Microsoft is phasing out SMS and voice authentication: passkeys are becoming the standard
Microsoft Entra ID is gradually transitioning authentication to stronger, phishing-resistant methods. Passkeys are becoming the standard sign-in experience, whilst Microsoft-provided SMS and voice authentication are being phased out as a native Microsoft Entra ID capability.
For organisations, this means that users who currently still use SMS or voice calls as a multi-factor authentication (MFA) method should be migrated to passkeys or other phishing-resistant methods, such as Windows Hello for Business or FIDO2 security keys, in good time. If the transition is not completed in good time, disruptions to the sign-in process may occur from February 2027.
Organisations should therefore check now which users are still using SMS or voice authentication, plan the roll-out of passkeys and inform affected users well in advance.
Why are SMS and voice authentication being phased out?
Microsoft no longer considers SMS and voice to be secure authentication methods. This is due to the shift away from methods susceptible to phishing towards phishing-resistant authentication. Passkeys use cryptographic keys instead of shared secrets and, according to Microsoft, are resistant to phishing, SIM swapping and replay attacks.
This change forms part of a stronger focus on security for Microsoft Entra ID and the growing importance of secure authentication in AI-enabled work environments.
| Timing | Microsoft change | What customers should do |
|---|---|---|
| 1 September 2026 | Users who are enabled for SMS or voice authentication will be automatically enabled for passkeys and prompted to register when signing in with MFA. | Inform end users, prepare the tenant for passkeys and plan passkey deployment. |
| 18 September 2026 | Microsoft announces further information regarding customer-managed telecoms providers via the Microsoft Security Store. | Check whether there are any regulatory or operational requirements for SMS/voice. |
| 30 October 2026 | According to Microsoft, customers who still require SMS or voice services can select and configure a telecoms provider via the Microsoft Security Store. | Assess exceptional cases, review provider options and conduct a pilot test. |
| 1 February 2027 | Microsoft-provided SMS and voice services will be fully phased out in Microsoft Entra ID. | Migrate all users to phishing-resistant methods or configure a customer-provided telecoms provider. |
| After 1 February 2027 | Users whose only MFA method is SMS or voice must register a passkey during sign-in; the prompt is blocking. | Complete the migration beforehand to avoid sign-in disruptions. |


