Home | Microsoft Is Retiring SMS Authentication: What Businesses Need to Know

Microsoft Is Retiring SMS Authentication: What Businesses Need to Know

Microsoft is changing how users sign in to Microsoft 365 and other Microsoft services.

From September 2026, passkeys will become the default authentication method in Microsoft Entra ID, and from February 2027, Microsoft’s built-in SMS and voice authentication services will be retired. Businesses still relying on text message authentication should start planning their transition now.

For businesses already using Microsoft 365, this change is another step towards stronger, phishing-resistant security and a future with fewer passwords.

Microsoft SMS Authentication Retirement: Quick Overview

Microsoft is:

  • Making passkeys the default authentication method from 1 September 2026.
  • Retiring Microsoft-provided SMS and voice authentication from 1 February 2027.
  • Encouraging organisations to adopt phishing-resistant authentication methods such as passkeys, Windows Hello for Business and FIDO2 security keys.
  • Requiring businesses that still need SMS or voice authentication to use a third-party telecom provider.

In short, Microsoft is moving away from traditional text-message verification and towards passwordless authentication.

When Is Microsoft Retiring SMS Authentication?

The change will happen in two stages.

1 September 2026

Users who are currently enabled for SMS or voice authentication will automatically be enabled for passkeys and encouraged to register them during the authentication process.

1 February 2027

Microsoft will retire its own SMS and voice authentication service within Microsoft Entra ID. Organisations that continue to use these methods will need to work with an approved telecom provider instead.

Businesses that do not prepare before this date could face sign-in disruption for users who still rely exclusively on SMS or voice verification.

Why Is Microsoft Replacing SMS Authentication With Passkeys?

The short answer is even stronger cyber security.

SMS authentication was once considered a major improvement over passwords alone, but cyber threats have continued to evolve. Attackers now regularly use phishing, social engineering and SIM-swapping techniques to bypass text-message verification methods.

Passkeys are designed differently. Instead of relying on passwords or one-time codes, they use cryptographic technology that is significantly more resistant to phishing and credential theft.

For businesses, this means stronger protection against account compromise and a lower risk of successful cyber attacks.

What Is a Passkey?

A passkey is a secure, passwordless way of signing in.

Rather than entering a password and waiting for a text message, users verify their identity using a trusted device or biometric method, such as:

  • Fingerprint recognition
  • Facial recognition
  • A device PIN
  • A security key

Because passkeys are tied to a user’s device and use modern cryptography, they are much harder for criminals to steal or misuse than passwords and SMS codes.

What Does This Mean for Microsoft 365 Users?

For many organisations, very little will change day-to-day.

Businesses already using passkeys, Windows Hello for Business or FIDO2 security keys are already aligned with Microsoft’s direction of travel.

However, organisations that still rely on SMS authentication for multi-factor authentication (MFA) should begin reviewing their environment and planning their transition.

This is particularly important for organisations looking to strengthen cyber security, improve Microsoft 365 security and reduce their reliance on passwords.

How Should Businesses Prepare For Microsoft Retiring SMS Authentication?

The good news is that there’s plenty of time to get ahead of the change. By starting early, businesses can reduce risk, avoid last-minute disruption, and help users become comfortable with new authentication methods. Here are four ways to prepare for the move to passkeys.

Review Existing Authentication Methods

Identify which users are currently using SMS or voice authentication and understand how widely these methods are used across the business.

Begin Planning a Passkey Rollout

Introducing passkeys before the deadline helps avoid a rushed migration and gives users time to become familiar with the new sign-in experience.

Communicate the Changes

Many users will be unfamiliar with passkeys. Clear communication and simple guidance can help ensure a smooth transition.

Strengthen Your Security Strategy

Microsoft’s move towards phishing-resistant authentication is part of a wider shift towards passwordless security. This is a good opportunity to review your wider Microsoft 365 security posture and cyber security policies.

Frequently Asked Questions

Is Microsoft completely removing SMS authentication?
Microsoft is retiring its own SMS and voice authentication service within Microsoft Entra ID. Organisations that still require these methods will need to use an alternative telecom provider.


Are passkeys more secure than SMS codes?
Yes. Passkeys are designed to be phishing-resistant and provide stronger protection against credential theft, account compromise and social engineering attacks than SMS-based authentication.


Will this affect Microsoft 365 users?
Yes. Any organisation using Microsoft Entra ID and SMS or voice authentication should review its authentication methods and prepare for Microsoft’s deadlines.


What are the alternatives to SMS authentication?
Microsoft recommends moving to phishing-resistant methods such as passkeys, Windows Hello for Business and FIDO2 security keys.

How ITC Service Can Help

Microsoft’s move to passkeys is a positive step for security, but every organisation’s environment is different. Understanding who’s using SMS authentication, planning a transition strategy and ensuring users remain productive can require careful planning.


At ITC Service, we help organisations make the most of Microsoft 365 while keeping security practical and user-friendly. Whether you’re reviewing your multi-factor authentication policies, exploring passwordless authentication, or preparing for Microsoft’s latest security changes, we’re here to help.

Share this post

Facebook
Twitter
LinkedIn