What Microsoft has announced
Microsoft says SMS and voice are no longer suitable as its default security methods and is moving Microsoft Entra ID towards passkeys. The change affects the Microsoft provided delivery of text messages and telephone calls used for multifactor authentication and self service password reset.
Since 1 September 2026, users who are enabled for SMS or voice can be automatically enabled for passkeys and prompted to register one when they complete multifactor authentication. This prompt is intended to move people gradually rather than waiting for the retirement deadline.
From 1 February 2027, Microsoft provided SMS and voice authentication will be retired for most users. If a user in scope has no usable method other than SMS or voice, Microsoft says passkey registration will become a blocking part of sign in. There is no option to bypass that requirement after the deadline.
Global Administrators and external users have a later retirement date of 1 July 2027. Internal guest users remain in the February group. Organisations should treat these as final dates, not the start of their migration work.
This does not mean multifactor authentication is ending
Multifactor authentication remains essential. Microsoft is changing the method used to prove identity, not removing the need for additional protection. Turning off multifactor authentication would make an account easier to compromise and would not solve the retirement problem.
The announcement also does not mean every mobile number must immediately be deleted from Microsoft 365. Telephone details may still be used for contact information or other business purposes. The important question is whether a user depends on Microsoft sending a text message or placing a call so they can sign in or reset a password.
Users who already use a passkey, Windows Hello for Business or a FIDO2 security key can continue using those methods. People who use Microsoft Authenticator notifications are not relying on Microsoft telephone delivery, although they may still be encouraged to register a passkey if SMS or voice is enabled on their account.
Why text messages and calls are being replaced
A text message code is better than protecting an account with only a password, but it can still be stolen through convincing phishing pages, intercepted through attacks on mobile accounts or disclosed to a caller pretending to be from support. Voice calls present similar social engineering risks.
Passkeys work differently. They use cryptographic credentials that are linked to the genuine website or service, so a fake sign in page cannot simply collect a reusable password or code. The National Cyber Security Centre now recommends passkeys where a service supports them because they provide stronger resistance to phishing.
The practical benefit is that a user normally approves sign in with the face, fingerprint or PIN already used on their device. The biometric information remains on the device and is not sent to Microsoft.
Choose a method that fits how people work
Microsoft Entra ID supports more than one form of passkey. A passkey may be saved in a supported credential manager and synchronised across a user's devices, or it may be bound to a particular device. Device bound options include a passkey in Microsoft Authenticator, Windows Hello for Business and a FIDO2 hardware security key.
There is no single choice that suits every organisation. Office staff using assigned Windows computers may be well served by Windows Hello for Business. Mobile workers may prefer a passkey held in Microsoft Authenticator. A hardware security key can be useful where staff cannot use a personal mobile telephone, where devices are shared or where an account needs strong independent credentials.
Before selecting a method, consider who owns each device, whether people move between computers, how replacement devices will be issued, what happens when a key is lost and how users with accessibility needs will sign in. The recovery process matters as much as the initial registration.
Schools and shared devices need extra planning
Schools often have a mixture of assigned staff laptops, shared classroom computers, temporary staff, contractors, pupils and accounts used by external services. A passkey plan should reflect those different users rather than applying one method without testing it in the school environment.
Staff who cannot or should not use a personal telephone need an approved alternative. Shared computers must be tested carefully so that one person's credential is not treated as a shared login. Global Administrator accounts should remain separate from everyday accounts and have more than one secure recovery route.
Communications should explain what the new registration prompt looks like and where users should ask for help. This reduces the chance of people ignoring a genuine prompt or being tricked by a phishing message that uses the Microsoft change as its story.
Check who currently relies on SMS or voice
Start with evidence from Microsoft Entra ID rather than asking users to remember how they sign in. An administrator with an appropriate role can review authentication method registration and activity to identify people who are enabled for, or actively using, SMS and voice.
The review should include ordinary users, administrators, internal guests, external users and any accounts used for important services. Pay particular attention to accounts that have only one registered method, obsolete telephone numbers and users who have not signed in recently enough to see a registration prompt.
Self service password reset is also within the scope of the retirement. A user may normally sign in with an app but still depend on a text message when resetting a password, so both sign in and recovery arrangements need to be checked.
- Identify users enabled for SMS or voice in the Authentication methods policy.
- Review recent authentication method activity and registration reports.
- Find users whose only available method is a text message or telephone call.
- Check Global Administrators, internal guests and external users separately.
- Confirm that emergency access accounts have secure and tested credentials.
- Record users who need an alternative to a personal mobile telephone.
Use a controlled migration
Enable the chosen passkey methods for a small pilot group first. Include people using different devices and working patterns, then test normal sign in, password reset, device replacement and account recovery. Record any applications or older sign in processes that behave differently.
Microsoft provides a registration campaign that can prompt eligible users to create a passkey during their normal sign in journey. Targeting groups in stages makes it easier to support users and investigate problems before the next group is added.
Keep an approved temporary method available during the change, but do not leave SMS as the permanent fallback for everyone. Once a person has registered and tested the new method, review whether old telephone authentication can be removed from their account and policy.
Microsoft plans to let organisations that still require SMS or voice purchase delivery from a supported telephony provider through Microsoft Security Store from 30 October 2026. This creates an alternative for genuine operational needs, but it introduces a provider agreement, possible costs and additional management. Microsoft recommends passkeys as the main migration route wherever possible.
Practical preparation checklist
- Confirm who owns the Microsoft Entra authentication policy and the migration plan.
- Export or review the users enabled for SMS and voice authentication.
- Identify anyone who has no other usable sign in or recovery method.
- Choose suitable passkey options for office, mobile and shared device users.
- Include accessibility, lost device and staff departure scenarios.
- Pilot registration and recovery with a representative group.
- Prepare clear user instructions and a route for support.
- Roll out in manageable groups and monitor registration progress.
- Protect Global Administrator and emergency access accounts separately.
- Check self service password reset as well as normal sign in.
- Complete the main migration before 1 February 2027.
- Complete the separate plan for Global Administrators and external users before 1 July 2027.
How Bury I.T. Support can help
Bury I.T. Support can review the authentication methods used across your Microsoft 365 tenant, identify users who depend on SMS or voice and plan a suitable move to passkeys, Windows Hello for Business or security keys.
We can also help with pilot groups, user communications, administrator protection and recovery planning so the change improves security without causing avoidable sign in problems for staff or pupils.
Official sources and further reading
These primary sources were checked when this article was last reviewed.
- Microsoft: Passkeys by default and retirement of Microsoft provided SMS and voice authentication
- Microsoft: Frequently asked questions about SMS and voice retirement
- Microsoft: Run a registration campaign for passkeys or Microsoft Authenticator
- Microsoft: Passkeys in Microsoft Entra ID
- NCSC: Passkeys are more secure than traditional ways to log in
- NCSC: Recommended types of multifactor authentication
