Microsoft is making a major change to multi-factor authentication (MFA) that could affect businesses using Microsoft 365.
From 1 February 2027, Microsoft will retire its own SMS and voice-call authentication delivery in Microsoft Entra ID as it moves users towards stronger, phishing-resistant authentication methods such as passkeys.
But businesses shouldn't wait until 2027 to deal with it.
The first significant change begins on 1 September 2026. Users who are currently enabled for SMS or voice authentication will be automatically enabled for passkeys and may start being prompted to register a passkey when they sign in and complete MFA.
For many organisations, that means employees who currently receive a six-digit security code by text message could soon start seeing unfamiliar Microsoft prompts asking them to set up a passkey.
This isn't something businesses should simply leave for users to work out for themselves.
Microsoft 365 administrators should identify which accounts still rely on SMS or voice MFA, decide which authentication method those users should move to, communicate the change and complete the migration well before Microsoft's February 2027 deadline.
In this guide, we'll explain what's changing, when it happens, what a passkey is, whether SMS MFA is disappearing completely, and what UK businesses using Microsoft 365 should do now.
Is Microsoft Ending SMS MFA?
Yes — but there is an important distinction.
Microsoft is retiring Microsoft-provided SMS and voice authentication in Microsoft Entra ID. The first stage begins on 1 September 2026, when users currently enabled for SMS or voice authentication will also be enabled for passkeys and may be prompted to register one.
From 1 February 2027, Microsoft-provided SMS and voice authentication will be retired, and users who have not registered another supported authentication method may be required to set up a passkey before they can continue.
This means businesses with employees who still rely on receiving an MFA code by text message or an automated voice call need to review their authentication arrangements now.
Key dates: Passkey registration changes begin 1 September 2026. Microsoft-provided SMS and voice authentication retires 1 February 2027.
Why Is Microsoft Getting Rid of SMS MFA?
SMS-based multi-factor authentication is significantly better than protecting an account with a password alone, but it is no longer considered one of the strongest ways to secure an account.
The problem is that a security code sent by text message can still be intercepted, stolen or tricked out of a user.
Common attacks include:
- Phishing – a user can be persuaded to enter both their password and SMS verification code into a fake Microsoft sign-in page.
- Adversary-in-the-middle attacks – sophisticated phishing sites can relay authentication information to the genuine service in real time.
- SIM-swap attacks – criminals can sometimes persuade a mobile provider to transfer a victim's telephone number to another SIM.
- Social engineering – users can be manipulated into disclosing authentication codes to someone pretending to be from Microsoft, IT support or another trusted organisation.
- Telephone network weaknesses – SMS and voice authentication ultimately depend on telecommunications infrastructure that was not originally designed as a modern identity-security system.
Microsoft has therefore been moving customers towards phishing-resistant authentication, where simply knowing a password or obtaining a six-digit code is not enough to impersonate the user.
What Is Microsoft Replacing SMS MFA With?
A major part of Microsoft's strategy is the increased use of passkeys.
A passkey allows a user to authenticate using a cryptographic credential associated with their device or security key rather than relying on a password and a code delivered by SMS.
Depending on the device and configuration, the user might authenticate using:
- Windows Hello;
- a fingerprint;
- facial recognition;
- a device PIN;
- Microsoft Authenticator; or
- a FIDO2-compatible physical security key.
The important difference is that passkeys are designed to be phishing-resistant.
A traditional SMS code can be typed into a convincing fake Microsoft login page. A properly implemented passkey is tied cryptographically to the genuine service, making that type of credential theft considerably harder.
Does This Mean Microsoft Authenticator Is Being Retired?
No. Microsoft Authenticator is not being retired as part of this change.
In fact, Microsoft Authenticator can be used as part of Microsoft's move towards stronger passwordless authentication, including device-bound passkeys.
Businesses should therefore distinguish between SMS or voice MFA and the Microsoft Authenticator app. They are different authentication methods, even though both may currently be offered to users during a Microsoft 365 sign-in.
Is Microsoft Turning Off All SMS Authentication?
Not quite.
The February 2027 change specifically concerns Microsoft-provided SMS and voice authentication services in Microsoft Entra ID.
Microsoft is also providing options for organisations that have a genuine requirement to continue using telephone-based authentication through supported external telecommunications providers.
For most SMEs, however, the more important question is not how to preserve SMS authentication indefinitely.
It is whether users can be moved to a stronger authentication method before Microsoft's changes begin affecting their normal sign-in experience.
Microsoft SMS MFA Retirement Timeline
Microsoft is introducing the change in stages. Businesses should pay particular attention to these two dates:
Stage One
1 September 2026
Users who are currently enabled for Microsoft-provided SMS or voice authentication will also be enabled for passkeys.
After successfully completing MFA, affected users may be prompted to register a passkey as Microsoft begins moving accounts towards stronger authentication.
Stage Two
1 February 2027
Microsoft-provided SMS and voice authentication will be retired.
Users who still depend on these methods and have not registered another supported authentication method may encounter a blocking passkey registration experience before they can continue.
Important: February 2027 should not be treated as the date to start preparing. User-facing changes begin in September 2026, so organisations still relying on SMS or voice MFA should review their Microsoft 365 authentication methods now.
What Should Microsoft 365 Administrators Do Now?
Businesses shouldn't wait until employees start seeing unfamiliar passkey registration prompts.
The first step is to understand how people in your organisation currently authenticate to Microsoft 365 and identify anyone who still depends on SMS or voice calls for MFA.
Microsoft 365 administrators should consider the following:
1. Identify Users Still Relying on SMS or Voice MFA
Review the authentication methods registered against users in Microsoft Entra ID.
Pay particular attention to accounts where a mobile telephone number and SMS verification remain the user's primary or only practical MFA method.
This will give you an indication of how many employees need to be migrated before Microsoft's changes take effect.
2. Decide Which Authentication Methods Your Business Will Support
Don't simply allow users to choose whatever authentication method is most convenient.
Organisations should decide which methods are appropriate for their security requirements, devices and workforce.
Depending on the environment, that could include:
- Microsoft Authenticator;
- passkeys;
- Windows Hello for Business;
- FIDO2 security keys; and
- other authentication methods supported by Microsoft Entra ID.
3. Test Passkey Registration Before Rolling It Out
Before asking an entire organisation to change authentication methods, test the process with a small group of users.
This helps identify potential problems involving devices, browsers, Microsoft Authenticator, Conditional Access policies or existing authentication configurations.
It also gives your IT provider or internal IT team an opportunity to understand the user experience before employees start asking for help.
4. Communicate the Change to Employees
This is particularly important from a cyber-security perspective.
If users suddenly receive a genuine Microsoft prompt asking them to register a passkey without having been warned beforehand, they may either ignore it or assume it is suspicious.
Conversely, once users know Microsoft is making the change, criminals may try to exploit that awareness with fake passkey-registration emails or phishing pages.
Employees should therefore be told:
- that Microsoft is changing its authentication requirements;
- when they should expect the change;
- which authentication method the business wants them to use;
- how the legitimate registration process works; and
- who to contact if they receive an unexpected authentication request.
5. Review Conditional Access and MFA Policies
This is a good opportunity to review the organisation's wider Microsoft 365 identity security rather than treating SMS retirement as an isolated change.
Businesses should check whether their existing Microsoft Entra and Conditional Access configuration still reflects how employees actually work.
That may include reviewing:
- which users are required to use MFA;
- legacy authentication;
- administrator accounts;
- authentication strength policies;
- sign-in risk;
- device requirements;
- guest accounts; and
- emergency access accounts.
What Happens If You Do Nothing?
Ignoring the change could eventually result in disruption for users who continue to depend on Microsoft-provided SMS or voice authentication.
From September 2026, affected users may begin seeing prompts to register a passkey.
Once Microsoft's SMS and voice authentication retirement takes effect in February 2027, users who haven't registered an appropriate alternative may encounter a blocking registration experience.
For a small business, dealing with this one employee at a time as people encounter sign-in problems is likely to be far more disruptive than planning the migration in advance.
The sensible approach is to identify affected accounts, choose the appropriate replacement authentication method and migrate users before the deadline becomes an operational problem.
Not Sure How Your Microsoft 365 Users Authenticate?
If your business uses Microsoft 365 but you're unsure which users still rely on SMS or voice MFA, KES can help review your Microsoft Entra authentication setup and identify accounts that may be affected by Microsoft's upcoming changes.
We can also help you assess stronger authentication options, review your existing MFA and Conditional Access policies, and plan a sensible migration before users start experiencing sign-in disruption.
Microsoft SMS MFA and Passkeys: Frequently Asked Questions
Why Is Microsoft Asking Me to Set Up a Passkey?
Microsoft is moving users towards stronger, phishing-resistant authentication methods and is retiring Microsoft-provided SMS and voice authentication.
From 1 September 2026, users who are currently enabled for SMS or voice authentication will also be enabled for passkeys and may be prompted to register a passkey after completing MFA.
If you use a Microsoft 365 account provided by your employer, your organisation may also have its own authentication policies that determine which methods you can use.
When Is Microsoft SMS MFA Ending?
Microsoft-provided SMS and voice authentication is scheduled to retire on 1 February 2027.
However, businesses should pay attention to the earlier 1 September 2026 date because that is when Microsoft's passkey registration changes begin affecting users currently enabled for SMS or voice authentication.
Will My Microsoft 365 Account Stop Working in February 2027?
Microsoft isn't switching off Microsoft 365 accounts simply because a user previously used SMS MFA.
However, users who still depend on Microsoft-provided SMS or voice authentication and haven't registered an appropriate alternative authentication method may encounter a blocking registration experience.
That's why businesses should migrate affected users before the February 2027 retirement date rather than waiting for employees to encounter the change themselves.
Can I Still Use Microsoft Authenticator?
Yes. Microsoft Authenticator is separate from SMS and voice authentication and is not being retired as part of this change.
Microsoft Authenticator can also support stronger passwordless authentication experiences, including passkeys.
What Is a Microsoft Passkey?
A passkey is a cryptographic credential that allows you to authenticate without relying on a traditional password and SMS security code.
Depending on your device and your organisation's configuration, authentication can involve Windows Hello, biometrics, a device PIN, Microsoft Authenticator or a compatible physical security key.
One of the major advantages of passkeys is that they are designed to be resistant to phishing attacks that attempt to steal passwords and MFA codes.
Do I Need to Buy Anything to Use a Passkey?
Not necessarily.
Many users may be able to use passkey-capable devices or Microsoft Authenticator without purchasing additional hardware.
Some organisations may choose to use physical FIDO2 security keys for particular users or circumstances, but the appropriate authentication method depends on the organisation's security requirements, devices and Microsoft 365 configuration.
Should I Remove SMS MFA From Everyone Immediately?
Businesses should avoid making authentication changes without first understanding their existing Microsoft Entra configuration and user requirements.
A planned migration is preferable: identify affected users, determine the replacement authentication methods, test them, communicate the change and then migrate users in a controlled way.
Does This Affect Small Businesses Using Microsoft 365?
Yes, potentially.
This isn't a change that only matters to large enterprises. Small and medium-sized businesses using Microsoft 365 can also have users registered for SMS or voice authentication through Microsoft Entra ID.
If employees currently receive text-message security codes when signing in to Microsoft 365, the organisation should check its authentication configuration and prepare for Microsoft's changes.
Could Criminals Use This Change for Phishing?
Potentially, yes.
Whenever a major technology provider introduces a change that requires users to take action, criminals have an opportunity to create convincing fake emails, sign-in pages or registration instructions.
Businesses should therefore tell employees how legitimate passkey registration will be handled and remind them not to follow unexpected links claiming that their Microsoft 365 account will be disabled unless they urgently “upgrade” their MFA.
If you're uncertain whether a Microsoft authentication prompt or email is genuine, contact your IT provider rather than entering credentials into an unfamiliar page.
More Microsoft 365 News & Advice
Microsoft is making significant changes across Microsoft 365, security and AI. Explore more practical guidance from KES for UK businesses.
Microsoft 365 Copilot Chat
Microsoft 365 users may already have access to Copilot Chat without purchasing a separate Microsoft 365 Copilot licence. Find out what's included and where the paid version differs.
Microsoft 365 Mailboxes Increasing to 100GB
Microsoft is increasing the primary mailbox limit for eligible Microsoft 365 business users from 50GB to 100GB. See who gets the increase and when it is happening.
Microsoft 365 Support for Business
KES helps businesses manage Microsoft 365 licensing, security, Exchange Online, Teams, SharePoint, identity and day-to-day support.
Is Your Business Ready for Microsoft's MFA Changes?
If you're unsure whether employees still rely on SMS or voice authentication, KES can review your Microsoft 365 environment and help you prepare for Microsoft's upcoming authentication changes.
We can help with Microsoft 365 security, Microsoft Entra, MFA, Conditional Access and ongoing Microsoft 365 management, helping your business move to stronger authentication without unnecessary disruption for users.
Talk to KES about Microsoft 365 security →
Last updated: 10 August 2026. Microsoft may update its authentication rollout, requirements and supported methods. KES will update this article if Microsoft announces material changes to the SMS and voice MFA retirement programme.