Microsoft ends SMS and Voice Authentication: Passkeys Become Mandatory
If your organization uses Microsoft Entra ID, the days of logging in with a text message code or an automated phone call are numbered. Microsoft has set February 1, 2027 as the shutdown date for its free SMS and voice login service, and passkeys become the default in its place. Here is exactly what changes, when it happens, and what you need to do before the deadline hits. It’s a good move that everyone should do now, including personal users.
For the moment, this only applies to organizations and governments using Microsoft Entra ID. The MFA (multi-factor authentication) options for getting the code are being limited, with passkeys made the preferred and default option.
Individuals can still get an authentication code via SMS or voice, for the moment. We’re going into detail about this change because it’s quite possible that Microsoft will do the same for all other accounts in the future, and with good reason.
Microsoft has set a firm end date for SMS and voice based multi-factor authentication in Entra ID: February 1, 2027. If your organization still lets people log in with a text message code or an automated phone call, that option is going away, and Microsoft is replacing it with passkeys by default.
This is not a gentle suggestion. It is a scheduled shutdown with a blocking screen at the end of it.
Why Microsoft Is Doing This
SMS and voice codes are the weak link in multi-factor, secure login. Those codes can be intercepted, phished with a fake login page, or hijacked through a SIM swap, where an attacker convinces a phone carrier to move your number to their device.
Passkeys use cryptographic keys tied to your device instead of a code that can be read out or typed into a fake site. Microsoft calls this phishing-resistant authentication, and it genuinely is a stronger category of protection.
What everyone should be doing
People in organizations will have no choice about using passkeys.
We strongly urge everyone with a Microsoft account (free or with Microsoft 365) to secure their logins with the latest technology and drop older, less secure options.
- Use passkeys on computers and devices. Passkeys are not only more secure, they’re a faster way to log in.
- Use an authentication app to get the additional code.
- Have a recovery key and another email address set up, just in case.
- Do NOT use SMS or voice to get the MFA login code.
What Is Actually Changing
Two things are happening for organizational users with Entra ID.
- Passkeys become the default. Anyone currently set up for SMS or voice MFA will automatically be enrolled for passkeys and will be prompted to register one the next time they sign in with MFA.
- Microsoft-provided SMS and voice delivery retires. This is the free, built-in telecom service Microsoft has been running for years. If your organization has instead configured its own telecom provider through the Microsoft Security Store, that setup is not affected.
In other words, this is not the end of SMS authentication everywhere. It is the end of Microsoft footing the bill and running the plumbing for it.
The Timeline for the end of SMS and voice authentication
This only applies to Microsoft Entra ID logins.
- September 1, 2026. Every user still enabled for SMS or voice gets automatically enabled for passkeys as well, and starts seeing registration nudges. Admins can move those users off SMS or voice in the Authentication Methods Policy before that date.
- February 1, 2027. Microsoft provided SMS and voice stops working entirely. Customer managed telecom providers keep working.
- After February 1, 2027. Anyone whose only MFA method is SMS or voice hits a blocking prompt. They cannot sign in until they register a passkey. There is no opt out. It applies to every tenant, no exceptions.
That last point deserves a plain restatement: this is a kill switch. Miss the deadline and affected users get locked out of the sign -in flow until they comply.
What This Means for You
If there are people still using SMS or voice authentication, here is the practical to-do list for Admins, in order.
- Find who is affected. Check the Authentication Methods Policy in Entra ID to see which users are still enrolled in SMS or voice.
- Get them onto passkeys. Turn on passkeys and run an actual registration campaign, meaning emails, reminders, maybe a deadline of your own, before the September 1, 2026 auto-enrollment kicks in and takes the decision out of your hands.
- Tell your users what is happening. Do not let them discover this through a surprise prompt or, worse, a lockout screen in 2027.
- Only look at a third-party telecom provider if you genuinely need SMS to survive. Some organizations have regulatory or operational reasons to keep phone-based MFA. If that is you, provider options and pricing appear in the Microsoft Security Store starting September 18, 2026, with configuration available from October 30, 2026. For everyone else, this is extra cost and complexity for a method Microsoft itself is walking away from.
Act before September 1, 2026 and you choose the pace and manage the rollout on your own terms. Wait, and Microsoft chooses for you, on a schedule that ends in a locked door.
Hackers and Microsoft Accounts: How To Stay Secure
Transition to a More Secure Outlook.com Login
Make sure an email link is real not phishing, why does Microsoft makes it easier for criminals?
Beware “Evil Kerning”: How Hackers Trick You with Fake Email Addresses
Fake Microsoft Purchase Email: Recognize the Scam
Publisher 365 Kill Switch: What Microsoft’s New Email Gets Wrong
Office 2016 Still Gets Security Updates: Check If Yours Qualifies