On July 30, 2026, Microsoft’s monthly security roundup dropped a deadline that every Entra ID administrator needs to circle: February 1, 2027. That’s the day Microsoft-provided SMS and voice call multifactor authentication stops working for tenants that haven’t arranged a customer-managed telecom provider. The default authentication experience is already shifting to passkeys, and affected users will be automatically opted into passkeys on September 1, 2026—whether you’re ready or not.
This move is just one piece of a sweeping set of updates that Microsoft is framing as security for the AI era. Alongside the MFA shake-up, the company announced new AI prompt-injection protection in Defender, tighter controls for Copilot grounding data in Purview, network-layer blocking of shadow AI uploads, expanded cloud container security, and the redistribution of Intune Suite features into standard E3 and E5 licenses. The common thread: Microsoft wants to close the gap between the speed of AI adoption and the security tooling that protects it.
What Microsoft Actually Announced
Passkeys become the default, SMS and voice MFA get a retirement date
Two dates matter above all. On September 1, 2026, any user whose only usable MFA method is SMS or voice will be automatically enabled for passkeys. Then, on February 1, 2027, tenants that rely on Microsoft’s telecom infrastructure for SMS or voice delivery will lose that method entirely. An opt-out will be available during the transition period, but it won’t apply to the February 2027 cut-off. Organizations that require SMS or voice—for regulatory reasons, for example—will need to bring their own telecom provider.
AI prompt-injection protection hits preview
Microsoft Defender for Office 365 is getting a new preview capability: it can now detect and quarantine emails carrying malicious instructions aimed not at the human reader but at an AI assistant. Microsoft says it identifies these prompt-injection attacks before delivery, safeguarding Copilot and other AI tools from being tricked into leaking data or performing unwanted actions.
Unified posture and runtime protection for cloud agents
Defender is also consolidating security posture assessment and runtime protection for custom agents built in Microsoft Foundry and Copilot Studio, as well as third-party agents managed through Microsoft Agent 365. The goal is a single place to see configuration risks and suspicious runtime behavior, instead of siloed controls for each AI platform.
Broadened cloud container security
Microsoft Defender for Cloud is extending Cloud Security Posture Management to serverless containers on Azure Container Apps, Azure Container Instances, and Amazon ECS on Fargate. For shops that manage multi-cloud Windows and Linux environments, this means visibility into container-hosted workloads that might otherwise fly under the radar.
Tighter coupling between Defender and Entra
Security operations center (SOC) analysts will now be able to disable compromised identities directly from the Defender workflow, using role-based access control that maintains least privilege. It’s a significant reduction in handoff friction between detection and containment.
Purview adds DLP for Copilot grounding and shadow AI blocking
A new Data Loss Prevention policy for Microsoft 365 Copilot, now in preview, lets administrators exclude externally sent email from being used as grounding data for Copilot responses. Separately, Purview integration with Microsoft Entra Internet Access can detect and block sensitive text and file uploads to unmanaged SaaS and AI applications at the network layer—preventing data from leaking to shadow AI tools before it leaves the environment.
Insider Risk Management alert experience revamped
A redesigned alert interface combines classic alerts with findings from the Data Security Triage Agent, whose advanced reasoning layer is now generally available. The agent performs multi-step analysis across user, device, and data signals to surface the most critical cases, cutting through noise.
Intune Suite capabilities land in E3 and E5
As of July 1, 2026, Microsoft folded many Intune Suite features into Microsoft 365 plans. E3 now includes Intune Plan 2, Remote Help, and Advanced Analytics; E5 and higher add Endpoint Privilege Management, Microsoft Cloud PKI, and Enterprise Application Management. This ends the separate-suite-add-on era for many organizations.
What It Means for You—and Your Organization
For IT administrators and identity teams
The SMS and voice MFA retirement is the most pressing item. You need to know exactly which users have SMS or voice as their only registered MFA method, because on September 1, 2026, they’ll be automatically switched to passkeys. If those users aren’t ready, they could be locked out. On February 1, 2027, Microsoft stops delivering SMS or voice entirely unless you bring your own telecom provider. Decide now whether that’s necessary.
For security analysts and SecOps teams
You get a raft of new tools. Prompt-injection protection in Defender can stop a fast-growing attack vector before it reaches a user’s AI assistant. The unified agent posture and runtime dashboard gives you cross-platform visibility into AI workloads. And the ability to disable identities from within Defender means one less pivot during an incident.
For data security and compliance teams
The Purview DLP exception for Copilot grounding is a narrow but critical control: it prevents confidential external emails from being summarized or referenced by Copilot. Combined with the Entra Internet Access integration, you can now block employees from pasting sensitive data into unauthorized AI services—a growing risk as generative AI tools multiply.
For endpoint management and IT operations
Check your Microsoft 365 licensing immediately. If you’re on E3, you already have Remote Help, Advanced Analytics, and Intune Plan 2 without extra cost. E5 users get the full suite. This changes the calculus for projects that previously stalled because of Intune Suite add-on pricing—removing standing local-admin rights and modernizing certificate management are suddenly within easier reach.
For everyday employees and Windows users
You may not see all these changes directly, but you will notice the MFA shift. Sometime between now and September 2026, if you only use SMS for two-factor authentication, you’ll be prompted to set up a passkey. It’s a good idea to do so proactively. Passkeys are more secure and, once configured, faster than waiting for a text message.
How We Got Here: The Long Goodbye to SMS MFA
SMS and voice-based MFA have been on borrowed time for years. The National Institute of Standards and Technology deprecated SMS as a second factor back in 2016, citing SIM-swapping and interception risks. Microsoft began nudging organizations toward passwordless and phishing-resistant methods with Windows Hello for Business and FIDO2 keys. Then came Authenticator-based approvals, and eventually passkeys—standards-based credentials that sync across devices and resist phishing.
Microsoft’s Entra documentation shows the timeline wasn’t sudden. The company initially announced plans to retire Microsoft-provided telecom delivery for MFA in 2025, setting the stage for the two-phase transition: auto-enablement for passive users in September 2026, followed by hard enforcement in February 2027. The licensing shift for Intune Suite also follows a pattern of bundling advanced security into higher-tier subscriptions, a trend that accelerated when Microsoft made Copilot available in more plans.
Your To-Do List: Actions to Take Now
Immediate steps—this quarter
- Audit MFA methods. In the Entra admin center, run a report on registered authentication methods to identify users who rely solely on SMS or voice. Start the passkey registration campaign now.
- Evaluate telecom requirements. If your organization must retain SMS or voice due to regulations or user needs, begin procuring a customer-managed telecom provider. Microsoft’s cutoff doesn’t prohibit those methods; it only ends the built-in delivery.
- Review new licensing benefits. Log into the Microsoft 365 admin console and explore which Intune Suite features are already available in your plans. Standing local-admin removal and Cloud PKI are two quick wins to pilot.
Next six months
- Enable prompt-injection protection preview. Navigate to Defender for Office 365 policies and turn on the preview. Monitor the quarantine for false positives.
- Configure DLP for Copilot. If you use Microsoft 365 Copilot, apply the new DLP policy to exclude emails from external senders from grounding data.
- Activate shadow AI blocking. Integrate Purview with Entra Internet Access and set policies to block sensitive data uploads to unmanaged AI apps.
By September 1, 2026
- Notify users about automatic passkey enablement. Send clear instructions on how passkeys work and encourage early adoption. Provide help desk training.
- Test passkey recovery workflows. Ensure users know how to regain access if they lose their device.
By February 1, 2027
- Confirm all users have a viable, non-SMS/voice MFA method registered. Disable or migrate any remaining telecom-dependent workflows.
- Remove the opt-out, if used. Once the hard deadline passes, the opt-out is no longer honored.
What Comes Next
Microsoft’s July 2026 updates are a down payment on a broader vision. Project Perception, the newly announced system of coordinated red, blue, and green AI agents, hints at a future where autonomous workflows handle much of the security cycle. But for now, the concrete deliverables are the ones that demand administrative attention: passkey defaults, AI prompt-injection defenses, and data controls for Copilot. Expect continued convergence between Entra and Defender, more agentic features in Purview, and the gradual retirement of less secure legacy methods. The message is clear: AI is reshaping the threat landscape, and Microsoft is reshaping the defense in response—sometimes with firm deadlines.