Microsoft Is Moving Away from SMS Authentication: What You Need to Know About Entra ID Passkeys

Jul 29, 2026Cybersecurity, IT Management, Microsoft, Security

SMS to Passkeys

If your organization uses Microsoft 365 or Microsoft Entra ID, there’s an important authentication change on the horizon that should be on your radar.

Microsoft recently announced that it will begin moving users away from SMS and voice-based multi-factor authentication (MFA) and toward passkeys as its preferred authentication method. While the change won’t happen overnight, organizations that still rely on text message verification codes should start planning now.

What’s Changing?

Starting September 1, 2026, Microsoft will begin making passkeys the default authentication experience within Entra ID. Users currently using SMS text messages or voice calls for MFA will begin seeing prompts to register a passkey when they sign in. [microsoft.com], [bleepingcomputer.com]

The bigger milestone arrives on February 1, 2027. That’s when Microsoft will retire its own SMS and voice authentication services within Entra ID. Organizations that still need phone-based authentication will have to work with approved third-party telecom providers instead of relying on Microsoft’s built-in service. [microsoft.com], [learn.microsoft.com]

Why Is Microsoft Doing This?

The short answer is security.

For years, SMS-based MFA was considered a major improvement over passwords alone. Unfortunately, attackers have become very good at working around it. SIM-swapping attacks, phishing campaigns, social engineering, and MFA code theft have all become common tactics used to bypass text-message-based security. [microsoft.com], [redmondmag.com]

Microsoft has also pointed to the rise of AI-powered phishing attacks, which are making it easier than ever for cybercriminals to create convincing fake login pages and trick users into handing over credentials and MFA codes. [microsoft.com], [computerworld.com]

Simply put, the threat landscape has evolved, and Microsoft believes it’s time for authentication methods to evolve with it. [microsoft.com], [redmondmag.com]

Who Will Be Impacted?

If your users currently receive a text message or phone call as part of their Microsoft sign-in process, this change affects you. [bleepingcomputer.com], [learn.microsoft.com]

Organizations already using:

  • Passkeys
  • Windows Hello for Business
  • FIDO2 security keys
  • Other phishing-resistant authentication methods

are largely ahead of the curve and won’t experience major disruptions. [bleepingcomputer.com], [learn.microsoft.com]

For everyone else, now is a good time to evaluate how users are authenticating and develop a transition plan.

So, What Exactly Is a Passkey?

Think of a passkey as a replacement for both passwords and text-message verification codes.

Instead of entering a password and waiting for a six-digit code to arrive, users authenticate using something they already have on their device, such as:

The underlying technology makes passkeys much more resistant to phishing attacks because there’s no code for an attacker to steal or intercept. [microsoft.com], [redmondmag.com]

What Are Your Options?

For most organizations, the clear recommendation is to begin adopting passkeys as users are prompted to enroll. Microsoft includes passkey support within Entra ID, and it represents the direction the industry is moving. [microsoft.com], [mc.merill.net]

Organizations can also continue using other phishing-resistant methods such as Windows Hello for Business or FIDO2 security keys. [bleepingcomputer.com], [learn.microsoft.com]

For businesses that have regulatory or operational requirements that still require SMS or voice authentication, Microsoft will allow those services to continue through approved telecom partners. However, there may be additional costs involved, and the organization will be responsible for managing that relationship. [microsoft.com], [mc.merill.net]

What Should Businesses Do Today?

While February 2027 may sound far away, these projects tend to take longer than expected—especially in organizations with a large number of users.

Now is the time to:

  • Identify users who still rely on SMS or voice authentication.
  • Review your current MFA policies.
  • Educate users about passkeys and passwordless authentication.
  • Test passkey deployments with a pilot group.
  • Develop a migration plan before Microsoft’s retirement deadline. [learn.microsoft.com], [bleepingcomputer.com]

Final Thoughts

This isn’t just another Microsoft feature update. It’s part of a broader shift across the technology industry toward phishing-resistant authentication.

Passwords are becoming less reliable. SMS-based MFA is becoming easier for attackers to bypass. Passkeys offer a simpler sign-in experience for users and a stronger security posture for organizations. [microsoft.com], [redmondmag.com]

Organizations that start preparing now will be in a much better position when Microsoft’s SMS and voice authentication retirement arrives in 2027. And as a bonus, they’ll likely end up improving both security and user experience along the way.

If you know that you’re business or organization is going to be impacted or if you think you might be impacted by the SMS retirement by Microsoft, please feel free to reach out to Elite IT Solutions using the form below. We’ll be glad to assist you in navigating your MFA needs.

Contact Us

0 Comments

Presets Color

Primary
Secondary