The End of an Era for MFA
For years, SMS text messages and automated phone calls have been the most common backup authentication methods in Microsoft 365 environments.
They were easy to deploy, familiar to users, and worked on virtually every mobile device.
That era is ending.
Microsoft has announced that passkeys will become the default authentication experience in Microsoft Entra ID on September 1, 2026, while Microsoft-provided SMS and Voice MFA will be retired on February 1, 2027. Organizations that continue relying on telephony-based authentication will need to migrate users to phishing-resistant authentication methods or implement a customer-managed telecom provider through the Microsoft Security Store.
This is one of the most significant authentication changes Microsoft has made since the introduction of Conditional Access and modern MFA.
Why Is Microsoft Making This Change?
The short answer is security.
SMS and Voice MFA have long been considered the weakest forms of multi-factor authentication because they remain vulnerable to:
- SIM swapping attacks
- Social engineering
- Adversary-in-the-middle phishing
- Intercepted authentication codes
- Real-time relay attacks
Microsoft's position is that as organizations adopt AI-powered productivity tools and increasingly cloud-centric workloads, authentication needs to become phishing-resistant by default. Passkeys provide substantially stronger protection because there is no code for an attacker to steal and no password to capture.
For many organizations, this announcement aligns with the broader industry movement toward:
- Passkeys
- Windows Hello for Business
- FIDO2 security keys
- Passwordless authentication
Security Takeaway
MFA is no longer enough. Phishing-resistant MFA is becoming the new baseline.
The Rollout Timeline
Key Dates
- September 1, 2026: Passkeys become the default authentication experience. Users currently enabled for SMS or Voice authentication are automatically enabled for passkeys and may begin seeing registration prompts during MFA sign-in.
- September 18, 2026: Microsoft plans to publish information about telecom provider options through the Microsoft Security Store for organizations that have business or regulatory reasons to continue phone-based MFA.
- October 30, 2026: Organizations that need SMS or Voice authentication can begin configuring customer-managed telecom providers.
- February 1, 2027: Microsoft-provided SMS and Voice MFA services are retired.
- After February 1, 2027: Users whose only authentication option is SMS or Voice will encounter a blocking registration experience and must register a passkey before continuing to sign in.
What Will Users Actually Experience?
This is where IT departments should focus their planning.
Most users will not suddenly lose access or be locked out on September 1. Instead, the experience will likely feel more like a gradual onboarding campaign.
Scenario 1: User Already Uses Microsoft Authenticator
Many organizations already use Microsoft Authenticator push notifications and number matching.
For these users:
- The sign-in experience remains largely unchanged at first.
- They may begin receiving prompts encouraging passkey registration.
- They can typically complete enrollment quickly when using an eligible device.
- Future authentication may shift from approval prompts to biometric or device-based verification.
This group should experience the least disruption.
Scenario 2: User Uses SMS MFA
These users are the primary target of Microsoft's rollout.
Current Process
- User enters password.
- Microsoft sends a text message.
- User enters the code.
- Access is granted.
Future Process
- User signs in.
- Microsoft prompts passkey registration.
- User configures a passkey using an eligible option such as Microsoft Authenticator, Face ID, Touch ID, Windows Hello, or a FIDO2 security key.
- Future authentications become passwordless or phishing-resistant.
The user may initially have opportunities to skip enrollment, but these prompts will become increasingly important as February 2027 approaches.
Scenario 3: Windows Hello for Business Users
Organizations already leveraging passwordless Windows authentication are in excellent shape.
Windows Hello for Business already provides a phishing-resistant authentication model and aligns directly with Microsoft's long-term strategy. Users utilizing Windows Hello may notice very little change.
Scenario 4: FIDO2 Security Key Users
Users already leveraging hardware security keys are effectively ahead of the migration.
Since these deployments already use phishing-resistant authentication, Microsoft's announcement simply reinforces the existing design.
The Biggest Challenge Will Not Be Technical
Many organizations assume authentication changes are infrastructure projects.
In reality, this will be a communication project.
Help desks should anticipate questions such as:
- What is a passkey?
- Why am I being prompted?
- Do I still need Microsoft Authenticator?
- What happens if I get a new phone?
- Can I use Face ID?
- Can I use a hardware key instead?
- How do I register multiple devices?
The organizations that communicate early will experience far fewer support incidents than those that wait for Microsoft registration prompts to begin appearing.
Help Desk Alert
Expect increased support volume around new phone replacements, passkey enrollment, Authenticator migration, hardware key questions, and Windows Hello onboarding.
What Should Administrators Do Now?
- Identify SMS and Voice users. Determine who is currently dependent on SMS or Voice MFA. These users represent the highest migration priority.
- Review Authentication Methods Policy. Verify which authentication methods are currently enabled and who is assigned to each method.
- Pilot passkeys. Start with IT staff and security teams so support personnel understand the user experience before broader deployment.
- Educate users. Create simple guides demonstrating passkey registration, device replacement procedures, recovery options, and multiple passkey enrollment.
- Update security standards. Many organizations still have standards that list SMS as an acceptable MFA method. Those documents should be updated now to reflect Microsoft's future direction.
Planning Reminder
Do not treat this as a February 2027 problem. September 2026 is when many users may begin seeing the change. That makes communication, pilot testing, and help desk readiness important before the retirement date arrives.
Final Thoughts
This announcement is bigger than the retirement of SMS.
It represents Microsoft's clearest signal yet that phishing-resistant authentication is becoming the new baseline security requirement for Microsoft 365 environments.
Organizations that have already invested in Microsoft Authenticator, Windows Hello for Business, FIDO2 security keys, Conditional Access, and passwordless authentication are well positioned for the transition.
Those still relying heavily on SMS and Voice MFA should begin planning now. September 2026 introduces the registration campaign, but February 2027 is the real deadline. By then, Microsoft's native SMS and Voice MFA services will be gone, and passkeys will be the expected authentication experience across Microsoft Entra ID.