Microsoft is retiring SMS and voice call codes as a multi-factor authentication method for Microsoft 365 and Entra ID. From 1 September 2026, any user still relying on text or phone call codes will start being nudged to set up a passkey instead.
- What it is: Microsoft is phasing out its own SMS and voice-call MFA in favour of passkeys, a more secure sign-in method tied to your device.
- Who is affected: Any Microsoft 365 or Entra ID user whose MFA method is currently set to text message or phone call.
- What the risk is: From 1 February 2027, SMS and voice MFA stops working entirely for these accounts unless a business has its own telecom provider configured. Users with no other MFA method could be locked out.
- What action is needed: Encourage staff to register a passkey or the Microsoft Authenticator app when prompted, rather than dismissing the notification. Review which users still rely solely on SMS or voice codes before the February cut-off.
We recommend getting ahead of this change now rather than scrambling in early 2027.