Microsoft is retiring SMS and voice MFA. What your business needs to do before February 2027

(Correct as of August 2026)

Microsoft is retiring SMS and voice MFA, and unlike a lot of Microsoft announcements, this one has a hard stop. From 1 February 2027, Microsoft will no longer send the text messages or make the automated phone calls that many businesses still use to verify sign-ins to Microsoft 365.

If your users already approve sign-ins through the Microsoft Authenticator app, a security key or Windows Hello, you're largely fine. If some of them still get a six-digit code by text, you've got work to do, and about five months before the first changes start appearing on their screens without warning.

Here's what's happening and what we'd recommend.

What exactly is changing?

Two separate things are bundled into one announcement, and it helps to keep them apart.

Passkeys become the default. From 1 September 2026, passkeys become the default sign-in experience in Microsoft Entra ID and are automatically enabled for anyone currently enabled for SMS or voice. Those users will start getting nudged to register a passkey when they complete MFA.

Microsoft stops delivering the texts and calls. From 1 February 2027, Microsoft-provided telecom delivery for SMS and voice is retired. The method itself doesn't vanish, but Microsoft is no longer the one sending the message. If you genuinely need a telecoms channel after that date, you'll need to bring your own provider through the Microsoft Security Store.

Everything else stays exactly as it is. Microsoft Authenticator push notifications and one-time codes, FIDO2 security keys, Windows Hello for Business, hardware tokens and third-party MFA are all unaffected.

When is it happening?

1st September 2026

Users enabled for SMS or voice are automatically enabled for passkeys and start being prompted to register one at sign-in. Your registration campaign settings change automatically too.

18th September 2026

Microsoft publishes details of the telecom providers available through the Security Store.

30th October 2026

You can select and configure a telecom provider if you need to keep SMS or voice.

1st February 2027

Microsoft-provided SMS and voice delivery is retired.

After 1st February 2027

Anyone whose only MFA method is SMS or voice gets a blocking prompt to register a passkey before they can sign in.

Two things stand out on that timeline. The September changes happen automatically, so doing nothing is still a decision. And there's no opt out from the February behaviour, which will be enforced across all tenants.

There is a temporary opt-out available for the September changes if you need breathing room while you plan, but it expires at the February deadline like everything else.

Who's affected?

You're in scope if you have anyone enabled for SMS or voice in your Entra authentication methods policy, or sitting in the older legacy MFA settings that plenty of tenants still have switched on quietly in the background.

In our experience it's rarely the whole business. It's usually a specific group: people who joined before the Authenticator app rollout, staff who didn't want a work app on a personal phone, senior people who set it up years ago and were never moved across, or shared and site-based accounts nobody wanted to touch.

It also catches self-service password reset. If your users reset their own passwords by receiving a text, that flow is affected too, which is the bit most businesses miss until someone locks themselves out on a Monday morning.

What happens if we do nothing?

Nothing dramatic happens on 1 February. Accounts aren't deleted or disabled.

What happens instead is quieter and more annoying. Affected users sit down, try to sign in, and hit a prompt they can't skip telling them to register a passkey. They'll do it on a personal phone, in a hurry, without guidance, or they'll ring whoever handles IT and ask what's going on.

That's the real cost here. It's not a security incident, it's a queue at the help desk, on a day you didn't choose, involving people who tend not to enjoy surprises about how they log in. Handled properly and in advance, it's a fifteen-minute job per person. Handled reactively, it's a fortnight of interruptions.

What to do before February 2027

Here's the order we'd work in.

1. Find out who's actually affected. Microsoft has published a PowerShell script that lists every user enabled for SMS or voice in your tenant. You can also pull this from the authentication methods activity report in the Entra admin centre. Start here, because the number is usually either much smaller or much larger than people assume, and it changes the plan either way. If you are one of our customers, we'll do this without needing you to do anything. We'll be in touch to let you know if you're affected.

2. Turn passkeys on properly. Make sure passkeys are enabled as an authentication method and decide which types you'll allow: passkeys held in Microsoft Authenticator, Windows Hello for Business, or physical security keys for the people who need them. This is a policy decision, not just a switch.

3. Tell your people before Microsoft does. This is the single biggest factor in whether the change goes smoothly. A short, plain-English message explaining what's changing, when, and what they need to do beats any technical control. Microsoft publishes end-user comms templates you can adapt.

4. Run the registration campaign on your terms. You can start prompting users to register a passkey now, at a pace you choose, rather than having it switched on automatically in September. Doing it during a quiet week, with support ready, is far better than having it land mid-quarter-end.

5. Sort out the awkward cases early. Shared accounts, shop floor and site-based staff, people without a smartphone, and break-glass admin accounts all need a decision. These take the longest and they're the ones that get left until January.

6. Decide whether you genuinely need SMS. If you're in a regulated sector with a real requirement for an out-of-band text message, you can configure a customer-managed telecom provider through the Security Store from 30th October 2026. Bear in mind it's a paid, per-message service, whereas moving users to passkeys costs nothing extra. For most businesses, passkeys are the answer.

7. Check your password reset flows. Anywhere SMS is used for self-service password reset needs the same treatment.

Why is Microsoft doing this?

Because codes sent by text can be intercepted, and people can be talked into reading them out. SIM swap fraud and phishing sites that harvest one-time codes in real time have made SMS a weak link, and attackers have got noticeably better at both.

Passkeys work differently. They use a cryptographic key tied to a device rather than a shared code, so there's nothing for a user to type in and nothing for an attacker to intercept. There's no code to be tricked out of someone.

For most businesses, this ends up being a genuine improvement rather than a chore. Signing in gets faster, the help desk fields fewer password resets, and one of the more common routes into a Microsoft 365 account closes.

Frequently asked questions

Do we have to move everyone to passkeys? No, but everyone needs to be on a phishing-resistant method. Microsoft Authenticator, Windows Hello for Business and FIDO2 security keys all still work. Passkeys are the default, not the only option.

What if some of our staff don't have smartphones? Physical security keys work well here, as does Windows Hello for Business on a company laptop. This is a solvable problem, it just needs deciding on early.

Does this affect anything other than sign-in? Yes. Self-service password reset by text is affected in the same way, and it's the flow most often forgotten.

Can we delay it? You can temporarily opt out of the automatic September changes while you prepare. You can't delay the 1 February 2027 retirement. That applies to every tenant.

Is there a cost? Moving users to passkeys costs nothing extra, as passkeys are included in your existing Microsoft licensing. Keeping SMS through a third-party telecom provider is a paid add-on, priced per message.

What we'd suggest doing next

If you're not sure how many of your users are still on SMS or voice, that's the question to answer first. Everything else follows from it.

We're working through this with our clients now, tenant by tenant: pulling the list of affected users, agreeing the right method for each group, and running the registration campaign at a time that suits the business rather than Microsoft's calendar.

If you'd like us to check your tenant and tell you what needs to change, get in touch and we'll take a look. It's a short conversation, and it's a much better one to have in September than in February.