Microsoft has drawn a line in the sand: after February 1, 2027, it will no longer provide SMS or voice call authentication for multifactor authentication (MFA) in Entra ID public cloud tenants. Users who still rely on those methods won’t be locked out entirely, but they will hit a mandatory passkey registration screen before they can sign in. This isn’t a suggestion—it’s a platform retirement with a fixed date, a narrow temporary opt-out, and real consequences for organizations that drag their feet.
The move is Microsoft’s strongest push yet to rid enterprise authentication of phishable factors that have become easy prey for AI-boosted attacks. While the Redmond giant will still allow organizations to keep telephony through a customer-managed telecom provider, the path of least resistance—and the one Microsoft is actively steering everyone toward—is passkeys.
What’s Actually Changing: Microsoft Kills Its Managed Telecom Layer
The critical nuance here is that Microsoft isn’t banning SMS or voice authentication outright. What’s retiring on February 1, 2027, is the Microsoft-provided delivery of those codes and calls. If your tenant uses the built-in Entra SMS or voice verification, it stops working. But organizations with a valid operational or regulatory need can still arrange SMS-based MFA by contracting a third-party provider through the Microsoft Security Store. That route, however, requires configuration, payment, and ongoing management—it’s not a free continuation of the old service.
For nearly everyone else, the retirement means that users whose only registered MFA method is SMS or voice will face a blocking prompt to set up a passkey the next time they try to sign in. Accounts aren’t deleted, and data isn’t lost, but users cannot proceed without completing passkey registration. That makes it less a lockout and more an enrollment gate—but if a user lacks a compatible device or can’t finish registration, it amounts to the same thing: blocked access.
The retirement also covers self-service password reset flows that rely on SMS or voice, and it extends to B2B guest users, though passkey support for external identities is scheduled to arrive by the end of 2026. In short, any piece of your Entra ID configuration that depends on Microsoft-managed phone-based verification needs to be reworked.
Why Microsoft is Killing SMS MFA—and AI’s Role
SMS one-time codes have long been the weakest link in the MFA chain. They’re vulnerable to SIM swapping, social engineering, and real-time phishing proxies that trick users into handing over codes on fake login pages. An attacker can stand up a convincing clone of a Microsoft sign-in page, relay credentials to the real service, intercept the SMS code, and complete the authentication—all while the user thinks they did nothing wrong.
AI hasn’t invented these attacks, but it has made them cheaper, faster, and more scalable. Phishing kits can now generate tailored emails and pixel-perfect login pages in moments, and the cost of running large-scale SIM-swap campaigns has dropped. Microsoft’s identity security team has warned for years that SMS-based MFA is up to 40% less effective than stronger methods like the Authenticator app, and the gap has only widened as attackers adopt new tools.
Passkeys, by contrast, eliminate the shared secret entirely. They use public-key cryptography where the private key never leaves the user’s device. A fake website can’t request a passkey response for the real Microsoft service because the domain won’t match. This makes passkeys inherently resistant to phishing, credential theft, and man-in-the-middle attacks—exactly the threats that SMS cannot handle.
Timeline: Every Date IT Admins Must Know
Microsoft’s rollout is staged, but the end point is non-negotiable. Here are the milestones to put on your calendar:
- August 1, 2026: API support and guidance for a temporary opt-out become available. This doesn’t cancel the February 2027 retirement; it only lets admins delay the automatic registration campaigns and passkey defaults while they finish their migration. Think of it as a pause button, not an escape hatch.
- September 1, 2026: Users still enabled for SMS or voice are automatically opted into passkey registration. Microsoft moves the registration campaign into a managed state, and users will see prompts to sign up for a passkey during their next MFA challenge. They can postpone the prompt—repeatedly, unless admins intervene—so don’t count on this nudge alone to finish the migration.
- September 18, 2026: Microsoft publishes details about the customer-managed telecom providers available through the Security Store. Organizations that need to keep telephony can start evaluating options.
- October 30, 2026: Configuration of selected telecom providers becomes possible. That gives you just over three months before the hard deadline.
- February 1, 2027: Microsoft-provided SMS and voice are retired. There is no opt-out. Users with only these methods will hit a blocking passkey registration screen.
If your organization hasn’t moved by February 2027, the disruption won’t be theoretical. Help desks could be flooded with calls from employees who can’t sign in, especially those on older devices, shared workstations, or without a modern smartphone.
How to Move Your Organization to Passkeys (Without Disrupting Work)
A successful migration treats authentication as more than a technology swap—it’s a user experience change. Here’s a phased plan that starts now:
1. Find Every User Still on SMS
Run Microsoft’s PowerShell scanner to identify who in your tenant has SMS or voice registered. You’ll need a Global Reader, Authentication Policy Administrator, or Security Reader role. A non-zero result means you’re in scope. Break the list into subgroups: executives, frontline workers, admins, contractors, shared-device users, those in low-connectivity regions. A one-size-fits-all approach will fail.
2. Inventory Devices and Readiness
Passkeys aren’t magical; they need a compatible device and operating system. Windows 11 22H2 provides the best experience, with deep integration into Windows Hello. Windows 10 22H2 supports Windows Hello for Business, but older builds won’t cut it. For Macs, you need macOS 13 Ventura; for iPhones, iOS 17; for Android, version 14. Devices that can’t meet these requirements can still use external FIDO2 security keys, but that requires purchasing and distributing physical hardware. Audit your fleet now.
3. Choose the Right Passkey Flavor
Entra supports two types:
- Synced passkeys stored in platform credential managers (like iCloud Keychain or Google Password Manager). They follow users across devices, making recovery easier. Great for general knowledge workers but may reduce visibility into how many devices hold copies.
- Device-bound passkeys tied to a single device, such as a Windows Hello container, a FIDO2 key, or the Microsoft Authenticator app. Better for admins, privileged roles, and regulated environments.
For most organizations, synced passkeys will cover the bulk of the workforce, while IT staff and executives get device-bound keys. Windows Hello for Business remains a cornerstone for managed Windows devices.
4. Pilot with Power Users and Support Staff First
Start your enrollment campaign with IT admins, help desk teams, and a friendly business unit. They’ll find the rough edges and become your frontline support. Create clear, non-generic communication: tell users why SMS is going away, show them step-by-step instructions for their specific device, and give them a way to get help if enrollment fails.
5. Test Recovery Before It’s an Emergency
A passkey is only as good as the path back in when a device is lost. Document and test recovery scenarios: lost phone, new laptop, damaged security key, employee traveling without their primary device. Use temporary access passes (TAPs), backup authentication methods, or managed device enrollment. If your help desk can be socially engineered into resetting a credential, attackers will target them instead of the user.
6. Decide on Telecom—But Don’t Default to It
The customer-managed provider option exists for a reason: some organizations face regulatory requirements, lack of device coverage, or operational constraints that make telephony unavoidable. But before you go that route, ask hard questions: Who exactly needs it? For how long? Who pays the per-message fees? Who manages the provider relationship? Treat SMS as a narrow exception, not a fallback plan.
What If You Still Need SMS? The Customer-Managed Telecom Option
If telephony is non-negotiable, you’ll need to act before February 2027. Starting October 30, 2026, you can select a telecom provider through the Microsoft Security Store, configure it for your tenant, and pay for messages. This is not a trivial add-on: you must review regional coverage, data-handling requirements, compliance obligations, and support responsibilities. Three months may feel like plenty of time, but procurement cycles and legal reviews can burn through it quickly. Engage your sourcing team early.
The Bottom Line: Start Now or Face Access Blocks
February 1, 2027, is coming, and it won’t bend. Microsoft is unambiguous about that. The temporary opt-out only buys you a few extra months to finish the migration; it doesn’t change the destination. Organizations that begin inventorying users, testing passkey scenarios, and communicating changes now will treat the date as a completed milestone. Those that wait will find themselves trying to modernize identity security while employees are locked out and the phones are ringing off the hook. The choice is yours, but the clock is ticking.