· Emad Adel · Security · 4 min read
Microsoft Is Retiring SMS and Voice MFA: Move to Phishing-Resistant Passkeys
Microsoft Entra ID is phasing out SMS and voice MFA in favour of passkeys, with a hard cutoff on 1 February 2027. Here are the dates that matter and what to do before them.
Microsoft has announced a major security shift for Microsoft Entra ID (formerly Azure AD): SMS and voice-based multi-factor authentication (MFA) are being phased out in favour of passkeys, a phishing-resistant authentication method. As identity attacks grow more sophisticated in the AI era, organizations need stronger authentication methods that protect users from phishing, credential theft, and social engineering.
This isn’t a minor update. It’s a mandatory, organization-wide transition with hard deadlines that every Microsoft Entra tenant — and every user who signs in with SMS or voice codes — needs to understand.
Why Is Microsoft Making This Change?
Microsoft says that traditional authentication methods including passwords, SMS one-time passcodes, and voice-based verification remain vulnerable to phishing, interception, and social engineering attacks. Attackers today use techniques like SIM swapping, man-in-the-middle reverse proxy attacks, and AI-generated phishing campaigns to intercept or trick users out of SMS codes.
Passkeys work differently. The private authentication key remains stored on the user’s device, and a fake login page cannot capture or reuse that key, which is what makes them “phishing-resistant” — even if a user is tricked into visiting a fraudulent site, there’s no code or secret for an attacker to steal.
Key Dates to Know
| Date | What Happens |
|---|---|
| 1 September 2026 | Passkeys become the default authentication experience in Microsoft Entra ID. Users currently using SMS or voice start being prompted to register a passkey. |
| 18 September 2026 | Microsoft publishes details on supported third-party telecom providers for organizations that still need SMS or voice. |
| 30 October 2026 | Organizations that must keep using SMS or voice need a customer-managed telecom provider configured. |
| 1 February 2027 | Microsoft-provided SMS and voice authentication stops working entirely. No permanent exemptions will be granted. |
How This Affects Users
- Individual users will start seeing prompts to register a passkey the next time they complete an MFA challenge, beginning in September 2026.
- IT administrators and organizations need to audit which users still rely on SMS or voice, plan a migration path, and decide whether any accounts have a legitimate business or regulatory need to keep phone-based MFA — which will require a separate, paid, third-party telecom provider through the Microsoft Security Store.
- After 1 February 2027, anyone still depending on Microsoft-provided SMS or voice codes without an alternative in place will be locked out of sign-in until they switch methods.
What Users Should Do Now
- Don’t wait for the deadline. Register a passkey as soon as your organization enables it, rather than waiting until the last prompt.
- Use a supported device. Passkeys can be stored on phones, computers, or dedicated hardware security keys (FIDO2), so check that your device supports biometric or PIN-based unlocking.
- Run an audit. IT teams should review Entra ID sign-in logs to identify every user or group still on SMS or voice, and prioritize migrating them early to avoid a last-minute support rush.
- Set up break-glass emergency accounts with phishing-resistant credentials, so administrators are never locked out during the transition.
- If SMS or voice is unavoidable for compliance or accessibility reasons, configure a customer-managed telecom provider through the Microsoft Security Store well before the 30 October 2026 checkpoint.
The Bigger Picture
This move reflects a broader industry trend: major platforms — Google, Apple, and Microsoft — are steadily pushing users away from SMS-based MFA toward passkeys, because SMS was never designed to be a secure authentication channel. It was repurposed for convenience. As AI makes phishing and social engineering faster and more convincing, phishing-resistant methods like passkeys are quickly becoming the baseline expectation rather than an optional upgrade.
For organizations, the practical takeaway is simple: start planning now. A six-month runway between the default rollout in September 2026 and the hard cutoff in February 2027 sounds like a lot of time, but large organizations with thousands of users, legacy devices, and compliance requirements will need every bit of it.
Sources: Microsoft Security Blog, Microsoft Entra ID documentation on Microsoft Learn, and industry reporting from Cybernews, WindowsLatest, and MajorKey Tech.


