That six-digit code you receive by text message when signing into Microsoft 365 feels secure because it arrives instantly. But SMS-based MFA is no longer considered a strong security method.
Attackers can bypass SMS MFA through phishing websites, SIM swapping, or intercepting text messages. It is still better than having no MFA at all, but it is much weaker than modern options like passkeys.
Microsoft has announced that it will stop providing SMS and voice-based MFA services from 1 February 2027.
Before that, Microsoft plans to start introducing passkey-related changes and user prompts from 1 September 2026.
For IT teams and MSPs, this means the time to prepare is now. Waiting until 2027 could result in confused users, increased support calls, and rushed security changes.
Why is Microsoft removing SMS MFA?
SMS MFA works by sending a one-time code to a user’s phone.
The problem is that the code itself is the security factor. If an attacker can trick a user into entering that code on a fake Microsoft login page, the attacker can sign in.
Other risks include:
- Phishing attacks where users enter their SMS code into fake websites
- SIM swapping where attackers move a user’s phone number to another SIM card
- Mobile network interception
Microsoft wants organisations to move towards stronger authentication methods that cannot easily be stolen.
What is replacing SMS MFA?
Microsoft is pushing users towards passkeys and other phishing-resistant authentication methods.
A passkey works differently from a password or SMS code.
Instead of proving your identity with something you know or something sent to your phone, the device creates a secure cryptographic key that proves you are signing into the real Microsoft service.
Even if a user clicks a fake phishing link, the passkey cannot be stolen and reused.
Examples of passkey storage include:
- Windows Hello
- Security keys such as YubiKeys
- Password manager apps
- Apple or Google password managers
Important dates to remember
1 September 2026
Microsoft expects to start enabling passkey-related changes and prompts.
Users may begin seeing requests to register stronger authentication methods.
1 February 2027
Microsoft will stop providing free SMS and voice MFA services.
Organisations that still require SMS or voice authentication will need to use third-party providers, which may involve additional costs.
How should IT teams prepare?
The first step is knowing who is still using SMS MFA.
Do not assume everyone is protected because they have Microsoft Authenticator installed.
Many users may have:
- Microsoft Authenticator configured
- But still have SMS enabled as a backup method
Those phone numbers still need to be reviewed.
Step 1: Check your current authentication methods
In Microsoft Entra admin centre:
Go to:
Protection → Authentication Methods
Review which users have:
- SMS
- Mobile phone
- Alternate phone
- Microsoft Authenticator
- Windows Hello
- Passkeys
Create a list of users who still rely on phone-based authentication.
Step 2: Check older MFA settings
Some organisations still have older per-user MFA configurations.
Review the legacy MFA portal and confirm whether SMS or voice authentication is still enabled.
Microsoft has been moving customers away from this older system, but some tenants may still have old settings remaining.
Step 3: Decide your passkey approach
Before enabling passkeys for everyone, decide what works best for your organisation.
You generally have two options:
Synced passkeys
Stored through services like:
- Apple iCloud Keychain
- Google Password Manager
- Password manager applications
Advantages:
- Easier for users
- Works across multiple devices
- Faster rollout
Disadvantage:
- The organisation has less control over where the passkey is stored
Device-bound passkeys
Stored on specific hardware such as:
- Company laptops
- Security keys
Advantages:
- Higher security
- Better control
- Suitable for privileged accounts
Disadvantage:
- More management overhead
Most small businesses will likely prefer easier adoption, while high-security environments may choose hardware-based passkeys.
Step 4: Run a passkey registration campaign
Simply enabling passkeys does not mean users are automatically protected.
Users still need to register their passkey.
Microsoft Entra provides a Registration Campaign that can prompt users to complete setup.
A good rollout approach:
- Enable passkeys for a pilot group
- Test the sign-in experience
- Fix issues
- Expand to more users
- Remove old SMS methods
Avoid forcing the whole company on day one.
Step 5: Prepare your users and helpdesk
Technology changes often fail because users are not prepared.
Before rollout:
- Explain why SMS MFA is changing
- Show users what the real Microsoft prompt looks like
- Provide setup instructions
- Explain what happens if they lose their phone
- Train the helpdesk team
Support teams should know how to handle:
- Lost devices
- New phones
- Temporary access
- Recovery requests
- Exceptions
Should you disable SMS immediately?
Not necessarily.
Microsoft is giving organisations time to prepare.
You can postpone automatic changes while you complete your migration, but delaying the project does not solve the problem.
The goal should be:
- Find users using SMS MFA
- Enable passkeys
- Register users
- Remove old phone authentication methods
Final thoughts
Microsoft is not removing MFA. It is removing a weaker MFA method.
SMS authentication helped organisations move away from passwords alone, but attackers have adapted.
The future is moving towards phishing-resistant authentication such as passkeys.
For IT teams and MSPs, the message is simple:
Do not wait until February 2027. Start identifying SMS users now, plan your rollout, and move users to passkeys before Microsoft forces the change.
The earlier you start, the smoother the transition will be.
Leave a comment