Microsoft Entra ID Moving Away from SMS and Voice MFA

Microsoft

Microsoft announced that it will be making passkeys the default authentication method in Microsoft Entra ID and retiring Microsoft-provided SMS and voice MFA on February 1, 2027.
 

Microsoft has noted that SMS and voice are among the most vulnerable authentication methods available today and provide significantly weaker protection against phishing, SIM-swap, and replay attacks than passkeys. Moving to phishing-resistant methods gives your organization stronger security by default.

Key Changes

  • Passkeys will become the default MFA experience for users who currently use SMS or voice authentication.
  • Microsoft-provided SMS and voice MFA services will be retired on February 1, 2027.
  • Schools using a third-party telecom provider through the Microsoft Security Store can continue using SMS/voice if needed.

Important Dates

September 1st 2026

  • Users enabled for SMS or voice MFA will automatically be enabled for passkeys.
  • Users will be prompted to register a passkey the next time they complete MFA.

February 1st 2027

  • Microsoft-provided SMS and voice MFA are retired.

After February 1st 2027

  • Users whose only MFA option is SMS or voice will be blocked from signing in until they register a passkey.
  • This enforcement applies to all tenants with no opt-out.

How to Prepare

If no users in your tenant are enabled for SMS or voice, no action is required and you can disregard the steps below.

If you do have users enabled for SMS or voice, the required action is to move every one of those users off SMS and voice before February 1, 2027. Microsoft recommends the following guidance to help you begin planning your transition now.  This will allow you to select the deployment approach that best fits your organization and ensure your users are prepared for upcoming changes to their sign-in experience.

  1. Identify users using SMS or voice MFA.
  2. Plan your passkey rollout. Enable passkeys and select the types that best fit your users’ devices and workflows. Microsoft Entra ID supports:
    • Synced passkeys: Passkeys stored in platform credential managers such as iCloud Keychain and Google Password Manager.
    • Device-bound passkeys: Passkeys tied to a specific device, such as:
      • Microsoft Authenticator passkeys
      • Entra passkeys on Windows
      • FIDO2 security keys
  3. Use a registration campaign to drive adoption. Microsoft Entra ID can help organizations accelerate passkey adoption at scale by prompting users to register a passkey during their multifactor authentication (MFA) sign-in experience. This approach encourages users to enroll passkeys as part of their normal sign-in flow, reducing friction and increasing enrollment rates across the organization. Steps to Run a Registration Campaign
  4. Communicate the change and timeline to users.

*If your school utilizes SMS or voice MFA, Microsoft recommends that you consider migrating users to passkeys now.  Completing the transition before September 1st 2026 will allow you to manage the rollout proactively and avoid user disruption when Microsoft retires SMS and voice authentication on February 1st 2027.

If SMS/voice must remain for compliance or operational reasons:

Today, Microsoft operates the backend telecommunications service that delivers MFA text messages and voice calls. After February 1st 2027, Microsoft will no longer provide this service. Schools that still require SMS or voice MFA should begin evaluating customer-managed telecom providers now and plan to select an approved provider through the Microsoft Security Store when they become available on October 30th 2026.

For more context on why Microsoft is moving to phishing-resistant authentication by default, please read their Microsoft Security Blog announcement.

If you have questions or would like more information please don’t hesitate to contact us.
Scroll to Top