Cyber threats are evolving rapidly, and traditional authentication methods are struggling to keep pace. Microsoft has announced a significant change that will affect organisations still replying on SMS or voice based multi-factor authentication (MFA): Microsoft provided SMS and voice authentication in Microsoft Entra ID will be retired on 1 February 2027.
While this may seem like another platform update, it's really part of a wider shift towards stronger, phishing-resistant security. For organisations using Microsoft Entra ID, now is the time to start planning the transition.
SMS and voice MFA have helped organisations strengthen security for many years, but they were never designed to defend against today's sophisticated threats.
Cybercriminals can exploit these methods through:
As AI-powered attacks become more convincing and scalable, organisations need authentication methods that provide stronger protection by design.
Microsoft's response is clear: move users towards phishing-resistant authentication, with passkeys becoming the default authentication experience in Microsoft Entra ID.
Passkeys are a modern authentication method that replaces passwords and vulnerable one-time codes with secure, cryptographic credentials.
Rather than entering a password and waiting for a text message, users authenticate using a trusted device and a biometric factor such as:
Because passkeys are tied to a specific device and cannot be shared, intercepted or replayed, they offer significantly stronger protection against phishing attacks.
The result is a login experience that is both more secure and easier for users.
Microsoft has outlined several important milestones that organisations need to be aware of.
Users currently enabled for SMS or voice authentication will automatically become eligible for passkeys.
When these users next perform MFA, Microsoft will encourage them to register a passkey.
Organisations that want to control the timing of this experience should start their migration before this date.
Microsoft-provided SMS and voice authentication will be fully retired in Microsoft Entra ID.
After this date, organisations can no longer rely on Microsoft's SMS or voice-based MFA services.
Users whose only available authentication method is SMS or voice will be blocked from continuing sign-in until they register a passkey.
This enforcement applies across all tenants and there is no option to opt out.
If your users already authenticate with phishing-resistant methods such as passkeys, little action may be required.
However, if any users still depend on SMS or voice MFA, Microsoft recommends beginning the transition as soon as possible.
Early action provides several benefits:
The first step is understanding how many users are still relying on SMS or voice authentication.
Review your authentication methods and identify users who need to move to a more secure alternative.
Passkeys are Microsoft's recommended replacement for SMS and voice MFA.
Introducing passkeys ahead of the automatic enablement date allows users to become familiar with the new experience before it becomes the default.
User adoption is key to a successful migration.
Explain:
Why the change is happening
The security benefits of passkeys
Key deadlines
What users need to do
Organisations that communicate proactively are more likely to see smooth adoption and fewer support tickets.
Some organisations may have regulatory, operational or business requirements that still demand SMS or voice authentication.
In these situations, Microsoft will allow organisations to configure a customer-managed telecom provider through the Microsoft Security Store.
However, for most organisations, Microsoft's recommendation remains the same: move users to phishing-resistant authentication wherever possible.
The retirement of Microsoft-provided SMS and voice authentication isn't just a technology change—it's an opportunity to strengthen identity security and reduce exposure to increasingly sophisticated attacks.
By migrating users to passkeys now, organisations can improve security, simplify the sign-in experience and avoid disruption when enforcement begins in 2027.
The earlier you start, the easier the transition will be.
Codec can help you assess your current authentication methods, identify affected users, build a passkey adoption strategy and prepare your organisation for the retirement of SMS and voice MFA.
Talk to our security experts about building a phishing-resistant identity strategy with Microsoft Entra ID.
Microsoft is retiring its SMS and voice-based authentication services for Microsoft Entra ID on 1 February 2027. Organisations currently using these authentication methods will need to move users to an alternative authentication method, such as passkeys.
SMS and voice-based authentication are move vulnerable to phishing, SIM-swap attacks, account takeover and replay attacks than modern authentication methods. Microsoft is moving towards phishing-resistant authentication by default to help organisations better protect their identities and data.
Passkeys are a phishing-resistant authentication method that allows users to sign in using biometrics, devise PINs or security keys instead of passwords and one-time passcodes. They provide a more secure and seamless sign in experience.
No. Microsoft provided SMS and voice authentication will continue to work until 1 February 2027. However, organisations should begin planning their migration now to avoid disruption and ensure users are prepared for the change.
Users currently enabled for SMS and voice authentication will automatically become eligible for passkeys. Microsoft will begin prompting these users to register a passkey the next time they complete MFA.
After 1 February 2027, users whose only available MFA method is SMS or voice will be required to register a passkey before they can continue signing in. This enforcement applies to all Microsoft Entra ID tenants and cannot be disabled.
No. Microsoft provided SMS and voice authentication will continue to work until 1 February 2027. However, organisations should begin planning their migration now to avoid disruption and ensure users are prepared for the change.