· Emad Adel · Security  · 4 min read

Microsoft Is Retiring SMS and Voice MFA: Move to Phishing-Resistant Passkeys

Microsoft Entra ID is phasing out SMS and voice MFA in favour of passkeys, with a hard cutoff on 1 February 2027. Here are the dates that matter and what to do before them.

Microsoft Entra ID is phasing out SMS and voice MFA in favour of passkeys, with a hard cutoff on 1 February 2027. Here are the dates that matter and what to do before them.

Microsoft has announced a major security shift for Microsoft Entra ID (formerly Azure AD): SMS and voice-based multi-factor authentication (MFA) are being phased out in favour of passkeys, a phishing-resistant authentication method. As identity attacks grow more sophisticated in the AI era, organizations need stronger authentication methods that protect users from phishing, credential theft, and social engineering.

This isn’t a minor update. It’s a mandatory, organization-wide transition with hard deadlines that every Microsoft Entra tenant — and every user who signs in with SMS or voice codes — needs to understand.

Why Is Microsoft Making This Change?

Microsoft says that traditional authentication methods including passwords, SMS one-time passcodes, and voice-based verification remain vulnerable to phishing, interception, and social engineering attacks. Attackers today use techniques like SIM swapping, man-in-the-middle reverse proxy attacks, and AI-generated phishing campaigns to intercept or trick users out of SMS codes.

Passkeys work differently. The private authentication key remains stored on the user’s device, and a fake login page cannot capture or reuse that key, which is what makes them “phishing-resistant” — even if a user is tricked into visiting a fraudulent site, there’s no code or secret for an attacker to steal.

Key Dates to Know

DateWhat Happens
1 September 2026Passkeys become the default authentication experience in Microsoft Entra ID. Users currently using SMS or voice start being prompted to register a passkey.
18 September 2026Microsoft publishes details on supported third-party telecom providers for organizations that still need SMS or voice.
30 October 2026Organizations that must keep using SMS or voice need a customer-managed telecom provider configured.
1 February 2027Microsoft-provided SMS and voice authentication stops working entirely. No permanent exemptions will be granted.

How This Affects Users

  • Individual users will start seeing prompts to register a passkey the next time they complete an MFA challenge, beginning in September 2026.
  • IT administrators and organizations need to audit which users still rely on SMS or voice, plan a migration path, and decide whether any accounts have a legitimate business or regulatory need to keep phone-based MFA — which will require a separate, paid, third-party telecom provider through the Microsoft Security Store.
  • After 1 February 2027, anyone still depending on Microsoft-provided SMS or voice codes without an alternative in place will be locked out of sign-in until they switch methods.

What Users Should Do Now

  1. Don’t wait for the deadline. Register a passkey as soon as your organization enables it, rather than waiting until the last prompt.
  2. Use a supported device. Passkeys can be stored on phones, computers, or dedicated hardware security keys (FIDO2), so check that your device supports biometric or PIN-based unlocking.
  3. Run an audit. IT teams should review Entra ID sign-in logs to identify every user or group still on SMS or voice, and prioritize migrating them early to avoid a last-minute support rush.
  4. Set up break-glass emergency accounts with phishing-resistant credentials, so administrators are never locked out during the transition.
  5. If SMS or voice is unavoidable for compliance or accessibility reasons, configure a customer-managed telecom provider through the Microsoft Security Store well before the 30 October 2026 checkpoint.

The Bigger Picture

This move reflects a broader industry trend: major platforms — Google, Apple, and Microsoft — are steadily pushing users away from SMS-based MFA toward passkeys, because SMS was never designed to be a secure authentication channel. It was repurposed for convenience. As AI makes phishing and social engineering faster and more convincing, phishing-resistant methods like passkeys are quickly becoming the baseline expectation rather than an optional upgrade.

For organizations, the practical takeaway is simple: start planning now. A six-month runway between the default rollout in September 2026 and the hard cutoff in February 2027 sounds like a lot of time, but large organizations with thousands of users, legacy devices, and compliance requirements will need every bit of it.


Sources: Microsoft Security Blog, Microsoft Entra ID documentation on Microsoft Learn, and industry reporting from Cybernews, WindowsLatest, and MajorKey Tech.

Back to Blog

Related Posts

View All Posts »
تسجيل الدخول الموحد (SSO)

تسجيل الدخول الموحد (SSO)

♦️تسجيل الدخول الموحد (SSO): مفتاح واحد لفتح العديد من الأبواب تخيل أنك تمتلك مجموعة كبيرة من المفاتيح، لكل باب في منزلك مفتاح مختلف. تخيل العناء الذي ستتعرض له كل يوم لتذكر كل هذه المفاتيح وإدارتها.

عالم الكمبيوتر "روبرت نورتون نويس

عالم الكمبيوتر "روبرت نورتون نويس

يحتفل صباح اليوم الاثنين 12-12 محرك البحث الشهير "جوجل" بذكرى ميلاد عالم الكمبيوتر "روبرت نورتون نويس"، وذلك من خلال تغيير شعاره الخاص به إلى صورة رمزية للعالم الذى سجل باسمه 16 براءة اختراع. ويعد نويس من الشخصيات...