What Is Changing
Microsoft has announced (Message Center notification MC1426371, backed by a Microsoft Security Blog post and official Entra documentation) that Entra ID is making passkeys the default multifactor authentication experience. The stated driver is simple: to help enterprises adopt AI at scale, Microsoft wants every organisation on phishing-resistant authentication by default. SMS and voice are no longer positioned as secure methods and will no longer be provided natively in Entra ID.
This is not a minor admin setting change. If your organisation relies on SMS or voice MFA through Microsoft, those methods will stop working after 1 February 2027 unless you take action. The good news is that there is a clear runway and a fallback option for organisations that genuinely cannot move everyone to passkeys in time.
The short version
Passkeys become the default. SMS and voice MFA provided by Microsoft get retired. You have from September 2026 to February 2027 to move your users across, with a telecom provider fallback available from October 2026 if you still need SMS for some staff.
The bottom line from Microsoft: every SMS and voice user must be on a phishing-resistant method, with passkeys recommended, before Microsoft-provided SMS and voice retire on 1 February 2027. Acting before 1 September 2026 lets you move users on your own schedule and avoid the blocking prompts that come later.
Key Dates and What Happens at Each One
Three dates matter. Each one changes what your users see and what you as an admin can control.
1 September 2026
Passkeys auto-enabled
Anyone currently set up for SMS or voice MFA gets passkeys automatically enabled, and your registration campaign moves to a Microsoft managed state pointing at passkeys. Users are nudged to register a passkey at their next MFA sign in. By default they get unlimited snoozes of the nudge, so nobody is locked out yet. If you do not want this auto-enablement, move users out of SMS or voice in the Authentication Methods Policy before this date.
18 September 2026
Terms published
Microsoft publishes pricing, commercial terms and the list of supported telecom providers in the Microsoft Security Store, for organisations that must keep phone based codes.
30 October 2026
Telecom provider window opens
If your organisation still needs SMS or voice MFA, you can configure your own telecom provider through the Microsoft Security Store. This is the path forward for orgs that cannot move everyone to passkeys in time.
1 February 2027
Microsoft SMS and voice retired
Microsoft stops providing SMS and voice as MFA options completely. The only way to keep SMS or voice after this date is through a telecom provider you configured yourself.
Important distinction
Microsoft is retiring the SMS and voice MFA that it provides. It is not banning SMS as an MFA concept. If you configure your own telecom provider through the Microsoft Security Store (available from 30 October 2026), SMS and voice remain available through that provider. This is the key fallback for organisations with frontline or deskless staff who cannot easily use passkeys.
Every tenant. No exceptions.
After 1 February 2027, passkey registration becomes a blocking prompt with no opt-out. A user whose only method was a phone number cannot get past it until they register a passkey.
Who This Hits Hardest
SMS and voice already feel like edge cases in most identity conversations. But this change might reach more people than it looks like on paper, especially anywhere frontline or deskless staff make up a big share of the workforce.
Frontline and deskless staff
Warehouse, retail, construction, healthcare and field workers who may not have a company laptop or easy access to the Microsoft Authenticator app. SMS has been the fallback that works on any phone.
Shared device environments
Kiosks, shared workstations and hot-desk setups where individual device enrolment for passkeys is harder to manage. These setups often leaned on SMS as the simplest per-user factor.
Guest and B2B users
External collaborators and guest accounts in your Entra tenant may be enrolled with SMS MFA. Their home organisation controls some of this, but you need to know who they are and what happens when SMS disappears.
Break-glass and emergency accounts
Some orgs use SMS as the MFA factor on emergency access accounts. These need a documented plan and ideally a hardware key instead, not a phone number that can be SIM-swapped.
If your workforce is mostly office-based with company laptops, this change is relatively straightforward. Microsoft Authenticator push with number matching is likely already deployed, and moving to passkeys is a small step. The complexity is in the populations above, where SMS has been the lowest common denominator that works everywhere and needs no device refresh or extra training.
Why Microsoft Is Doing This
Microsoft's framing is blunt: SMS and voice are among the most vulnerable authentication methods available today, providing significantly weaker protection against phishing, SIM-swap and replay attacks than passkeys. The official line is that moving to phishing-resistant methods gives your organisation stronger security by default, and that this is a precondition for adopting AI at scale. Here is why passkeys are the replacement.
SMS weaknesses
- + Vulnerable to SIM swap attacks where an attacker ports your number to their device
- + Susceptible to SS7 signalling interception on the telecom network
- + Can be relayed in real-time phishing kits that capture and forward the code
- + Depends on mobile coverage and carrier reliability
Passkey advantages
- Phishing-resistant by design. Cryptographically bound to the domain
- No SIM dependency, no carrier interception risk
- Works with Windows Hello, Face ID, fingerprint and hardware keys
- Aligns with ACSC Essential Eight phishing-resistant MFA expectations
ACSC alignment: The Essential Eight Maturity Model recommends phishing-resistant MFA and lists SMS as not suitable for privileged accounts. Moving to passkeys brings your organisation closer to what the ACSC and most cyber insurers now expect.
Two types of passkey in Entra ID
Microsoft supports two passkey flavours. Both are phishing-resistant, but the deployment looks different.
Synced passkeys
Saved to a platform credential manager such as iCloud Keychain or Google Password Manager and synced across the user's devices. Best for staff who already use a platform credential manager on their phone.
Device-bound passkeys
Created and stored on a single device, such as Passkey in Microsoft Authenticator, Entra Passkey on Windows, or a FIDO2 hardware security key. Best for shared devices and break-glass accounts.
What to Do Before September 2026
You have a runway. Use it. Here is what to do before the automatic passkey prompt starts appearing for your users.
Audit who is using SMS or voice today
In the Entra admin centre, check the authentication methods report. Export the list of users with SMS or voice as their registered MFA method. This is your migration scope.
Deploy the Microsoft Authenticator app broadly
Get the Authenticator app onto every company and BYO device now, before the September prompt starts appearing. Users who already have the app with push notifications can move to passkeys with minimal friction.
Enable passkeys in your tenant
In Entra authentication methods policy, enable FIDO2 security keys and passkey (Microsoft Authenticator) before Microsoft auto-enables them. This lets you control the rollout timing and communication.
Identify who genuinely cannot use a passkey
Some staff will not have a compatible device or will need a hardware security key. Identify these people now so you can budget for keys and plan the telecom provider fallback if needed.
Communicate the change to staff
Tell people what is happening, when, and what they will see. A short heads-up before September prevents helpdesk spikes when the passkey registration prompt appears during sign-in.
Plan your Conditional Access updates
Review your Conditional Access policies. If any policies explicitly require or allow SMS as an authentication method, update them. Your phishing-resistant MFA policies should already favour passkeys and hardware keys.
The Telecom Provider Option
From 30 October 2026, you can configure your own telecom provider through the Microsoft Security Store. This is the official path for organisations that still need SMS or voice MFA after Microsoft retires its own SMS and voice options.
How the telecom provider option works
You select and configure a telecom provider in the Microsoft Security Store. That provider handles the SMS and voice delivery for your tenant. You are responsible for the provider relationship, configuration, and any associated costs. Microsoft no longer acts as the telecom intermediary.
This option is a relief for organisations with frontline or deskless staff. It gives you a real path forward instead of a hard cutoff. But it should be a targeted fallback for specific user populations, not a reason to delay passkey adoption for everyone who can use one.
Use it for who actually needs it
Identify the specific users or roles where passkeys are genuinely not viable. Configure the telecom provider for those populations, not the whole tenant.
Budget for the provider costs
Unlike Microsoft-provided SMS, a third-party telecom provider has its own pricing. Factor this into your identity and security budget for the 2027 financial year.
Keep working on passkey adoption
The telecom provider is a bridge, not a destination. Continue moving users to passkeys where possible, and revisit your SMS-dependent population each quarter.
Check Your Current MFA Setup
Before you can plan your migration, you need to know who is using SMS or voice today. Here is how to check.
1. Open the Entra admin centre
Go to entra.microsoft.com and navigate to Protection then Authentication methods then Activity.
2. Check the registered methods report
Look at the registration count for each authentication method. Filter for users with SMS or voice as their primary or only registered method. Export this list.
3. Review your authentication methods policy
Check whether SMS and voice are currently allowed or targeted for specific groups. Review your FIDO2 and passkey settings to see if they are already enabled or still in the default state.
4. Check Conditional Access policies
Review any Conditional Access policies that require MFA. Identify policies that explicitly allow SMS as an acceptable method. These will need updating to favour phishing-resistant methods.
If you are not sure where to start or do not have an Entra ID admin on staff, this is exactly the kind of thing we help with. We can run the audit for you and give you a clear report of who is on SMS, what needs to change, and a timeline to get it done before February 2027.
Migration Checklist
A practical checklist to work through between now and February 2027.
Frequently Asked Questions
Q.Will SMS MFA stop working for my users on 1 September 2026?
No. On 1 September 2026, passkeys get automatically enabled for anyone currently set up for SMS or voice. Users will see a prompt to register a passkey when they sign in, but they can skip it. SMS still works as a fallback until 1 February 2027, unless you configure your own telecom provider before then.
Q.What happens after 1 February 2027 if I do nothing?
After 1 February 2027, Microsoft stops providing SMS and voice as MFA options completely. Any user whose only available MFA method is SMS or voice will hit a blocking prompt requiring them to register a passkey before they can continue signing in. There is no opt out from this behaviour and it applies to all tenants. Acting before 1 September 2026 lets you move users on your own schedule and avoid the blocking prompts.
Q.Can I keep SMS MFA after February 2027?
Yes, but only if you configure your own telecom provider through the Microsoft Security Store. This option becomes available from 30 October 2026. You are responsible for the provider relationship and costs. Microsoft will no longer provide SMS or voice MFA directly.
Q.Does this affect Google Workspace or other non-Microsoft platforms?
No. This change is specific to Microsoft Entra ID (formerly Azure AD). It affects MFA for Microsoft 365, Azure, and any SaaS application that uses Entra ID for single sign-on. Google Workspace, AWS, and other platforms have their own MFA policies and are not affected by this announcement.
Q.Are passkeys phishing-resistant?
Yes. Passkeys use FIDO2 standards and are cryptographically bound to the domain. This means a passkey registered for your tenant cannot be used on a fake phishing site, even if a user is tricked into entering their password there. This is a significant improvement over SMS, which is vulnerable to SIM swap and real-time phishing.
Q.Does this align with ACSC Essential Eight guidance?
Yes. The ACSC Essential Eight recommends phishing-resistant MFA and explicitly lists SMS as not suitable for privileged accounts at higher maturity levels. Moving from SMS to passkeys brings your organisation closer to Essential Eight maturity requirements and what cyber insurers expect.
Sources
- Microsoft Message Center notification MC1426371 and the accompanying Microsoft Security Blog announcement on phishing-resistant authentication by default.
- Microsoft Learn: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication (official migration guidance, including the PowerShell usage analyser and registration campaign steps).
- Always verify the latest details and any updates in your own Microsoft 365 admin centre Message Center, as Microsoft may adjust timelines or scope. This guide reflects the announcement as published in August 2026.
Need help moving off SMS MFA?
We audit your Entra tenant, identify every user on SMS or voice, deploy passkeys and the Microsoft Authenticator app, configure Conditional Access, and set up the telecom provider fallback if you need it.

Remote Support