Microsoft has begun an important change to how organizations authenticate users in Microsoft Entra ID.
As of September 1, 2026, Microsoft has started making passkeys the default authentication experience for users currently enabled for SMS or voice authentication. The next major date is February 1, 2027, when Microsoft will retire its native SMS and voice authentication delivery in Entra ID.
For most organizations, this should not be viewed as another IT migration to put on the backlog. It is an opportunity to remove a known weakness from one of the most important parts of your security program: identity.

Why Is Microsoft Moving Away From SMS and Voice Authentication?
SMS and voice-based MFA were an important step forward from passwords alone. They helped make multifactor authentication practical and accessible at scale.
But the threat environment has changed. SMS and voice depend on communication channels that can be intercepted, socially engineered, or manipulated. Microsoft now describes SMS and voice as significantly weaker against phishing and account compromise than passkeys and is moving users toward phishing-resistant authentication.
Passkeys work differently. They use public-key cryptography instead of shared secrets and are designed to resist phishing. Microsoft Entra supports phishing-resistant options that include passkeys, Windows Hello for Business, and FIDO2 security keys.
The important point for business leaders is simple: not all MFA provides the same level of protection.
What Is the Microsoft Entra SMS and Voice Retirement Timeline?
The first milestone has already arrived.
September 1, 2026: Microsoft began automatically enabling passkeys for users enabled for SMS or voice authentication. When affected users next sign in and complete MFA, Microsoft’s registration campaign can prompt them to register a passkey.
September 18, 2026: Microsoft plans to make information about supported telecom providers available through the Microsoft Security Store for organizations with a legitimate business, regulatory, or operational need to continue using SMS or voice.
October 30, 2026: Microsoft plans to make configuration of supported telecom providers available through the Microsoft Security Store.
February 1, 2027: Microsoft-provided SMS and voice authentication will be retired in Entra ID. Users whose only available MFA method is Microsoft-provided SMS or voice will be required to register a passkey during sign-in to continue accessing their account. Microsoft says there will be no opt-out from this February enforcement.
Organizations with a legitimate regulatory, technical, or operational requirement to retain SMS or voice will have an alternative through customer-managed telecom providers. For most organizations, however, I would focus on migration rather than maintaining the older authentication model.
Why Organizations Should Not Wait Until January
February 2027 may sound like there is plenty of time. There is, if organizations use that time intentionally.
This type of change becomes difficult when it turns into a last-minute user support project. Authentication touches almost everyone in an organization. Executives, remote employees, contractors, service desks, administrators, and users with unusual device configurations may all have different requirements.
The technology is only part of the transition. The bigger question is whether you know who is affected and have a practical plan to move them.
Now that Microsoft’s September transition is underway, organizations have an opportunity to see how the change affects their environment while there is still time to address problems deliberately.
What Should Organizations Do Now?
I would start with five straightforward actions.
1. Identify your exposure.
Determine which users and groups are still enabled for SMS or voice authentication. Microsoft recommends identifying active SMS and voice users and reviewing the Authentication Methods Policy as part of migration planning.
2. Define your target authentication standard.
Passkeys are Microsoft's recommended primary migration path, but organizations should determine which phishing-resistant methods fit their workforce, devices, applications, and operational requirements. Windows Hello for Business and FIDO2 security keys are also phishing-resistant options within the Entra ecosystem.
3. Pilot before broad deployment.
Start with a manageable group. Test registration, sign-in, account recovery, device changes, onboarding, and support procedures. The objective is not simply to enable a feature. It is to make sure people can use it reliably.
4. Communicate clearly with users.
People need to understand what is changing, why it matters, and what they need to do. A well-managed authentication change should reduce friction rather than create confusion.
5. Build an exception plan.
There may be users or business processes that cannot immediately move to the preferred method. Identify those cases early and make an explicit risk decision rather than discovering them during enforcement.
Why This Is Really a Risk Management Decision
I think there is a broader lesson here. Cybersecurity programs sometimes treat controls as binary. MFA is either enabled or it is not. A box is checked, and the organization moves on.
Risk does not work that way. The strength of the control matters.
If an organization has MFA everywhere but relies heavily on an authentication method that is increasingly vulnerable to phishing and social engineering, leadership should understand that exposure.
The decision then becomes straightforward: mitigate the risk by moving to stronger authentication, accept a documented exception where necessary, avoid workflows that cannot be adequately protected, or transfer portions of the risk where appropriate.
That is risk-based cybersecurity.
Does Stronger Authentication Have to Mean More Complexity?
There is another positive side to this change. Better security does not always have to make life harder for users.
Passkeys can remove passwords from parts of the authentication experience while providing stronger protection against phishing. Microsoft is moving toward phishing-resistant authentication rather than continuing to rely on SMS and voice as native authentication methods.
For SMBs in particular, that matters. We do not have unlimited people, budgets, or time. The goal should be to make a few high-value improvements that materially reduce risk without creating unnecessary operational overhead.
Identity is one of those areas.
If your organization still relies on SMS or voice MFA in Microsoft Entra ID, now is a good time to understand where it is being used and begin moving those users to phishing-resistant authentication.
The deadline is February 1, 2027. The better operational deadline is much sooner.
The September 1 transition is already underway. Organizations that act now still have time to make the change deliberately, test it properly, educate their people, and resolve exceptions before authentication becomes a business interruption.
That is a much better position than waiting for a blocking sign-in prompt to make the decision for you.
Frequently Asked Questions
Is Microsoft eliminating SMS and voice MFA?
Microsoft is retiring Microsoft-provided SMS and voice authentication delivery in Entra ID on February 1, 2027. Organizations with a legitimate need to continue using SMS or voice will be able to use customer-managed telecom providers through the Microsoft Security Store.
When did Microsoft begin enabling passkeys by default?
Microsoft began the transition on September 1, 2026. Users enabled for SMS or voice are being automatically enabled for passkeys and can be prompted to register a passkey when they sign in and complete MFA.
What happens on February 1, 2027?
Microsoft-provided SMS and voice delivery will be retired in Microsoft Entra ID. If a user's only available MFA method is Microsoft-provided SMS or voice and the organization has not configured a customer-managed telecom provider, the user will need to register a passkey before continuing to sign in.
Are passkeys more secure than SMS MFA?
Passkeys are phishing-resistant and use public-key cryptography rather than shared secrets. Microsoft describes SMS and voice as significantly weaker against phishing and account compromise and recommends moving users to passkeys or another phishing-resistant authentication method.
What should SMBs do about Microsoft's SMS and voice retirement?
Start by identifying users who still rely on SMS or voice authentication. Then determine the appropriate phishing-resistant authentication method, pilot the transition, communicate with users, and identify legitimate exceptions well before February 1, 2027.
Sources
Microsoft. “Passkeys by default and retirement of Microsoft-provided SMS and voice authentication.” Email communication received July 22, 2026.
Microsoft Learn. SMS and voice authentication retirement in Microsoft Entra ID.
Microsoft Learn. SMS and voice authentication retirement FAQ.
Microsoft Security Blog. Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID.
Tags:
Sep 11, 2026, 4:10:50 PM