Microsoft is ending support SMS and voice multi-factor authentication (MFA) inside of Microsoft 365 and Entra ID. We mentioned it a couple of years back, but it’s now official and we have a timeline. Here’s what you need to know.
First off, why is Microsoft moving away from SMS MFA? While enabling SMS or voice-based MFA is far better than relying solely on a password, treating phone numbers as a secure verification channel has become a major liability. Telecom protocols were designed decades ago for connectivity rather than security, leaving text messages and phone calls exposed to structural exploits. Through SIM swapping, attackers manipulate customer support representatives at mobile carriers to port a victim’s phone number onto a rogue SIM card, rerouting every incoming code directly to the hacker’s device. This allows the bad folks to intercept or bypass SMS verification with significantly less work than in the past.
Microsoft has announcement its timeline to give decision makers time to plan and update policies around other authentication methods. Here are the critical dates, from Microsoft:
- September 1, 2026: Tenants with users enabled for SMS or voice, those users are auto-enabled and nudged for Passkey registration upon MFA sign-in.
- February 1, 2027: Microsoft-provided SMS and voice authentication is retired for all users except Global Administrators and external users.
- After February 1, 2027: Users in scope for the February 1 retirement whose only available MFA method is SMS or voice are required to register a passkey during sign-in to continue accessing their account. This prompt is blocking. Users must register a passkey before they can continue to sign in to their account. There is no opt out from this February 1 behavior for users in scope of the February 1 retirement.
- July 1, 2027: Microsoft-provided SMS and voice authentication is retired for Global Administrators and external users. After this point, everybody needs to have a passkey or some other form of MFA.
If you’re in charge of an Entra environment and want to see users who are enabled for SMS or Voice MFA, you can follow Microsoft’s directions here and there are PowerShell scripts to help automate this process as well.
Taking care of all this ahead of time keeps things moving along and helps to keep things secure. And Velonex can help with our free Microsoft 365 Security assessment. Contact us today for more details.