Move to Phishing-Resistant Authentication Before SMS and Voice Retire
- Ruby Harper

- 1 day ago
- 7 min read
Microsoft Entra ID is changing - is your organisation ready?
Authentication is changing rapidly.
As organisations adopt cloud services, AI and increasingly sophisticated digital tools, attackers are also finding new ways to compromise user accounts. Traditional authentication methods that were once considered adequate are no longer providing the level of protection organisations need.
Microsoft is now taking another significant step with Microsoft Entra ID: passkeys are becoming the default authentication experience, while Microsoft-provided SMS and voice authentication will be retired from 1 February 2027.
For organisations still relying on SMS or voice calls for multi-factor authentication (MFA), this is more than a technology update. It is a clear signal that the industry is moving away from phone-based authentication and towards phishing-resistant authentication.
What is changing?
Microsoft is making two important changes to authentication in Entra ID.
First, from 1 September 2026, users who are currently enabled for SMS or voice authentication will automatically be enabled for passkeys. When those users next complete MFA, they may be prompted to register a passkey.
Second, on 1 February 2027, Microsoft-provided telecom delivery for SMS and voice authentication will be retired in Microsoft Entra ID.
This means organisations that currently depend on Microsoft's built-in SMS or voice service need to start planning their transition now.
Importantly, organisations that use a customer-managed telecom provider configured through the Microsoft Security Store will not be affected in the same way and can continue using SMS or voice where there is a genuine business, regulatory or operational requirement.
Why is Microsoft moving away from SMS and voice?
The answer is simple: security.
SMS and voice authentication rely on telecommunications infrastructure that was never designed to provide the strongest possible protection against modern account takeover techniques.
Attackers can use phishing, social engineering, SIM swapping and other techniques to intercept or manipulate phone-based authentication.
A user receiving a six-digit code by text may feel secure because there is an additional step in the login process. However, if an attacker can convince the user to provide that code on a fraudulent website, the additional factor can potentially be defeated.
Passkeys work differently.
Rather than relying on a shared secret such as a password or one-time SMS code, passkeys use cryptographic credentials. The authentication process is designed so that the credential cannot simply be handed over to an attacker through a phishing website.
Microsoft describes passkeys as a phishing-resistant credential and recommends moving users away from phishable authentication methods.
What makes passkeys different?
One of the biggest advantages of passkeys is that they remove much of the human element from authentication.
With SMS authentication, a typical attack might look like this:
Attacker → Fake Microsoft login page → User enters credentials → SMS code requested → User enters code → Account compromised
With a passkey, the authentication mechanism uses cryptographic keys and verifies the legitimate website or service as part of the authentication process.
This makes passkeys significantly more resistant to phishing and other attacks that rely on tricking users into revealing authentication codes.
Microsoft Entra supports different types of passkeys, including synced passkeys and device-bound credentials such as FIDO2 security keys and other supported passkey implementations.
For organisations, this means the move to passkeys isn't simply about replacing one MFA prompt with another. It is an opportunity to fundamentally improve the security of identity and access.
The important dates
There are three dates organisations should have on their radar.
1 September 2026 - Passkeys become the default
From 1 September, users who are enabled for SMS or voice will automatically be enabled for passkeys.
When those users next sign in and complete MFA, they may receive a prompt encouraging them to register a passkey.
Microsoft recommends organisations proactively prepare users rather than waiting for this process to happen automatically.
1 February 2027 - Microsoft SMS and voice retire
This is the key deadline.
Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID.
Organisations that have not migrated affected users to an alternative authentication method could experience disruption to their users' sign-in experience.
After 1 February 2027 - Blocking registration prompts
There is an important consequence for users who have not made the transition.
If a user's only available MFA method is SMS or voice, they will be required to register a passkey during sign-in before they can continue accessing their account.
This is not an optional recommendation or a prompt that administrators can simply ignore. Microsoft states that this enforcement will apply to all tenants.
In other words, waiting until February 2027 isn't a migration strategy.
What should your organisation do?
If your organisation uses Microsoft Entra ID, now is the time to understand whether you are affected.
1. Identify users still relying on SMS or voice
Start by finding out exactly how many users in your tenant still have SMS or voice enabled.
This is particularly important in larger environments, where legacy authentication methods can remain enabled for users long after newer authentication options have been introduced.
Your security team should establish:
Which users are using SMS authentication?
Which users are using voice authentication?
Are these methods their only MFA options?
Are there privileged or high-risk accounts still relying on them?
Are there frontline or remote users with specific authentication requirements?
Are there regulatory or operational reasons why SMS or voice must remain available?
Getting an accurate picture of your current authentication landscape should be the first step.
2. Start moving users to passkeys
Once affected users have been identified, begin moving them towards phishing-resistant authentication.
Microsoft recommends passkeys as the primary migration path. Other phishing-resistant options, such as Windows Hello for Business and FIDO2 authentication, can also form part of an organisation's authentication strategy.
Rather than attempting to change every user overnight, organisations should consider a phased rollout.
For example:
Phase 1: Pilot passkeys with IT and security teams.
Phase 2: Roll out to a small group of users from different departments.
Phase 3: Expand the deployment and monitor registration and authentication issues.
Phase 4: Complete migration of remaining SMS and voice users.
Phase 5: Remove unnecessary legacy authentication methods.
Microsoft also provides a passkey registration campaign designed to encourage users to register passkeys during sign-in.
Don't forget about the user experience
Technology migrations often fail because organisations focus on the technical configuration and forget about the people using it.
For many employees, receiving an SMS code has become second nature. Being asked to use a passkey may initially feel unfamiliar.
That means communication matters.
Users should understand:
Why the organisation is making the change
What a passkey is
How they will register one
What devices they can use
What the new sign-in experience will look like
Where to get help if registration doesn't work
The message shouldn't be:
"Microsoft is removing SMS, so you have to use a passkey."
Instead, explain the security benefit.
We're moving away from authentication methods that attackers can intercept or phish and towards authentication designed to resist those attacks.
That makes the change much easier for users to understand.
What if your organisation still needs SMS or voice?
Not every organisation will be able to remove telecommunications-based authentication immediately.
There may be specific regulatory, operational or technical requirements that make SMS or voice necessary for certain groups of users.
Microsoft is providing an alternative for these scenarios through customer-managed telecom providers available through the Microsoft Security Store.
Microsoft has indicated that provider information will become available from 18 September 2026, with configuration available from 30 October 2026. Organisations with a genuine requirement should therefore assess their options well before the February 2027 retirement date.
However, this shouldn't be interpreted as a reason to keep SMS as the default authentication method.
Where possible, organisations should use phishing-resistant authentication and reserve telecommunications-based methods for situations where they are genuinely required.
Why this matters even more in the AI era
There is a wider lesson behind Microsoft's announcement.
Attackers are increasingly using automation and AI to make phishing campaigns more convincing, scalable and targeted.
Traditional security advice has often focused on teaching users how to spot suspicious emails and websites. That remains important, but organisations should not rely solely on users identifying every sophisticated attack.
The stronger approach is to combine security awareness with authentication technology that is inherently harder to phish.
This is where phishing-resistant authentication becomes particularly important.
Instead of asking users to become better at spotting every attack, we can make the authentication mechanism itself harder to attack.
That is the real significance of the move towards passkeys.
A practical checklist for IT and security teams
If your organisation uses Microsoft Entra ID, we recommend reviewing the following before the February 2027 deadline:
Identify all users currently enabled for SMS or voice.
Determine whether SMS or voice is their only MFA method.
Enable and configure passkeys.
Test passkey registration with a pilot group.
Run a passkey registration campaign.
Prioritise administrators and privileged accounts.
Communicate the change to employees.
Provide user guidance and help-desk support.
Test recovery and account-access scenarios.
Review frontline and shared-device requirements.
Identify any genuine regulatory or operational requirement for SMS or voice.
If required, evaluate customer-managed telecom providers.
Complete the migration before 1 February 2027.
Don't wait for the deadline
The retirement of Microsoft-provided SMS and voice authentication shouldn't come as a surprise in February 2027.
Organisations have an opportunity now to use the change as a catalyst for improving their wider identity security strategy.
Moving users from SMS and voice to passkeys can reduce reliance on phishable authentication methods, strengthen protection against account compromise and provide users with a more modern sign-in experience.
The key message is simple:
Don't wait for Microsoft to force the change. Start moving to phishing-resistant authentication now.
If your organisation still relies heavily on SMS or voice authentication, now is the time to identify affected users, plan your migration and start preparing your people.
The February 2027 deadline may seem a long way away — but identity migrations are rarely as simple as changing a setting.
The earlier you start, the smoother and more secure the transition will be.
Further reading
Microsoft's detailed guidance on the retirement of SMS and voice authentication and the move to passkeys is available in the Microsoft Entra ID documentation.



