All advice

Security · 5 min read

Move off SMS and voice MFA before Microsoft retires them in 2027

Microsoft is retiring SMS and voice MFA. Here is what it means and what to do.

A glowing blue smartphone showing a passkey icon with a faded crossed-out SMS text bubble, representing the move from SMS MFA to passkeys in Microsoft Entra ID

If anyone in your organisation logs in with a code sent by text message or a phone call, this one is for you. Microsoft is retiring SMS and voice multi-factor authentication in Microsoft Entra ID, and the deadline is closer than it sounds.

What is changing

Microsoft is moving to phishing-resistant authentication by default, and passkeys are becoming the standard way to sign in. As part of that shift:

  • Passkeys become the default for users who currently use SMS or voice.
  • Microsoft-provided SMS and voice will retire on 1 February 2027.
  • Customer-managed telecom providers, configured through the Microsoft Security Store, are not affected.

The reason is straightforward. SMS and voice are among the weakest authentication methods available today. They are vulnerable to phishing, SIM-swap and replay attacks. Passkeys are stronger, simpler and harder to trick a user out of.

The key dates

  • 1 September 2026. Users currently enabled for SMS or voice are automatically enabled for passkeys, and will be nudged to register one the next time they complete MFA. If you do not want this, move users off SMS or voice in the Authentication Methods Policy before this date.
  • 1 February 2027. Microsoft-provided SMS and voice are fully retired in Entra ID.
  • After 1 February 2027. Anyone whose only available MFA method is SMS or voice will get a blocking prompt to register a passkey before they can sign in. There is no opt-out, it applies to every tenant.

If nobody in your tenant uses SMS or voice, you do not need to do anything.

What to do if you have SMS or voice users

The required action is to move every one of those users off SMS and voice before 1 February 2027. Microsoft recommends passkeys, which are the default phishing-resistant credential in Entra ID.

  • Find affected users. Identify who is still enabled for SMS or voice.
  • Move them to passkeys. Enable passkeys and run a registration campaign so people are set up before the automatic enablement on 1 September 2026.
  • Communicate the change. Tell your users what is changing, when, and what they need to do. A short heads-up goes a long way.
  • Evaluate a telecom provider only if you must. If you have a regulatory or operational reason to keep SMS or voice, configure a customer-managed provider through the Microsoft Security Store before 1 February 2027. Provider options and pricing are published from 18 September 2026, with configuration available from 30 October 2026.

The bottom line

Every SMS and voice user must be on a phishing-resistant method, passkeys recommended, before Microsoft-provided SMS and voice retire on 1 February 2027. Acting before 1 September 2026 lets you move people on your own schedule and avoid the blocking prompts.

If you are not sure whether anyone in your tenant is still on SMS or voice, or you would like a hand moving people to passkeys, get in touch.

Microsoft's official guidance

For the full migration steps from Microsoft, read the passkeys by default documentation. If you would rather have it translated into a plan for your tenant, that is exactly the kind of thing I do, so get in touch.

Need a hand with this?

I help small organisations across the UK with exactly this kind of work. Honest advice, plain English, no pressure.

Get in touch