Do you want to switch the language?

Discontinuation of Microsoft SMS & Voice Authentication

Microsoft is phasing out SMS and voice authentication: passkeys are becoming the standard

Microsoft Entra ID is gradually transitioning authentication to stronger, phishing-resistant methods. Passkeys are becoming the standard sign-in experience, whilst Microsoft-provided SMS and voice authentication are being phased out as a native Microsoft Entra ID capability.

For organisations, this means that users who currently still use SMS or voice calls as a multi-factor authentication (MFA) method should be migrated to passkeys or other phishing-resistant methods, such as Windows Hello for Business or FIDO2 security keys, in good time. If the transition is not completed in good time, disruptions to the sign-in process may occur from February 2027.

Organisations should therefore check now which users are still using SMS or voice authentication, plan the roll-out of passkeys and inform affected users well in advance.

Why are SMS and voice authentication being phased out?

Microsoft no longer considers SMS and voice to be secure authentication methods. This is due to the shift away from methods susceptible to phishing towards phishing-resistant authentication. Passkeys use cryptographic keys instead of shared secrets and, according to Microsoft, are resistant to phishing, SIM swapping and replay attacks.

This change forms part of a stronger focus on security for Microsoft Entra ID and the growing importance of secure authentication in AI-enabled work environments.

TimingMicrosoft changeWhat customers should do
1 September 2026Users who are enabled for SMS or voice authentication will be automatically enabled for passkeys and prompted to register when signing in with MFA.Inform end users, prepare the tenant for passkeys and plan passkey deployment.
18 September 2026Microsoft announces further information regarding customer-managed telecoms providers via the Microsoft Security Store.Check whether there are any regulatory or operational requirements for SMS/voice.
30 October 2026According to Microsoft, customers who still require SMS or voice services can select and configure a telecoms provider via the Microsoft Security Store.Assess exceptional cases, review provider options and conduct a pilot test.
1 February 2027Microsoft-provided SMS and voice services will be fully phased out in Microsoft Entra ID.Migrate all users to phishing-resistant methods or configure a customer-provided telecoms provider.
After 1 February 2027Users whose only MFA method is SMS or voice must register a passkey during sign-in; the prompt is blocking.Complete the migration beforehand to avoid sign-in disruptions.
We bring about positive change

Who is affected?

SMS or voice as an authentication method

This affects customers who have enabled SMS or voice as an authentication method in Microsoft Entra ID – either in the Authentication Methods Policy or via legacy MFA settings. According to Microsoft, Self-Service Password Reset (SSPR) is also affected by this retirement change.

Users who already use passkeys, Windows Hello for Business, FIDO2 security keys or other phishing-resistant methods are not affected by the SMS/voice dependency. These users can continue to use their existing methods.

How can customers determine whether they are affected?

Microsoft recommends identifying which users are enabled for SMS or voice prior to migration:

  • Identify users who are enabled for SMS or voice.
  • Check the Authentication Methods Policy and, where applicable, legacy MFA settings.
  • Create and prioritise user groups that rely on SMS or voice.
  • Check whether SMS or voice is also used for self-service password reset.
  • Document any exceptions where a telecommunications channel is required for regulatory or operational reasons.

Recommended approach for customers

Identify SMS and voice usage within the tenant and record the affected user groups:

  • Define a passkey strategy: synced passkeys, device-bound passkeys, Windows Hello for Business or FIDO2 security keys.
  • Prepare the tenant for passkey capability and define a pilot group.
  • Plan user communication: awareness, specific instructions and reminders.
  • For exceptional cases, check whether a customer-managed telecoms provider via the Microsoft Security Store is required.
  • Before 1 February 2027, ensure that users are not relying solely on SMS or voice.

Technical Focus

Passkeys

Passkeys are the standard option recommended by Microsoft for phishing-resistant authentication in Microsoft Entra ID. They can be device-bound or synchronised and are based on cryptographic keys rather than one-time codes.

Windows Hello for Business and FIDO2 security keys

Microsoft cites Windows Hello for Business and FIDO2 security keys as further phishing-resistant methods to which users should migrate before the retirement date.

Telecommunications providers managed by customers

If SMS or voice communication is still required for regulatory, operational or technical reasons, Microsoft refers customers to telecoms providers managed by the customer via the Microsoft Security Store. This option should only be used for clearly defined user segments.

CANCOM M365 Pro-Active Services

Microsoft 365 is constantly evolving. New features, changes, risks and technical end-of-life announcements are now part and parcel of day-to-day cloud operations. With CANCOM M365 Pro-Active Services, we help Microsoft 365 administrators stay proactively informed and better understand relevant changes within their own environment.

In the context of ‘Passkeys by Default’ and the retirement of Microsoft-provided SMS and voice authentication, this means that CANCOM assists customers as part of its general Microsoft 365 and Entra ID operational and configuration support. The aim is to highlight relevant changes at an early stage, jointly assess configurations and provide expert guidance on necessary adjustments.

Service modules in accordance with CANCOM M365 Pro-Active Services

ModuleBenefits in the context of Passkeys / Entra ID / M365 operations
Release RadarRelevant Microsoft 365 and Entra ID changes are professionally filtered, both retrospectively and prospectively, and prepared for practical IT use.
Regular GAP analysisConfiguration discrepancies are identified based on proven CANCOM best practices.
Security InsightsAlerts regarding identity risks and security-related events within the customer’s tenant support improved security management.
Adoption InsightsAnalyses of service usage, as well as MFA and password reset statuses, help to manage transitions such as passkeys in a structured manner.
Service AvailabilityRelevant disruptions and outages within the Microsoft 365 cloud services are summarised.
Tenant Health Review / M365 Tenant AssessmentAn annual expert review of Microsoft 365 data and critical settings, including personalised advice.

You might also be interested in:

Microsoft Secure Boot certificates

Read more

Discontinuation of Microsoft SMS & Voice Authentication

Read more

Contact
CANCOM Austria

Please speak to your CANCOM contact if you would like to know how to prepare your Microsoft 365 environment for ‘Passkeys by Default’ and the retirement of Microsoft-provided SMS and voice authentication.

CANCOM Austria AG processes your personal data exclusively in the context of your inquiry. Processing is carried out in accordance with Art. 6(1)(b) GDPR for the performance of a contract or a request. For storage and hosting, we use IT service providers who may access your data in the process. Providing your data is voluntary; however, without it, your inquiry cannot be processed. For questions, you can reach us at info@cancom.com.

Under this link you will find our privacy policy with further information.
How may I help you?
CANCOM Austria AG processes your personal data exclusively in the context of your inquiry. Processing is carried out in accordance with Art. 6(1)(b) GDPR for the performance of a contract or a request. For storage and hosting, we use IT service providers who may access your data in the process. Providing your data is voluntary; however, without it, your inquiry cannot be processed. For questions, you can reach us at info@cancom.com.

Under this link you will find our privacy policy with further information.