Move to phishing-resistant authentication before SMS and voice retire
We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication. Passkeys are becoming the default authentication experience in Microsoft Entra, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027.
For more context on why Microsoft is moving to phishing-resistant authentication by default, please read our Microsoft Security Blog announcement.
What is changing
- Passkeys become the default authentication experience for users currently enabled for SMS or voice.
- Microsoft-provided telecom delivery for SMS and voice will be retired. Customer-managed telecom providers configured through the Microsoft Security Store are not affected.
Why this is changing
SMS and voice are among the most vulnerable authentication methods available today and provide significantly weaker protection against phishing, SIM-swap, and replay attacks than passkeys. Moving to phishing-resistant methods gives your organization stronger security by default.
Impact on you and key dates
- September 1, 2026 — Users enabled for SMS or voice are automatically enabled for passkeys and will be nudged to register a passkey when they next complete MFA. (If you do not want this, move users out of SMS or voice in the Authentication Methods Policy before this date.)
- February 1, 2027 — Microsoft-provided SMS and voice are fully retired in Microsoft Entra ID. Customer-managed telecom providers are unaffected.
- After February 1, 2027 — Users whose only available MFA method is SMS or voice will receive a blocking prompt to register a passkey before they can continue signing in. There is no opt out from this enforcement; it applies to all tenants.
If no users in your tenant are enabled for SMS or voice, no action is required and you can disregard the steps below.
If you do have users enabled for SMS or voice, the required action is to move every one of those users off SMS and voice before February 1, 2027. Microsoft recommends passkeys — the default phishing-resistant credential in Microsoft Entra ID. Take the following steps:
- Find affected users. Identify who in your tenant is still enabled for SMS or voice.
- Move users to passkeys. Enable passkeys and run a registration campaign to drive adoption at scale before auto-enablement on September 1, 2026.
- Communicate the change. Notify your users of what is changing, when, and the action they need to take.
- Evaluate a telecom provider only if required. If you have a regulatory or operational need to keep SMS or voice, configure a customer-managed provider through the Microsoft Security Store before February 1, 2027 (provider options and pricing published beginning September 18, 2026; configuration available beginning October 30, 2026).
The bottom line: every SMS and voice user must be on a phishing-resistant method — passkeys are recommended — before Microsoft-provided SMS and voice retire on February 1, 2027. Acting before September 1, 2026 lets you move users on your own schedule and avoid blocking prompts.