Skip to main content
Mino IT
Cybersecurity & Compliance

Microsoft Is Retiring SMS and Voice Authentication: What It Means for Your Business

Microsoft-provided SMS and voice sign-in codes retire on 1 February 2027, with passkey prompts starting 1 September 2026. Most staff on the Authenticator app are unaffected, but every account still receiving codes by text or phone call must be moved. Here are the dates, the reasons, and how to handle the migration.

Keith MinoCEO, Mino IT6 min read

Microsoft has confirmed a major change to how people sign in to Microsoft 365. Passkeys are becoming the default authentication method in Microsoft Entra ID, and Microsoft-provided SMS and voice authentication will be retired on 1 February 2027.

If some of your staff still receive their sign-in codes by text message or phone call, this change affects your business directly. The good news is that the fix is stronger, faster to use, and something a well-run IT provider will handle for you.

What is changing, and when

Microsoft notified all Entra ID tenants of the change in August 2026. The dates that matter:

  • 1 September 2026. Users set up for SMS or voice authentication are automatically enabled for passkeys. They will be prompted to register a passkey the next time they complete multi-factor authentication.
  • 18 September 2026. Microsoft publishes third-party telecom provider options and pricing for organisations that must keep SMS or voice for regulatory reasons.
  • 30 October 2026. Administrators can configure a customer-managed telecom provider through the Microsoft Security Store.
  • 1 February 2027. Microsoft-provided SMS and voice authentication is fully retired.

After 1 February 2027, anyone whose only sign-in method is SMS or voice will hit a blocking prompt. They will have to register a passkey before they can sign in at all. There is no opt-out. It applies to every Microsoft 365 tenant.

Who is actually affected

Fewer people than you might think.

Most businesses on Microsoft 365 already use the Microsoft Authenticator app for multi-factor authentication. If your staff approve sign-ins through the app, they are not part of this retirement and will see little or no change.

The change affects the smaller group of users who still receive a six-digit code by text message or a phone call when they sign in. Those methods are the ones being switched off. In our experience this cohort is small: a handful of long-standing accounts, shared mailboxes set up years ago, or staff who never moved off the old method.

That said, “small” is not “zero”. Every one of those accounts needs to be moved before the deadline, and finding them takes an audit of your tenant’s authentication methods.

Why Microsoft is doing this

SMS and voice are the weakest forms of multi-factor authentication still in common use. They are vulnerable to:

  • Phishing. A convincing fake login page can capture a texted code and replay it in real time. Microsoft reports that AI-generated phishing campaigns now achieve click-through rates as high as 54 per cent, compared with around 12 per cent for traditional attacks.
  • SIM swapping. An attacker convinces a mobile carrier to move your number to their SIM, then receives your codes.
  • Interception and replay. A texted code is a shared secret. Anything that can read the message can use the code.

Passkeys close all three gaps. A passkey uses public-key cryptography tied to your device and the genuine website. There is no code to steal, and a fake login page gets nothing useful. This is what “phishing-resistant” means in practice, and it is the standard the Australian Signals Directorate points to in the Essential Eight’s stronger maturity levels for multi-factor authentication.

What passkeys look like day to day

For staff, a passkey is less effort than the old method, not more. Instead of waiting for a text and typing a code, they sign in with the same unlock they already use on their device: a fingerprint, a face scan, or a PIN. It works through Windows Hello, the Microsoft Authenticator app on a phone, or a physical FIDO2 security key for shared or high-security scenarios.

Set-up takes a couple of minutes and Microsoft will prompt affected users to do it automatically from 1 September 2026.

What your business needs to do

Microsoft’s guidance boils down to four steps:

  • Find affected users. Audit the tenant to identify everyone still enabled for SMS or voice authentication.
  • Move them to passkeys. Enable the right passkey types for your environment and run a registration campaign so users enrol before the automatic prompts begin.
  • Communicate the change. Tell staff what is changing, when, and that the passkey registration prompt is legitimate and not a phishing attempt.
  • Keep SMS only if you must. If a regulatory or operational requirement forces you to keep SMS or voice, configure a customer-managed telecom provider through the Microsoft Security Store before 1 February 2027. You will pay the telecom costs directly.

Acting before 1 September 2026 means you move users on your own schedule. Waiting means Microsoft’s prompts, and eventually its blocking enforcement, set the schedule for you.

How Mino IT is handling this for our clients

We are not waiting for the deadline. Mino IT is already auditing every managed tenant, identifying the accounts still on SMS or voice, and migrating them to phishing-resistant authentication ahead of the 1 September 2026 auto-enablement date.

For our managed clients this means:

  • An audit of authentication methods across the tenant, so nothing is missed.
  • A managed migration to passkeys, with staff told exactly what to expect.
  • Conditional Access and authentication policies updated so the weak methods are properly retired, not left half-enabled.
  • No blocking prompts, no locked-out staff, and no scramble in January 2027.

This is what Technology Governance looks like in practice: a vendor announces a disruptive change, and your IT provider has already dealt with it before your staff notice.

Not sure where your business stands?

If you do not know how many of your staff still sign in with texted codes, that is worth finding out now. Mino IT can audit your Microsoft 365 tenant, show you exactly who is affected, and map the move to phishing-resistant authentication. Call us on 1300 700 187 or get in touch through our contact page.

Frequently Asked Questions

Is Microsoft getting rid of multi-factor authentication?

No. Multi-factor authentication is still required. Microsoft is retiring the weakest delivery methods, SMS text codes and voice calls, and replacing them with passkeys, which are stronger and faster to use.

My staff use the Microsoft Authenticator app. Are we affected?

Mostly no. The retirement only applies to users who receive sign-in codes by text message or phone call. Staff who approve sign-ins through the Authenticator app are already on a stronger method, and most businesses will only have a small number of affected accounts.

What happens if we do nothing?

From 1 September 2026 affected users will be prompted to register a passkey when they sign in. From 1 February 2027 Microsoft-provided SMS and voice stop working entirely, and users with no other method will be blocked from signing in until they register a passkey.

Can we keep using SMS authentication after February 2027?

Only by configuring a customer-managed telecom provider through the Microsoft Security Store, and paying the telecom costs yourself. Microsoft intends this for organisations with a regulatory or operational requirement, not as a way to avoid the change.

What is a passkey?

A passkey is a sign-in credential stored on your device that uses public-key cryptography instead of a code. You approve sign-ins with your fingerprint, face, or PIN through Windows Hello, the Microsoft Authenticator app, or a physical security key. Because there is no code to type, there is nothing for a phishing site to steal.

Want to discuss how these insights apply to your business?