Microsoft is retiring SMS and voice authentication
Microsoft has announced an important change to how users authenticate when signing into Microsoft 365 and other Microsoft services. Microsoft will retire SMS text message and voice call authentication on 1 February 2027.
Most organisations still use some of these methods for multi-factor authentication (MFA), so you will need to move to more secure alternatives before then. This change reflects Microsoft’s move towards phishing-resistant authentication.
Microsoft now recommends passkeys as the most secure option, followed by authenticator apps including Microsoft Authenticator. SMS and voice authentication are being phased out entirely because they are more vulnerable (for example, text messages are not sent or received in encrypted format). Passkeys are a secure, passwordless credential that lets you sign in using your device’s fingerprint, face scan, or screen lock – they replace traditional passwords with cryptography.
Beginning 1 September 2026, users who are still using SMS or voice authentication will begin receiving prompts to register a passkey when they sign in. From 1 February 2027, anyone who has only the old methods configured will be unable to sign in until they register a modern, supported authentication method.
For help identifying affected users or deploying passkeys across your organisation, please contact us for support.