Microsoft 365 Security

Microsoft Is Retiring SMS and Voice MFA: Is Your Business Ready?

What the February 2027 deadline means for every Microsoft 365 business

11 min read — Altitude Microsoft 365 Team

Microsoft has confirmed that its own SMS and voice authentication service in Microsoft Entra ID will retire on 1 February 2027.

From 1 September 2026, affected users will begin being moved towards passkeys and prompted to register.

For businesses still relying on text-message codes, this is no longer a future security recommendation. It is a migration deadline.

The immediate risk is not only weaker security. It is users discovering during sign-in that their normal authentication method is no longer available.

If your organisation is already planning the move, Altitude's Microsoft 365 Authentication Review and Passkey Migration service covers how we manage the whole project.

What Microsoft Has Announced

Microsoft is retiring the SMS and voice authentication it provides directly through Microsoft Entra ID. This is the service that sends a six-digit text message to a user's mobile number or places an automated voice call. It is one of the most commonly used MFA methods in small and medium-sized organisations.

Microsoft's announcement distinguishes between its own telecom service and customer-managed telecom providers. Organisations with a genuine operational requirement may be able to use a customer-managed provider through the Microsoft Security Store. This is not a general opt-out — it is a route for specific assessed exceptions.

The September 2026 Change

From 1 September 2026, users who are enabled for SMS or voice authentication will be automatically enabled for passkeys in the Authentication Methods Policy. Those users will begin receiving prompts to register a passkey when they complete MFA.

This means the transition starts before the retirement date. Businesses that do not plan their own migration will have Microsoft begin managing the user experience for them.

The February 2027 Retirement

From 1 February 2027, Microsoft-provided SMS and voice authentication will no longer function in Microsoft Entra ID. Users whose only available MFA method is SMS or voice may face a blocking prompt requiring passkey registration before they can continue signing in.

Microsoft states there is no general opt-out from the February 2027 enforcement. Planning must happen before the deadline, not because of it.

Who Is Affected

Any Microsoft 365 user who relies on a text-message code or voice call for MFA is affected. But the scope is usually wider than businesses expect:

  • Users who registered SMS years ago and have never been prompted to change
  • Administrators who use SMS for convenience rather than a stronger method
  • Users whose mobile number has since changed but whose Entra registration has not
  • Former employees whose numbers are now in use by someone else
  • Contractors, guests and shared accounts with phone-based authentication
  • Self-Service Password Reset configured to use phone methods
  • Conditional Access policies with exclusions for phone-based MFA
  • Emergency accounts that depend on the retiring method

The difference between which methods are enabled, which users have registered, and which users are actively using SMS is significant. Altitude reviews all three — they are not the same list.

Why Microsoft Is Moving Away from SMS

SMS one-time codes are vulnerable to interception, SIM swapping and phishing. A user who receives a text-message code and enters it into a convincing fake sign-in page has just handed their MFA code to an attacker. Passkeys are designed to prevent this: the credential is cryptographically bound to the legitimate website, so it cannot be entered somewhere else.

Microsoft's position is that SMS and voice represent a category of authentication that is technically weaker than the phishing-resistant methods now available. This is consistent with guidance from NCSC and other security organisations that have described SMS-based MFA as better than nothing but weaker than modern alternatives.

What Passkeys Are

A passkey is a phishing-resistant credential that replaces a password or one-time code. Instead of typing a text-message code, a user authenticates using a biometric (fingerprint or face recognition) or a device PIN. The passkey is tied to a specific service and cannot be intercepted or entered into a fake site.

Passkeys come in two forms. Synced passkeys are stored in a platform credential provider — such as Windows, Apple Keychain or a password manager — and can be synchronised across a user's devices. Device-bound passkeys remain on a single device and do not synchronise, which can suit managed or higher-security scenarios.

Passkeys, Windows Hello and Security Keys

Passkeys in Microsoft Entra ID can be registered through several methods. Microsoft Authenticator supports passkeys on compatible iOS and Android devices. Windows Hello for Business uses a device-bound passkey backed by biometrics or a PIN on a managed Windows device. FIDO2 physical security keys are a passkey-compatible hardware token.

Not every user needs the same method:

  • Synced passkeys may suit users with supported devices and credential providers across phone, laptop and tablet.
  • Windows Hello for Business may suit managed Windows environments where biometric or PIN authentication is already configured.
  • FIDO2 security keys may suit administrators, shared-device users, users without smartphones and accessibility requirements — the key works on any compatible device without needing a personal phone.
  • Microsoft Authenticator may support passkeys or app-based MFA depending on the current configuration and platform.
  • Temporary Access Pass is not a permanent MFA method but a time-limited administrator-issued passcode that can be used to bootstrap passkey registration — useful for new starters, device replacements and recovery.

The right combination depends on the user population, device management approach, applications and accessibility requirements — not a single universal recommendation.

What Happens to Self-Service Password Reset

If Self-Service Password Reset is configured to use phone-based methods, those methods will be affected by the retirement. This is commonly overlooked. A business may successfully move all its users to passkeys for sign-in, but leave SSPR still pointing at SMS — meaning password resets break after February 2027.

SSPR must be reviewed as part of the authentication migration. Combined registration — where MFA and SSPR registration happen together — should be configured where appropriate.

Administrators and Emergency Accounts

Administrator accounts require the most urgent attention. Global Administrators and privileged role holders are high-value targets, and any administrator still using SMS authentication after the deadline may find themselves unable to access the tenant at a critical moment.

Emergency-access accounts — sometimes called break-glass accounts — must be specifically reviewed. These accounts are designed to be available when normal administrator accounts cannot be used. If an emergency account depends on an SMS code sent to a mobile number that is no longer active, it is not an emergency account at all.

Altitude migrates administrators before general users. The accounts needed to recover Microsoft 365 must not depend on Microsoft's retiring telecom service.

Users Without Suitable Smartphones

Not every employee has a compatible smartphone, is willing to use a personal device for work authentication, or is able to use a phone-based method due to accessibility requirements. These are real situations that require individual decisions — not a blanket assumption that every user will install Microsoft Authenticator.

FIDO2 security keys, Windows Hello for Business and Temporary Access Pass can support users in these situations, but only when the devices, licensing and support processes are in place to use them.

Accessibility and Shared Devices

Passkey registration assumes the user has a personal device to authenticate with. Frontline workers using shared computers, users with motor or cognitive accessibility requirements, and staff whose role does not include a dedicated device all need individual planning.

Shared-device users may not be able to use Windows Hello or a synced passkey. Physical FIDO2 security keys can work in these scenarios — but their distribution, loss and replacement procedures need to be designed before the rollout, not discovered during it.

Why Waiting Creates Business Risk

From September 2026, Microsoft will begin showing passkey registration prompts to SMS-dependent users without the business having planned the experience. Users will encounter these prompts without context, without instructions and without a helpdesk process to support them.

From February 2027, users whose only MFA method is SMS or voice may face blocking prompts that prevent sign-in until a passkey is registered. If the helpdesk does not have Temporary Access Pass prepared as a recovery route, those users may be unable to work.

A managed migration before the deadline gives the business control over which users move, in what order, with what guidance, and what happens if something goes wrong.

A Practical Migration Plan

A practical migration follows a logical sequence:

  1. Measure. Review which methods are enabled, which users have registered them, and which are actively using SMS or voice — these are three different assessments.
  2. Understand. Identify the right method for each user group: passkeys, Windows Hello, FIDO2 keys or a combination. Map out recovery, exception and accessibility cases.
  3. Improve. Configure the Authentication Methods Policy, registration campaign, Temporary Access Pass and authentication strengths. Pilot with a representative group before the full rollout.
  4. Migrate and verify. Move users in controlled phases. Confirm sign-in, MFA and recovery work for each group before removing SMS as a fallback.
  5. Maintain. Review authentication regularly as users, devices and policies change — not once as a project deliverable.

Common Mistakes

  • Assuming it only affects sign-in. SSPR, emergency accounts, application sign-on and conditional access policies can all be affected.
  • Treating registration as completion. A user who registers a passkey but has not tested sign-in and recovery may still hit a problem.
  • Removing SMS before testing the replacement. Remove weaker methods only after the stronger method is proven — not at the same time as the rollout starts.
  • Ignoring administrators. Administrators should be moved first, not last.
  • One guide for everyone. A single registration email does not address shared devices, accessibility requirements or staff without compatible phones.
  • Changing the Authentication Methods Policy without reviewing impact. Policy changes can affect more users and scenarios than expected. Review before applying.

How Altitude Manages the Migration

Altitude approaches passkey migration as a structured business project, following our Measure • Understand • Improve • Maintain framework:

  • Measure. Identify users, methods, policies, recovery dependencies and device compatibility across the tenant.
  • Understand. Select suitable methods for different user groups, map recovery and exception cases, and design the migration sequence.
  • Improve. Configure passkeys, the Authentication Methods Policy, Temporary Access Pass, registration campaigns and authentication strengths. Pilot with representative users. Move administrators first.
  • Maintain. Review authentication, exceptions, passkey adoption, SSPR and recovery through an Operational Heartbeat — because users, devices and policies continue to change after the project ends.

For organisations that need a full assessment before committing, Altitude offers a Microsoft 365 Authentication Readiness Review — a paid engagement that produces a documented picture of the current state, the affected-user register, the risk register and a migration plan.

Learn more about Altitude's Microsoft 365 Authentication Review and Passkey Migration service.

Conclusion

Microsoft has confirmed the timetable. September 2026 brings passkey registration prompts. February 2027 brings the retirement. Businesses that plan early have control over the rollout. Businesses that wait will have Microsoft control the user experience — and their helpdesks responding to avoidable sign-in problems.

The migration is not technically complex for most organisations. What requires care is the people: administrators, frontline workers, shared-device users, accessibility requirements, recovery processes and the staff who will need guidance when something goes wrong.

Does your business still rely on SMS MFA?

Altitude can review your Microsoft Entra environment, identify affected users and plan a controlled migration to passkeys or other suitable authentication methods — before the 2027 deadline.

Talk to Altitude IT Support