Microsoft is Retiring SMS and Voice MFA: Why Your Business Needs Passkeys Before February 2027

Microsoft has confirmed a major change to how organisations using Microsoft Entra ID (formerly Azure AD) authenticate their users. SMS and voice-based multi-factor authentication, provided directly by Microsoft, will be retired on 1 February 2027. Passkeys are becoming the default authentication method across the platform, and every business still relying on text message or phone call codes needs a plan.

At System Force IT, we work with organisations across Gloucestershire and beyond to keep Microsoft 365 environments secure and compliant. This change affects a large number of tenants, so here is what you need to know and what to do about it.

Why Microsoft is making this change

SMS and voice authentication have long been recognised as the weakest widely-used forms of MFA. They remain vulnerable to SIM-swap fraud, phishing, and interception in ways that modern phishing-resistant methods are specifically designed to prevent. Passkeys, built on the FIDO2/WebAuthn standard, tie authentication to a physical device or biometric and cannot be phished, replayed, or intercepted in the same way.

Key dates to plan around

  • 1 September 2026 – Any user still enabled for SMS or voice will be automatically enabled for passkeys and prompted to register one at their next sign-in. If you want to control this rollout yourselves, you need to act before this date.
  • 1 February 2027 – Microsoft-provided SMS and voice authentication is switched off completely. Organisations using a customer-managed telecom provider via the Microsoft Security Store are not affected by this retirement.
  • After 1 February 2027 – Any user whose only registered MFA method is SMS or voice will be blocked at sign-in until they register a passkey. There is no exemption or opt-out from this enforcement.

What this means for your business

If none of your users currently rely on SMS or voice for MFA, no action is required. But for most organisations that have been using Microsoft 365 for a while, at least some users, particularly those who joined before Authenticator app policies were tightened, are still on SMS or voice codes.

Left unmanaged, this change becomes a helpdesk problem: users locked out mid-morning, unable to sign in until they self-register a passkey through an unfamiliar prompt. Managed proactively, it is a straightforward security upgrade.

Recommended steps

  1. Audit your tenant. Identify exactly which users are currently enabled for SMS or voice authentication in your Authentication Methods Policy.
  2. Roll out passkeys on your own timeline. Enable passkey registration and run a structured adoption campaign well ahead of the September 2026 auto-enablement, so your team controls the rollout rather than reacting to it.
  3. Communicate clearly. Let affected staff know what is changing, why, and exactly what they need to do, ideally with a short walkthrough rather than a generic Microsoft prompt.
  4. Assess whether SMS/voice is genuinely still needed. A small number of organisations have a regulatory or operational reason to retain SMS or voice MFA. For those cases, a customer-managed telecom provider can be configured through the Microsoft Security Store, with provider options published from 18 September 2026 and configuration available from 30 October 2026.

What we do

This is exactly the kind of change we handle for our managed clients as standard: identifying affected users, planning a phased passkey rollout, and communicating the change so nobody gets caught out by a blocking prompt. If you manage your own Microsoft 365 tenant and want a second opinion on your authentication posture, or you would simply rather this was handled for you, get in touch.

Acting before September 2026 means this is a planned security improvement on your terms. Waiting until February 2027 means it becomes an emergency.

How System Force IT can help

System Force IT provides fully managed IT support and cyber security for businesses across Gloucestershire and the UK, backed by UKAS ISO/IEC 27001 certification. If you would like help with any of the above, our managed IT support team is here for you. Get in touch or call 01452 701355 for a no-obligation chat.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name