Microsoft Is Retiring SMS and Voice MFA: What Passkeys by Default Means for You

Microsoft is switching off SMS and voice MFA for Entra ID by February 2027, and passkeys are becoming the default way people prove who they are. If your team still gets a text message or a phone call as their second login step, this change affects you, and it’s worth acting on now rather than waiting for Microsoft to force the issue.

The short answer: Microsoft is retiring SMS and voice as MFA methods in Entra ID, with passkeys becoming the default instead. There’s no opt-out from the eventual switch, so the sensible move is to get ahead of it now: find out who in your business is still using SMS or voice, and start moving them to passkeys on your own timeline rather than Microsoft’s. Full dates below.

SMS and voice codes have always been the weakest link in multi-factor MFA. They can be intercepted, they’re vulnerable to SIM-swap fraud, and they don’t stop a well-crafted phishing page from harvesting the code in real time and using it before you notice anything wrong. Attackers have got much better at automating exactly this kind of attack, which is a big part of why Microsoft is pushing every tenant towards phishing-resistant methods rather than leaving it as a recommendation.

Passkeys close that gap. Instead of a code you type in (and could be tricked into typing into the wrong place), a passkey uses cryptographic keys tied to your device and confirmed with your fingerprint, face, or PIN. There’s nothing to intercept and nothing to phish, because the passkey simply won’t work on a fake login page. That’s a meaningful upgrade for any business that handles client data, financial information, or anything an insurer or regulator would care about.

1st September 2026

Any user still enabled for SMS or voice is automatically enabled for passkeys and prompted to register one the next time they log in. If you’d rather manage this rollout on your own terms, this is the deadline to act before Microsoft does it for you.
1st February 2027

Microsoft-provided SMS and voice MFA stops working entirely across Entra ID.

If you have a genuine reason to keep SMS or voice, a regulatory requirement or an operational constraint, for example the only route is a customer-managed telecom provider configured through the Microsoft Security Store rather than Microsoft’s own. This is a niche path most SMEs won’t need, but worth knowing about if it applies to you.
After 1st February 2027

Anyone whose only MFA method is SMS or voice hits a blocking prompt and can’t sign in until they set up a passkey. This isn’t a soft nudge; it stops access.

For most small and medium businesses, this isn’t a dramatic overhaul. It’s a case of knowing who in your organisation still authenticates by text or phone call, and getting them moved across before the deadline creates a fire drill. The businesses that struggle with changes like this are usually the ones that find out about it from a support ticket rather than planning for it, so the earlier you know your numbers, the calmer the rollout.

A few things worth thinking through before you start:

  • Not every device supports passkeys equally well. Older phones, shared kiosk-style machines, and some frontline worker setups need a bit more thought than a standard laptop-and-mobile user.
  • Passkeys can live in more than one place. Windows Hello, a phone’s built-in authenticator, or a physical security key can all work as a passkey, so you have some flexibility in how you roll this out across different teams.
  • User education still matters. A passkey is more secure by design, but a rollout that isn’t explained properly still generates confusion and helpdesk calls. A short, clear message about what’s changing and why goes a long way.
  • This is a good moment to review your wider authentication policy, not just tick off SMS and voice users. If you’re touching MFA settings anyway, it’s worth checking conditional access policies and legacy authentication methods at the same time.
  1. Find out who’s still on SMS or voice. This is visible in your Authentication Methods Policy in Entra ID. Most businesses are surprised by how many legacy users are still on it, often because it was the default years ago and never revisited.
  2. Enable passkeys for those users and start a registration push, ahead of the automatic enrolment date, so you can support people through it properly rather than reacting to it.
  3. Communicate the change clearly, in plain terms, well before anyone hits a blocking prompt. People are far more receptive to a security change when they understand why it’s happening rather than being told to “just do it.”
  4. Flag any genuine exceptions early (see the telecom provider route above) rather than discovering them at the last minute.
  5. Fold this into your broader security posture, rather than treating it as a one-off Microsoft notice to action and forget. Phishing-resistant authentication is one part of a wider approach that should also include monitoring, patching and staff awareness.

It’s tempting to treat vendor security notices like this as background noise, but this one is a genuine step up in protection for very little effort. Credential theft and MFA-bypass attacks are consistently among the most common ways businesses get compromised, and SMS/voice codes are one of the easier methods for attackers to work around. Moving to passkeys removes a whole category of that risk without adding real friction for your team once it’s set up.

For SMEs without a dedicated in-house security function, changes like this are exactly where things get missed, not because anyone’s being careless, but because there’s rarely a single person whose job it is to track every vendor security update and translate it into “here’s what we need to do, and by when.” That’s the gap a managed SOC and IT partner is there to close.

As a Microsoft Partner and 24/7 Security Operations Centre for UK SMEs, this is exactly the kind of change we plan for on behalf of our clients, identifying who’s affected, running the rollout without disrupting day-to-day work, and making sure nothing gets left to the last minute. If you’d like a hand finding out who in your business is still on SMS or voice authentication, or want support planning a passkey rollout before the September deadline, get in touch with our team.

A passkey is a phishing-resistant way to sign in that replaces passwords and one-time codes with a cryptographic key stored on your device, unlocked with your fingerprint, face, or device PIN. It can’t be phished or intercepted the way an SMS code can.

Microsoft-provided SMS and voice MFA in Entra ID retires on 1st February 2027. Automatic enrolment into passkeys for existing SMS/voice users begins earlier, on 1st September 2026.

Only if your only MFA method is SMS or voice and you haven’t registered an alternative by the time enforcement begins. Setting up passkeys (or another phishing-resistant method) before then avoids any disruption.

No. If no one in your tenant is enrolled in SMS or voice MFA, this change doesn’t affect you directly, though it’s still a good prompt to review your wider MFA setup.

Only via a customer-managed telecom provider configured through the Microsoft Security Store, which is intended for businesses with a specific regulatory or operational need. For most SMEs, moving to passkeys is the simpler and more secure route.

Book your free consultation today