Microsoft Entra Is Retiring SMS and Voice MFA in February 2027


entra sms retirement
Image credit: Microsoft

Microsoft Entra MFA will stop supporting Microsoft-provided SMS and voice authentication on February 1, 2027. Microsoft will move public cloud tenants toward passkeys as the preferred sign-in method.

According to Windows Latest, organizations that still need SMS or voice authentication will have to use a supported third-party telecom provider.

Microsoft Entra MFA Is Moving to Passkeys

Microsoft plans to make passkeys the default authentication method for Entra ID starting in September 2026.

From September 1, users may receive prompts to register a passkey while completing an MFA challenge. Microsoft will gradually encourage organizations to move users away from phone-based verification before enforcement begins.

The change applies to Microsoft Entra public cloud tenants.

Why Microsoft Is Retiring SMS and Voice MFA

Microsoft considers SMS codes and voice calls less secure than phishing-resistant authentication methods, and it has been pushing users towards passkeys for a while.

Attackers can target phone-based MFA using phishing websites, SIM-swapping attacks, message interception, social engineering, and automated credential theft techniques.

Microsoft also warns that AI tools make it easier for attackers to create convincing fake sign-in pages and launch phishing campaigns at scale.

Why Passkeys Offer Better Security

Passkeys use public-key cryptography instead of passwords or temporary codes.

The private authentication key remains stored on the user’s device. A fake login page cannot capture or reuse that key.

This design helps protect users against phishing, credential interception, and stolen verification codes.

Microsoft Entra MFA Retirement Timeline

Microsoft outlined several important dates for the transition:

  • August 1, 2026: Microsoft expects to provide API support for temporary opt-outs.
  • September 1, 2026: Users will begin receiving passkey registration prompts during MFA challenges.
  • September 18, 2026: Microsoft plans to publish supported telecom provider options.
  • October 30, 2026: Organizations continuing to use SMS or voice must configure a supported provider.
  • February 1, 2027: Microsoft-provided SMS and voice authentication will stop working.

Microsoft Will Not Offer a Permanent Opt-Out

Organizations will not receive a permanent exemption from the February 2027 deadline.

Microsoft will provide a temporary opt-out between September 2026 and February 2027. This option gives administrators additional time to prepare users and update authentication policies.

After February 1, Microsoft-provided SMS and voice MFA will no longer remain available.

What Happens to Accounts After February 2027?

Microsoft will not delete or disable affected accounts.

However, users who only registered SMS or voice authentication will not be able to sign in until they configure a supported passkey or another approved authentication method.

Existing account data will remain intact.

Businesses Can Still Use Third-Party SMS and Voice Services

Organizations with regulatory, accessibility, or operational requirements can continue using telephone-based authentication through supported third-party providers.

Administrators must configure these services through the Microsoft Security Store.

Third-party SMS and voice services will require separate payment. Pricing will depend on the selected provider and region.

How Organizations Can Prepare

IT administrators should identify accounts that still rely on SMS messages or voice calls for authentication and determine where stronger sign-in methods can be introduced.

Organizations should also check whether employee devices support passkeys, begin passkey registration campaigns before enforcement starts, update authentication and conditional access policies, and inform users about the upcoming sign-in changes.

Where phone-based authentication is still required, organizations should also test third-party telecom providers to ensure reliability.

Starting the migration early should reduce account lockouts when Microsoft retires its phone-based MFA services.

Microsoft has also started phasing out SMS authentication for personal Microsoft accounts as it expands its broader move toward phishing-resistant sign-in methods.

More about the topics: microsoft, microsoft entra, passkeys

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages