Microsoft is preparing a significant change to authentication for Microsoft Entra ID, its cloud-based identity and access management platform.
From February 1, 2027, Microsoft will discontinue the SMS and voice authentication service it provides for Entra ID. Organizations whose employees still depend on phone numbers and one-time SMS codes will need to prepare alternative authentication methods.
The company is encouraging customers to move toward passkeys and other phishing-resistant authentication technologies rather than waiting until the deadline.
Why Is Microsoft Moving Away From SMS Authentication?
SMS-based one-time passwords remain convenient, but they have security limitations.
An attacker can potentially attempt to obtain an SMS verification code through phishing or social engineering. Phone-number-related attacks can also create additional risks.
Microsoft is therefore encouraging authentication methods that do not require users to disclose a temporary secret code to a website.
Passkeys are designed to make phishing significantly harder by using cryptographic credentials rather than a code sent by SMS.
What Changes From September 2026?
Microsoft has begun making passkeys the default authentication experience for Entra ID as part of its transition away from SMS and voice authentication.
Users who currently rely on SMS or voice authentication may increasingly be prompted to set up another authentication method.
The important dates are:
- September 1, 2026: Microsoft begins transitioning the Entra ID authentication experience toward passkeys.
- February 1, 2027: Microsoft’s own SMS and voice authentication service will be discontinued.
- After the deadline: Users who do not have another suitable authentication method may be required to register or use one before continuing to sign in.
This does not mean that every Microsoft account will suddenly stop working on February 1. The impact depends on the authentication methods configured by the organization and its users.
What Is a Passkey?
A passkey is a modern sign-in credential based on public-key cryptography and standards from the FIDO ecosystem.
Unlike an SMS password, users do not receive a temporary code that they have to type into a website.
Instead, the private portion of the credential remains protected on the user’s device. Authentication can typically use a device PIN, fingerprint, facial recognition or another local security mechanism.
This makes passkeys substantially more resistant to conventional phishing attacks than passwords and SMS codes.
Also Read: OpenAI AI Agents Turned German Website Into Secret Message Board, Made 15,000 Edits
Who Will Be Affected Most?
The change is particularly relevant to organizations where employees still use SMS as their primary or only practical authentication method.
Businesses should pay special attention to:
- Employees who depend exclusively on SMS verification
- Frontline workers using phone-number-based authentication
- Employees using shared devices
- Users who have not registered a second authentication method
- Organizations with legacy authentication policies
Microsoft has supported phone-number and SMS-based sign-in scenarios for certain frontline-worker environments, making migration planning particularly important for these organizations.
Will SMS Authentication Completely Disappear?
There is an important distinction here.
Microsoft’s own SMS and voice authentication service is being discontinued. That does not necessarily mean that every possible third-party SMS authentication option will disappear.
Microsoft says organizations that have specific business, technical or regulatory requirements can use supported third-party telecommunications providers through the appropriate Microsoft channels.
However, Microsoft is encouraging organizations to move toward more phishing-resistant options rather than continuing to depend on SMS wherever possible.
What Authentication Options Can Businesses Use?
Organizations can prepare for the change by evaluating alternatives such as:
- Passkeys
- Windows Hello for Business
- FIDO2 security keys
- Other supported phishing-resistant authentication methods
- QR Code Authentication for certain frontline or shared-device scenarios
The right option will depend on the organization’s security requirements, devices, workforce and existing Microsoft Entra configuration.
What Should IT Administrators Do Now?
Businesses should not wait until January 2027 to begin the migration.
IT teams can start by identifying users and applications that still depend on SMS or voice authentication.
Recommended preparation steps
- Identify SMS-dependent users
Check which employees still rely on SMS or voice authentication. - Introduce alternative authentication methods
Begin registering passkeys, security keys or other supported methods. - Test with a pilot group
Roll out the new authentication process to a limited group before wider deployment. - Update employee instructions
Explain how employees can register and use their new authentication method. - Prepare account-recovery procedures
Make sure users have a secure recovery option if they lose access to their device. - Monitor authentication policies
Review Entra ID policies and authentication methods before the February deadline.
What Happens If a User Has Only SMS?
This is one of the most important issues for organizations to address.
If a user has no alternative authentication method registered when Microsoft’s SMS and voice service is discontinued, the user may be required to set up a supported authentication method before being able to continue signing in.
For this reason, organizations should identify affected accounts well before the deadline rather than treating February 2027 as the starting point for migration.
Why This Change Matters
The move away from SMS is part of a broader industry shift toward passwordless and phishing-resistant authentication.
For businesses, the transition could require more than simply changing a login setting. IT departments may need to update policies, enroll devices, train employees and establish recovery procedures.
For users, the biggest change will be moving from a familiar SMS code to an authentication experience based on a passkey, security key or another approved method.
Final Take
Microsoft’s Entra ID authentication changes are designed to reduce reliance on SMS and voice verification and encourage stronger authentication methods.
The key date to remember is February 1, 2027, when Microsoft’s own SMS and voice authentication service for Entra ID is scheduled to end.
Organizations that still rely heavily on SMS should begin identifying affected users and introducing alternative authentication methods now, rather than waiting until the deadline approaches.
Read in App ★ Free