Microsoft has set a firm date: February 1, 2027. That’s when the Microsoft-provided SMS and voice call authentication you might use to sign into work or school accounts will stop working. For the millions of users who still get a text message with a code as their second factor, the clock is ticking. And while the deadline might feel far off, the practical steps start much sooner—because on September 1, 2026, Microsoft will begin automatically nudging those users toward passkeys.
This isn’t a gentle suggestion. It’s a mandatory shift to phishing-resistant authentication, part of a sweeping move to kill off the weakest link in the identity chain. The good news? Migrating to passkeys is free, more secure, and often faster than waiting for a text message. The catch? If you or your organization don’t prepare, users could get locked out come February 2027.
Here’s exactly what’s changing, who’s affected, and how to get ahead of the transition.
The Key Dates in Microsoft’s SMS and Voice Retirement
Microsoft’s timeline is spelled out in an advisory on its Entra ID documentation site. Two dates matter most:
September 1, 2026 – For tenants where any users are still enabled for SMS or voice MFA in the Authentication Methods Policy, Microsoft will automatically enable passkeys for those users. The registration campaign will switch to Microsoft-managed, meaning after users complete an MFA sign-in, they’ll see a prompt to set up a passkey. They can snooze it—unlimited times, by default—so the immediate disruption is low. But this is the starting gun.
February 1, 2027 – Microsoft-provided SMS and voice delivery is retired, period. There’s no opt-out. If a user’s only available MFA method is SMS or voice and no customer-managed telecom provider is configured, they’ll be blocked at sign-in and forced to register a passkey before they can proceed. For organizations, this is a hard compliance deadline.
There’s also a temporary reprieve: between August 1, 2026, and February 1, 2027, admins can opt out of the automatic passkey enablement and registration campaign changes. This buys time for testing, but it doesn’t extend the SMS and voice service. The retirement date is non-negotiable.
Who’s Affected—and What Changes on Your Screen
The short answer: any user in a public-cloud Microsoft Entra ID (formerly Azure AD) tenant who uses SMS or voice for multi-factor authentication. That includes employees at companies of all sizes, students at universities, and potentially guest users. Microsoft notes that passkey support for B2B and internal guest users is planned by the end of 2026, so they’re in scope too.
What will actually happen to you? If you’re a typical user who gets a text code when logging into Office 365 or a corporate app, here’s how your experience could change:
- Starting September 1, 2026: After you sign in with your password and enter an SMS code one day, you’ll see a new prompt: “Set up a passkey for a faster, more secure sign-in.” You can tap “Skip” or “Snooze,” and it’ll go away until next time. But every MFA event becomes an opportunity for the reminder to reappear.
- Before February 1, 2027: If you haven’t registered a passkey or moved to another phishing-resistant method (like Windows Hello for Business or a FIDO2 hardware key), when you attempt to sign in after the deadline, you’ll hit a roadblock. The prompt won’t have a snooze button. You must complete passkey setup to continue.
- After you register a passkey: You’ll sign in with your face, fingerprint, PIN, or device security key—no more typing codes. It’s both faster and immune to SIM-swap and phishing attacks that plague SMS.
For administrators, the change is more profound. The automatic shift means that on September 1, 2026, any user still enabled for SMS or voice in the policy will suddenly be in scope for passkeys. If you haven’t prepared your environment—testing passkeys on your managed Windows devices, deciding between device-bound and synced passkeys, training your help desk—you could face confusion and support tickets. Worse, if you rely on SMS and voice for critical workflows like self-service password reset (SSPR) or emergency access, you’ll need a plan.
Why SMS Had to Go
SMS-based authentication has been on life support for years. It’s vulnerable to SIM-swapping attacks, where a criminal transfers your phone number to their device and intercepts your codes. It’s phishable: a fake login page can trick you into entering a one-time code, which an attacker instantly replays. Modern threats don’t care about your strong password if they can grab a six-digit number from your carrier.
Microsoft has been pushing passwordless and phishing-resistant methods for a while. Windows Hello, FIDO2 security keys, and platform passkeys (synced across devices via iCloud Keychain or Google Password Manager) use public-key cryptography. The private key never leaves your device, making remote interception impossible. The FIDO Alliance standards behind passkeys are now supported across Windows, macOS, iOS, and Android, so cross-platform use is no longer a barrier.
The retirement also reflects a broader industry trend. NIST guidelines have long advised against using SMS for MFA when stronger options exist. Google began pushing passkeys as the default for personal accounts in 2023. Microsoft sees the Entra change as part of making “passkeys the default authentication experience” for enterprise users, aligning security with how people actually use devices—biometrics and PINs are second nature on modern hardware.
Your Action Plan: 5 Steps to a Painless Migration
Whether you’re an IT admin responsible for thousands of users or a power user managing a few accounts, these steps will keep you ahead of the deadline.
1. Find Out Who’s Still Using SMS or Voice
Admins: Run the PowerShell script Microsoft provides (available in the retirement documentation) to export a list of users enabled for SMS or voice. But a word of caution: being enabled doesn’t mean the user actually relies on that method. Cross-reference with sign-in logs to see who actively uses it. Create a clear inventory: users who are ready to switch, those who need help, and those who require a phone-based fallback for valid business reasons.
End users: Check your own security info. In the My Security Info page (aka.ms/mfasetup), see which methods you have. If SMS is your only or primary MFA, you’ll need to add something else.
2. Pick and Enable the Right Passkey Type
Microsoft Entra supports two categories:
- Synced passkeys – Store the credential in a platform manager (Apple’s, Google’s, or Microsoft’s own credential manager) and sync across devices. Ideal for users who move between phone, tablet, and PC.
- Device-bound passkeys – Tied to a specific device, like a passkey in Microsoft Authenticator, a Windows Hello for Business PIN/fingerprint, or a physical FIDO2 key. Best for high-security roles or shared devices where syncing isn’t allowed.
Admins: Enable “Passkey (FIDO2)” in the Entra Authentication Methods Policy for the relevant groups. If you use Windows Hello for Business, tie it to the policy so users can sign in with their face or PIN without a separate registration. Test every scenario: first-time sign-in, new device setup, browser switch, and recovery from a lost device.
3. Run a Registration Campaign Before September 2026
Don’t wait for Microsoft to nudge users. Proactively set up a registration campaign now. In the Entra admin center, go to Authentication Methods > Registration campaign, set state to Microsoft Managed (or custom if you prefer), and target the group of SMS/voice users. When users log in next and complete MFA, they’ll see a prompt to set up a passkey. You can configure the snooze limit—Microsoft’s default is unlimited, but you might want to limit snoozes to 3-5 before it becomes persistent. This drives adoption gradually without overwhelming the help desk.
Pair this with user communication. Microsoft provides templates, but tailor them: explain why the change is happening (“your text codes are easy for hackers to steal”), what they’ll use instead (“your face or fingerprint on your phone or laptop”), and where to get help. Send reminders at least 60, 30, and 7 days before the September 2026 auto-enable date.
4. Treat Exceptions as a Separate Project
Some users genuinely can’t switch to passkeys. Maybe they work frontline shift jobs on shared devices without biometrics. Maybe regulatory rules require an out-of-band SMS channel for certain transactions. For these cases, Microsoft offers a path: customer-managed telecom providers available through the Microsoft Security Store, starting with evaluation on September 18, 2026, and configuration from October 30, 2026.
But don’t make everyone an exception. Identify only the small set of users with documented business or regulatory needs. You’ll pay per-message rates (pricing varies by provider and region), and you’ll manage the contract yourself. Start vetting providers early so you’re not scrambling in late 2026.
Also review your Conditional Access policies, SSPR recovery flows, and emergency access accounts. Make sure none of them rely solely on Microsoft-provided SMS or voice to work. If emergency accounts use SMS as a backup, update them to use a hardware key or offline recovery codes instead.
5. Measure Success, Not Just Registration Counts
A passkey “registered” doesn’t mean a passkey used. Track how many users actually sign in with a phishing-resistant method post-campaign. Monitor failed sign-in attempts due to lack of registered methods. Check help desk ticket volumes related to MFA changes. If you see high snooze rates for the registration prompt, follow up with those users directly—they might be stuck on a device that doesn’t support passkeys, or they might not understand the importance.
Set a target: by December 2026, have over 95% of your active users registered and using a passkey or other phishing-resistant method, with a clear exception list for the rest.
Outlook: What Comes Next
After February 1, 2027, SMS and voice won’t vanish entirely—they’ll just become a premium, customer-managed feature. Microsoft is pushing the industry toward a passwordless future where biometrics and device-bound keys are the norm. The plan already covers public cloud; other environments (government clouds, sovereign clouds) will get their own timeline later.
For users, the shift means fewer codes to type and stronger protection against account takeovers. For admins, it’s a forced modernization that, if executed well, reduces long-term support costs and security incidents. The next 18 months are a window to get it right. Start now, and the 2027 deadline won’t be a crisis—it’ll be the day you finally left phishable MFA behind.