
One of the earliest forms of MFA was getting text messages (SMS) or automated phone calls to verify identity. While SMS-based MFA is better than no MFA, it’s still not nearly as secure as other MFA methods. SMS messages are much easier than other methods to intercept to spoof. And because they are well-established and aren’t really adaptable technologies, there’s not a whole lot than can be done to harden SMS MFA.
Microsoft is eventually going to be completely turning off SMS and Phone MFA options in the future (they’ve already made it a non-preferred method in Office 365 and Azure). Since we want to make sure our clients are as secure as possible, we are going to be working with our clients over the next several months to migrate away from SMS-based MFA to using app-based authentication (using the Microsoft Authenticator app) or hardware-based MFA (using something like a Yubikey of some sort). Many folks are already using the Microsoft Authenticator app, but this audit will make sure that we get SMS disabled and secure things up the best we can. You will be hearing from your lead technician and account manager as we work out way through that roll out.