Still Using Text Message MFA? Time to Plan Ahead
- Read time: 2 mins.
Microsoft has announced a significant change to how users authenticate to Microsoft 365 and Microsoft Entra ID. Organizations that still rely on text message (SMS) or phone call verification for multi-factor authentication (MFA) need to start planning their transition now. Microsoft will begin moving users toward passkeys on September 1, 2026, and will fully retire Microsoft-provided SMS and voice authentication services on February 1, 2027.
Why Is Microsoft Making This Change?
Cyberattacks have evolved dramatically in recent years. Traditional MFA methods like SMS codes and voice calls are increasingly vulnerable to phishing attacks, SIM-swapping, and social engineering. Microsoft is shifting customers toward phishing-resistant authentication methods such as Passkeys, Windows Hello for Business, and FIDO2 security keys to better protect identities and sensitive data.
What Happens Next?
Beginning September 1, 2026, users currently configured for SMS or voice authentication will automatically be enabled for passkeys and encouraged to register them when they sign in.
On February 1, 2027, Microsoft-provided SMS and voice authentication services will be retired. Organizations that still require phone-based MFA will need to procure and configure a third-party telecom provider through the Microsoft Security Store. Otherwise, users relying solely on SMS or voice authentication may experience sign-in disruptions.
Why Organizations Should Act Now
Many organizations are surprised to discover how many users still depend on SMS-based MFA. Waiting until the retirement deadline can lead to:
- Increased help desk requests
- User sign-in interruptions
- Compliance and security concerns
- Last-minute migration efforts
Microsoft recommends identifying affected users now and developing a migration plan before the enforcement date approaches.
How HBS Can Help
Heartland Business Systems can help your organization prepare for this transition by:
- Assessing your current MFA and authentication method usage
- Identifying users still relying on SMS and voice authentication
- Designing and implementing a Passkey adoption strategy
- Deploying Windows Hello for Business and FIDO2 security keys
- Updating authentication policies and Conditional Access controls
- Providing end-user communication and training
- Reviewing regulatory or operational requirements for organizations that must continue using telecom-based authentication
Don’t Wait Until the Deadline
This change impacts every Microsoft Entra ID tenant. Organizations that start planning now can improve security, reduce user disruption, and avoid a rushed migration later. If you’d like help evaluating your environment and building a roadmap to modern, phishing-resistant authentication, contact the HBS Modern Workplace team today.
Related Content
Combatting MFA Bombing
Identify and prevent MFA bombing attacks. Stay vigilant and protect your accounts by recognizing legitimate MFA requests and following best security practices.
Mobile Device Security: Phishing, Mishing, and More
Protect your business from evolving mobile threats. Learn the top mobile security risks, best practices to mitigate them, and how HBS can help.
Microsoft Secure Score: What It Is, Why It Matters, and How to Improve Yours
Learn what Microsoft Secure Score is, how it works, what a good score looks like, practical ways to improve it. Tips, tools, and managed security options.