
Microsoft is retiring SMS and voice MFA and moving users toward more secure, phishing-resistant authentication methods such as passkeys.
If your business uses Microsoft 365 or Microsoft Entra ID, there’s an important authentication change coming that is worth planning for now.
Microsoft is retiring the SMS and voice authentication services it currently provides for multi-factor authentication, or MFA. The change becomes final on February 1, 2027.
For businesses that still have employees receiving a text message or phone call from Microsoft when they sign in, this means those methods will eventually stop working unless the organization moves to a supported third-party telecom provider.
From a security standpoint, passkeys offer better login security to protect your network from unauthorized logins. From a business standpoint, it’s something you want to prepare for before employees start running into sign-in problems.
From a security standpoint, that’s a good move. From a business standpoint, though, it’s something you want to prepare for before employees start running into sign-in problems.
Here’s what you need to know.
Why Microsoft Is Moving Away From SMS and Voice MFA
SMS and voice MFA have been around for years, and they’re still better than using a password by itself. The problem is that attackers have learned how to get around them.
Text-message and phone-based authentication can be vulnerable to phishing, SIM-swapping, interception, and other techniques. Passkeys are designed to make those attacks much harder because they don’t rely on a code that can simply be stolen or tricked out of someone.
In other words, Microsoft is trying to move businesses toward a stronger way of proving that the person signing in is actually who they say they are.
For most users, that will eventually mean using a passkey tied to a trusted device, biometric sign-in such as a fingerprint or facial recognition, or another supported phishing-resistant method.
You don’t need to understand all the technology behind it. The important part is that these methods are significantly harder for attackers to fake.
The Key Dates to Know
There are a few dates involved, but two matter most for most businesses.
September 1, 2026
Microsoft begins automatically enabling passkeys for users who are currently enabled for SMS or voice authentication.
Those users may start seeing prompts asking them to register a passkey when they sign in.
Organizations can temporarily opt out of this automatic migration while they prepare, but that does not remove the final retirement deadline.
February 1, 2027
Microsoft-provided SMS and voice authentication will be retired.
At that point, businesses that still depend on Microsoft’s built-in text-message or voice-call delivery will need to have another authentication method in place.
If an employee’s only available MFA method is SMS or voice, that person may eventually be blocked from signing in until they register a supported passkey or another acceptable method.
That’s the situation businesses should be working to avoid.
What About Businesses That Still Need SMS or Voice?
Microsoft is creating an option for organizations that have a legitimate reason to continue using SMS or voice authentication.
Beginning later in 2026, organizations will be able to work with supported telecom providers rather than relying on Microsoft’s built-in SMS and voice service.
Microsoft plans to publish provider and pricing information on September 18, 2026, with configuration becoming available on October 30, 2026.
For most small and midsize businesses, though, keeping SMS simply because it’s familiar probably isn’t the best long-term choice. If a stronger authentication method works for your team, this is a good opportunity to make the switch.
What Your Business Should Do Now
The first step is simply figuring out whether this change affects you.
If no one in your organization is using SMS or voice authentication, there may be very little you need to do. But if you’ve been using Microsoft 365 for a while, there’s a good chance at least some users were enrolled with a phone number at some point.
Start by reviewing which employees are still enabled for SMS or voice MFA. From there, begin moving those users to passkeys or another stronger authentication method well before the February deadline.
Doing this early gives you some breathing room. Employees have time to get used to the new sign-in process, your IT team can catch any unusual cases, and you’re not trying to solve everything at once when Microsoft starts enforcing the change.
Communication matters here, too.
If employees suddenly see a new Microsoft prompt asking them to register a passkey, some of them are going to wonder whether it’s legitimate. That’s understandable. We spend a lot of time teaching people not to trust unexpected sign-in prompts.
A simple heads-up can prevent confusion.
Let employees know that a change is coming, explain what they’ll see, and give them clear instructions on what they need to do. That small amount of preparation can save a lot of help-desk calls later.
Why Waiting Until the Deadline Is a Bad Idea
This change probably won’t feel urgent until someone can’t get into email, Teams, or another Microsoft service.
That’s exactly why it’s better to handle it ahead of time.
Picture an employee trying to sign in five minutes before an important customer meeting. Their usual text-message verification no longer works, and now they’re being asked to register a new authentication method on the spot.
One person dealing with that is inconvenient. Twenty employees dealing with it at the same time is a business problem.
The goal isn’t just to meet Microsoft’s deadline. It’s to make the transition boring.
That means getting users moved over gradually, answering questions before they become emergencies, and making sure everyone can still get to the systems they need to do their jobs.
If You’re Already a Stimulus Technologies Client
If you’re on one of our Premiere or Pinnacle support plans, we’re taking care of this for you.
Our team is reviewing affected users, helping manage the move to passkeys, and making the necessary policy changes so you don’t have to keep track of every Microsoft authentication update yourself.
That’s part of what proactive IT support should do. Your team should be able to focus on running the business while we keep an eye on changes like this in the background. That fits the way Stimulus Technologies positions its support: reducing disruption, responding proactively, and giving business owners fewer technology problems to manage.
If you’re on another Stimulus Technologies plan, reach out to your account manager, or give us a call, so we can review your environment and help you build a transition plan before the February 2027 deadline.
Not a Client? Now Is a Good Time to Check Your Setup
If you’re not sure whether your employees are still using SMS or voice authentication, it’s worth finding out now rather than discovering it when someone gets locked out.
We can help you review your current Microsoft 365 and Entra ID setup, identify which users may be affected, and put a practical transition plan in place.
Schedule a free 15-minute initial consultation and we’ll help you figure out what needs to change before Microsoft’s deadline arrives.
The goal is simple: make the change before it becomes a disruption.
This article reflects Microsoft’s published guidance regarding the retirement of Microsoft-provided SMS and voice authentication. Microsoft may update implementation details as the deadline approaches, so organizations should continue reviewing Microsoft’s documentation or work with their IT provider.

