Content Summary
- Microsoft Entra ID will make passkeys the default authentication method starting September 1, 2026.
- Microsoft-provided SMS and voice MFA will be fully retired by February 1, 2027.
- Organizations that still need SMS/voice for compliance must configure a third-party telecom provider through the Microsoft Security Store starting October 30, 2026.
- SIM-swap fraud has surged roughly 1,055%, and AI-generated phishing messages now achieve click-through rates as high as 54% (vs. ~12% for traditional phishing), per Microsoft Threat Intelligence.
- Phishing-resistant MFA blocks over 99% of identity-based attacks, according to Microsoft’s Digital Defense Report 2025.
- Businesses should inventory current authentication methods now, define approved alternatives (passkeys, security keys, Windows Hello, hardware tokens), and test before enforcing company-wide.
Quick answer: Microsoft will make passkeys the default sign-in method in Microsoft Entra ID starting September 1, 2026, and will fully retire Microsoft-provided SMS and voice authentication by February 1, 2027. Businesses still relying on SMS-based MFA need to inventory current authentication methods, choose phishing-resistant alternatives (passkeys, security keys, Windows Hello), and test the transition before Microsoft’s rollout reaches their tenant.
Security changes often sound simple. Stop using one authentication method. Start using another. Then the change meets real people.
One employee does not own a smartphone. Another does not want to install a company-related app on a personal device. Someone else is comfortable receiving a text message but does not want to learn a new system.
Microsoft Entra ID: SMS & Voice MFA Retirement Timeline
Microsoft has confirmed the official timeline. Starting September 1, 2026, passkeys become the default sign-in method in Microsoft Entra ID, and users still on SMS or voice authentication will be automatically nudged to register one. Native SMS and voice MFA from Microsoft will be fully retired by February 1, 2027. This follows an earlier move to phase out SMS codes for personal Microsoft account sign-in and recovery, which began in May 2026.
Passkeys become the default; auto-enrollment begins.
September 1, 2026
Telecom provider pricing & terms published
September 18, 2026
Organizations must configure 3rd-party telecom for SMS/voice
October 30, 2026
Microsoft-provided SMS & voice MFA fully retired
February 1, 2027
Timeline showing key milestones from September 2026 auto-enrollment to February 2027 complete retirement.
Businesses should prepare now, but they should do so in a way that accounts for the people who must actually use the technology.
Why Is Microsoft Moving Away from SMS?
SMS authentication is familiar and easy to understand. A user enters a password, a code arrives by text message, and the user types in the code. The problem is that text-message codes can be intercepted or stolen.
Attackers may use SIM-swapping, phone-number porting, phishing websites, or social engineering to gain access to a user’s messages, or trick someone into entering a password and texted code into a fake login page. The numbers show why Microsoft is done treating this as an acceptable long-term control. AI has made the gap worse: Microsoft Threat Intelligence reports that AI-generated phishing messages now achieve click-through rates as high as 54%, compared to roughly 12% for traditional phishing attempts.
SIM-swap fraud has surged an estimated 1,055% in recent years, directly undermining SMS as a trustworthy second factor.
Verizon's 2026 Data Breach Investigations Report found mobile-centric phishing (text & voice) produces click-through rates 40% higher than email-based phishing.
MFA passkeys, FIDO2 keys, & similar methods, block more than 99% of identity-based attacks, even when an attacker has a valid username & password.
SIM-swap fraud, mobile phishing click rates, and the effectiveness of phishing-resistant MFA, by the numbers.
- 1,055% Surge in SIM-Swap Fraud: Directly undermines text messages as a trustworthy second factor.
- 40% Higher Click Rate: Verizon’s Data Breach Investigations Report found mobile phishing (SMS & voice) gets far higher engagement than email phishing.
- 99%+ Attacks Blocked: Phishing-resistant MFA (passkeys, FIDO2 keys) blocks over 99% of identity-based attacks even if passwords are stolen.
SMS is usually better than protecting an account with only a password. It is simply not as secure as newer methods such as passkeys, security keys, Windows Hello, or properly configured authenticator apps. The practical message for businesses is not that SMS will disappear tomorrow. The message is: Do not build your long-term security strategy around it.
Not sure which of your users are still relying on SMS or voice MFA? Request a free consultation from our team to ensure you have a transition plan before Microsoft’s rollout.
How Should Businesses Prepare for the Passkey Transition?
The first step is not sending everyone an email telling them to install an app. It’s understanding how employees currently authenticate and identifying anyone who will need an alternative.
- Inventory Current Authentication Methods: Determine which employees are using SMS, phone calls, authenticator apps, hardware tokens, security keys, Windows Hello, or other methods. Pay particular attention to administrators, executives, accounting personnel, remote employees, and anyone with access to sensitive information.
- Identify Employees Who Need Another Option: Who does not have a smartphone? Who uses a personal phone for company authentication? Who does not want to install a work-related app? Who works in an area with poor cellular service? Who uses a shared or specialized computer? The goal is not to argue about phone preferences — it’s to assign each person a secure and supportable authentication method.
- Establish Preferred Methods and Exceptions: A business may decide that phishing-resistant authentication is the preferred standard — authenticator apps or Windows Hello for general users, physical security keys for admins and high-risk roles, and hardware tokens for anyone without a smartphone. SMS can remain available for a limited group, but as an exception, not the default.
- Plan for Lost Devices and Lockouts: Phones break, keys disappear, employees replace computers, and people forget PINs. Before changing authentication methods, decide who can reset authentication methods, how the help desk will verify a user’s identity, whether backup keys or tokens will be issued, whether a temporary access code can be used during setup or recovery, and whether authentication changes are logged and reviewed. A strong authentication policy needs a strong recovery process.
- Test Before Enforcing: Start with a small group. Test normal sign-in, new-device setup, lost-device recovery, remote access, mobile apps, and third-party systems before enforcing the change across the company. A method that works well in the office may create problems for someone working remotely, traveling, or using specialized equipment.
Phishing
Phishing
AI-generated phishing attacks achieve nearly 4.5x higher click-through rates than traditional phishing emails.
An Authenticator App Cannot Be the Only Answer
Microsoft Authenticator is a good option for many users. It is more secure than SMS, particularly when number matching and other safeguards are enabled. But requiring every employee to install an app on a personal phone creates legitimate concerns: some employees do not own a compatible smartphone, and others do not want company access tied to personally owned equipment. A business can strengthen security without making personal phones mandatory by offering a defined list of approved options:
- Company-Owned Devices: For employees with company-issued smartphones or tablets, Microsoft Authenticator is often the easiest choice — the business owns and manages the device, and if the employee leaves or the device is lost, the company can manage the transition through its normal onboarding and offboarding process.
- FIDO2 Security Keys & Hardware Tokens: A FIDO2 security key (plugged in or tapped via NFC) is highly phishing-resistant because the credential can’t be copied from a text message into a fake site. A code-generating hardware token is a lower-friction, if slightly less secure, alternative that needs no smartphone, cellular service, or app — perfect for staff without smartphones.
- Windows Hello & Temporary Access Passes: Windows Hello for Business lets employees sign in with a PIN, fingerprint, or facial recognition tied to a managed device. Microsoft’s Temporary Access Passes give administrators a short-lived code to help someone register a new method or recover after losing a phone, key, or token.
- Cisco Duo Integration: Some businesses may benefit from a third-party platform like Cisco Duo, which supports Duo Push, passkeys, security keys, hardware tokens, and SMS passcodes. Duo does not make SMS immune to phishing or SIM-swapping — SMS should still be treated as a fallback or transitional method, not a long-term one.
How Complete IT Helps You Navigate the Passkey Shift
As an Austin-based managed IT services provider, Complete IT helps organizations build passkey transition plans tailored to their employees, not just Microsoft’s timeline. We assist with tenant audits, hardware key deployment, and help-desk workflows so your business stays secure without operational disruption.
Stronger Security Still Has to Work for People
The move away from SMS is part of a broader shift toward passwordless and phishing-resistant authentication. While good for security, it does not mean every employee must use the same method. Some users will be comfortable with an authenticator app. Others may be better served by Windows Hello, a physical security key, or a hardware token. A small number may temporarily continue using SMS through Microsoft or a third-party service while the business develops a better long-term option.
The strongest authentication method is not helpful if employees cannot use it, the help desk cannot support it, or the company has no recovery plan.
Microsoft’s announcement is not a reason to panic. It is a good reason to take inventory, identify exceptions, test alternatives, and create a practical plan before the next authentication change arrives.
A Few Takeaways to Keep in Mind
Passkeys become default in Entra ID on September 1, 2026. Native SMS and voice MFA from Microsoft retire completely on February 1, 2027. Phishing-resistant MFA stops over 99% of identity attacks. Providing alternative hardware tokens avoids friction over personal smartphone use. Complete IT can map out your passkey migration before enforcement deadlines hit.
FAQ
When does Microsoft retire SMS authentication?
Microsoft-provided SMS and voice authentication in Entra ID will be fully retired on February 1, 2027. Passkeys become the default sign-in method starting September 1, 2026, with automatic nudges for current SMS/voice users.
Can my business still use SMS authentication after 2027?
Only through a third-party telecom provider configured via the Microsoft Security Store, available starting October 30, 2026. Microsoft will no longer provide SMS or voice authentication natively.
Is SMS two-factor authentication still secure?
SMS is better than a password alone, but it is vulnerable to SIM-swapping, phishing, and social engineering. Security agencies including CISA and NIST classify SMS-based one-time codes as a restricted authenticator and recommend phishing-resistant alternatives such as passkeys or FIDO2 security keys.
What should replace SMS authentication for employees without smartphones?
A physical FIDO2 security key or a code-generating hardware token. Both work without a smartphone, app installation, or cellular signal, and a security key offers stronger phishing resistance.
What is a passkey?
A passkey is a phishing-resistant sign-in credential, often tied to a device or biometric (fingerprint, face, or PIN), that replaces passwords and one-time codes. Passkeys cannot be phished the way a texted code can, because there is no code for an attacker to intercept or relay.