Microsoft Entra ID to Retire SMS and Voice MFA in 2027: What Organizations Need to Know

Microsoft is making a major change to how users authenticate with Microsoft Entra ID, announcing plans to retire Microsoft-provided SMS and voice authentication in favor of more secure, phishing-resistant methods.

Beginning February 1, 2027, Microsoft-provided SMS and voice authentication will no longer be available in Microsoft Entra ID. Microsoft is recommending that organizations transition affected users to passkeys, which are becoming the default authentication experience for users currently relying on SMS or voice.

The transition begins much sooner, however, with an important deadline arriving on September 1, 2026.

When Is Microsoft Retiring SMS and Voice MFA?

Microsoft-provided SMS and voice authentication will officially retire from Microsoft Entra ID on February 1, 2027.

The rollout includes two major dates:

September 1, 2026: Microsoft Entra ID users who are enabled for SMS or voice authentication will automatically become enabled for passkeys. When those users next complete multifactor authentication (MFA), Microsoft will encourage them to register a passkey.

February 1, 2027: Microsoft-provided SMS and voice authentication will be fully retired.

After the February deadline, users whose only available MFA method is SMS or voice will receive a blocking prompt requiring them to register a passkey before they can continue signing in.

Microsoft says there will be no opt-out from this enforcement, and the requirement will apply to all Microsoft Entra ID tenants.

Why Is Microsoft Eliminating SMS and Voice Authentication?

Microsoft says the move is designed to improve account security as phishing attacks become increasingly sophisticated.

SMS and voice authentication are considered weaker forms of MFA because they can be vulnerable to attacks including:

  • Phishing
  • SIM-swapping
  • Replay attacks
  • Social engineering
  • Interception of authentication codes

Passkeys provide stronger protection because they are designed to be phishing-resistant and don’t require users to manually enter a one-time security code received through a text message or phone call.

Microsoft is positioning passkeys as its preferred phishing-resistant credential for Microsoft Entra ID.

What Are Passkeys in Microsoft Entra ID?

Passkeys are a passwordless authentication method that can use a device’s built-in security features to verify a user’s identity.

Instead of receiving an SMS code, users can authenticate through supported methods such as biometrics, a device PIN, or compatible security credentials.

Because the authentication credential is tied more closely to the legitimate service and user’s device, passkeys are substantially more resistant to traditional credential phishing.

What Happens on September 1, 2026?

September 1 is the first major deadline organizations should prepare for.

Starting September 1, 2026, Microsoft will automatically enable passkeys for users who are currently enabled for SMS or voice authentication.

Those users will then be nudged to register a passkey the next time they complete MFA.

Organizations that don’t want Microsoft to automatically enable this experience should move affected users out of SMS and voice in the Authentication Methods Policy before September 1, 2026.

This gives IT administrators an opportunity to manage the migration themselves instead of waiting for Microsoft’s automatic rollout.

What Happens on February 1, 2027?

The biggest change arrives on February 1, 2027, when Microsoft-provided SMS and voice authentication are fully retired from Microsoft Entra ID.

Organizations should ensure users have another supported authentication method configured before this date.

Users who reach the deadline with SMS or voice as their only available MFA method will be required to register a passkey before they can continue signing in.

Microsoft says there will be no option for organizations to disable this enforcement.

What Should Microsoft Entra Administrators Do?

Organizations using Microsoft Entra ID should begin reviewing their authentication policies well before the 2027 deadline.

Administrators should first identify users who are currently enabled for SMS or voice authentication.

Those users should then be migrated to passkeys or another appropriate phishing-resistant authentication method.

Microsoft recommends organizations:

  1. Identify affected users who still have SMS or voice authentication enabled.
  2. Enable passkeys within the organization’s Microsoft Entra authentication policies.
  3. Launch a registration campaign encouraging affected users to create their passkeys.
  4. Communicate the upcoming changes so employees understand why their authentication experience is changing.
  5. Complete the migration before February 1, 2027 to prevent users from encountering blocking prompts during sign-in.

Organizations that begin the transition before September 1, 2026 can manage the migration on their own schedule and potentially reduce support issues when Microsoft’s automatic passkey prompts begin.

Can Organizations Continue Using SMS or Voice MFA?

There is an exception for organizations that have regulatory, accessibility, operational, or other requirements for SMS or voice authentication.

Microsoft is retiring its own telecom delivery of SMS and voice authentication, but customer-managed telecom providers are not affected.

Organizations that need to retain SMS or voice can configure a customer-managed telecom provider through the Microsoft Security Store.

Microsoft says provider options and pricing are scheduled to become available beginning September 18, 2026, with configuration becoming available beginning October 30, 2026.

Organizations considering this approach will still need to have their alternative provider configured before Microsoft’s February 1, 2027 retirement date.

Do All Microsoft Entra ID Users Need to Take Action?

No.

If an organization’s Microsoft Entra ID tenant has no users enabled for SMS or voice authentication, Microsoft says no action is required.

The change primarily affects organizations that currently allow users to authenticate through Microsoft-provided text messages or voice calls.

Administrators should nevertheless review their Authentication Methods Policy to determine whether any accounts remain eligible for these methods.

Microsoft Pushes Toward Phishing-Resistant Authentication

Microsoft’s decision represents another significant step toward eliminating authentication methods that depend on passwords and one-time codes.

Passkeys are increasingly being positioned as a replacement because they can provide a simpler authentication experience while offering stronger resistance to phishing.

For Microsoft Entra ID administrators, the most important date may actually be September 1, 2026, rather than the final 2027 retirement deadline.

Migrating SMS and voice users before September allows organizations to control how and when employees transition to passkeys.

The final deadline is February 1, 2027. By that point, every user currently dependent on Microsoft-provided SMS or voice MFA should have another authentication method configured.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.