned for this change will be those that use the transition as an opportunity to modernise authentication rather than simply search for another way to keep SMS alive.

Audit your current authentication methods. Identify real SMS and voice dependencies. Understand your user and device personas. Design credential recovery. Pilot passkeys with representative users. Measure successful usage, not just registrations. Communicate repeatedly. And keep customer-managed telecommunications only for the scenarios where there is a genuine reason to retain it.

The broader message from Microsoft is difficult to miss:

The future of identity security is not simply passwordless. It is phishing-resistant.

For Microsoft Entra environments, February 1, 2027 is the point where that future becomes much harder to postpone.

RELATED ARTICLES

Most Popular