Organizations Still Relying on SMS MFA Face a Forced Move to Passkeys

What begins as a passkey registration prompt in 2026 could eventually become a sign-in roadblock for organizations that delay moving users away from SMS and voice authentication.

Cloud Computing

Key Takeaways:

  • Microsoft will begin retiring its native SMS and voice MFA services in 2027.
  • Passkeys will become the default authentication experience for affected users starting in September 2026.
  • Organizations that fail to migrate users could encounter mandatory passkey enrollment requirements during sign-in.

Microsoft is preparing a major shift in its authentication strategy by retiring its native SMS and voice-based multifactor authentication (MFA) services in Microsoft Entra ID. The company argues that traditional phone-based verification methods are increasingly vulnerable to phishing, SIM-swapping, and other social engineering attacks, which makes phishing-resistant authentication methods a better fit for modern security requirements.

This change is part of Microsoft’s broader effort to make passkeys the default sign-in experience for Microsoft Entra ID customers. Passkeys rely on cryptographic credentials stored on trusted devices or credential managers rather than shared secrets such as passwords or one-time codes. According to Microsoft, this approach provides stronger protection against account compromise while simplifying the user experience.

Passkeys become the default sign-in experience

Starting on September 1, 2026, Microsoft will automatically enable passkey support for users who currently rely on SMS or voice authentication. These users will start receiving prompts encouraging them to register a passkey after completing MFA sign-ins. Organizations are expected to prepare users for the transition and begin deploying phishing-resistant authentication methods ahead of the enforcement deadlines.

Microsoft supports both synced passkeys, which can be stored in services such as platform credential managers and synchronized across devices, and device-bound passkeys stored locally on hardware security keys, Microsoft Authenticator, or Windows devices.

Microsoft to retire native SMS and voice Authentication

The retirement will occur gradually in phases. For most users, Microsoft-provided SMS and voice authentication services will stop working on February 1, 2027. Global Administrators and external users will receive a temporary extension until July 1, 2027. Internal guest users remain subject to the February deadline.

After the retirement date, users whose only MFA option is SMS or voice authentication will encounter a mandatory passkey registration process during sign-in. Microsoft says this enforcement cannot be bypassed, which means affected users must register a passkey before they can continue accessing their accounts.

Microsoft is not eliminating phone-based authentication entirely. Instead, the company is ending its own telecom delivery service. Organizations with regulatory, compliance, or operational requirements that still depend on SMS or voice authentication will be able to select a customer-managed telecom provider through the Microsoft Security Store. This option is expected to become available later this year.

How IT teams should prepare for the migration

Microsoft recommends that administrators identify users who still rely on SMS and voice authentication and begin migrating them to more secure alternatives such as passkeys, Windows Hello for Business, or FIDO2 security keys. The company has published tools, such as a PowerShell script, to help organizations locate affected users and plan their migration strategy.

Microsoft also encourages organizations to launch passkey registration campaigns and communicate upcoming changes well before enforcement deadlines. Keep in mind that early adoption can reduce help desk workloads and minimize the risk of user lockouts.