If you’ve been following Microsoft’s identity roadmap over the past few years, this latest announcement shouldn’t come as a surprise. Microsoft has been steadily moving organizations away from passwords and weaker authentication methods toward a passwordless future built around phishing-resistant authentication. We’ve seen Windows Hello for Business, FIDO2 security keys, Microsoft Authenticator, Temporary Access Pass, Authentication Strengths, passkeys, and countless improvements to Conditional Access. Each release has been another step in the same direction.
The latest announcement continues that journey.
Microsoft has confirmed that its SMS and voice authentication services for Microsoft Entra ID will be retired, with passkeys becoming the preferred authentication method for users.
This isn’t simply a feature retirement buried in the release notes. For many organizations, especially those with large user populations that still rely on phone-based MFA, this is a change that should begin to influence identity planning today.
Why Is Microsoft Making This Change?
SMS and voice authentication were a huge improvement over passwords when Multi-Factor Authentication first became mainstream. They raised the bar considerably and helped prevent countless account compromises. However, the threat landscape has changed significantly over the past decade.
Attackers have become increasingly effective at bypassing phone-based authentication through techniques such as:
- SIM swapping
- Social engineering
- Phone number hijacking
- SS7 network attacks
- Real-time phishing proxy attacks
While SMS still provides better protection than passwords alone, it is no longer considered a phishing-resistant authentication method. Microsoft, along with much of the security industry, has been encouraging organizations to adopt authentication methods that eliminate these weaknesses entirely rather than mitigate them.
Passkeys, FIDO2 security keys, and Windows Hello for Business all provide authentication methods that are significantly more resistant to phishing attacks and improve the user experience once users become familiar with them.
What Is Actually Changing?
There are really two separate announcements that administrators should understand.
The first is that passkeys will become the default registration experience for eligible users. Starting on September 1, 2026, Microsoft-managed registration campaigns will prompt users to register passkeys during sign-in. Initially, users will still have the option to skip registration, but the direction is clear. Microsoft wants passkeys to become the primary authentication method across Entra ID.
The second, and arguably more significant, change is that Microsoft will retire its own SMS and voice authentication infrastructure on February 1, 2027.
After that date:
- Microsoft will no longer provide SMS authentication services.
- Microsoft will no longer provide voice call authentication services.
- Organizations that wish to continue using phone-based authentication will need to configure a supported telecom provider through the Microsoft Security Store.
- Organizations that take no action risk authentication failures for users who continue relying on Microsoft-hosted SMS or voice authentication.
That distinction is important because many people have interpreted the announcement as Microsoft eliminating SMS authentication entirely. That isn’t the case.
Is SMS Authentication Going Away?
No.
SMS authentication itself is not being removed from Microsoft Entra ID. Instead, Microsoft is retiring its own hosted SMS and voice delivery service. Organizations that still require SMS authentication can continue using it by integrating with a supported third-party telecom provider.
This approach shifts responsibility for message delivery away from Microsoft while still allowing organizations to support scenarios where SMS remains necessary.
For many organizations, that will be a perfectly reasonable solution. Others may take this opportunity to accelerate their move toward passwordless authentication and eliminate SMS altogether.
Why Some Organizations Will Still Need SMS
Although security professionals often recommend moving entirely to phishing-resistant authentication, real-world environments are rarely that straightforward.
Many organizations still have users who fall into categories such as:
- Frontline workers
- Manufacturing employees
- Retail staff
- Healthcare workers
- Contractors
- Seasonal employees
- BYOD-only users
- Shared device users
These users may not have managed devices or may not be able to register passkeys immediately. SMS continues to provide an acceptable level of security for many of these scenarios, particularly when balanced against operational realities.
The goal of Microsoft’s announcement is not to eliminate flexibility. Instead, it is to make stronger authentication methods the default while allowing organizations to continue supporting phone-based authentication where business requirements justify it.
This Fits Microsoft’s Long-Term Identity Strategy
When viewed in isolation, this announcement might appear to be a retirement notice for an older authentication method. In reality, it fits into a much broader strategy that Microsoft has been executing for several years.
Recent investments across Microsoft Entra ID include:
- Passkeys
- FIDO2 security keys
- Windows Hello for Business
- Temporary Access Pass
- Authentication Strengths
- Passwordless authentication
- Microsoft Authenticator enhancements
- Improved registration campaigns
- Continuous Conditional Access improvements
None of these features were introduced independently. Together, they represent Microsoft’s long-term vision of reducing reliance on passwords, shared secrets, and authentication methods that attackers can intercept or socially engineer.
If anything, this latest announcement reinforces that passwordless authentication is no longer a future goal—it is becoming the expected standard.
What Should Administrators Be Doing Now?
Although the retirement date is still several months away, this isn’t something that should be left until the last minute. Organizations with thousands of users can easily spend months planning, communicating, testing, and rolling out authentication changes.
The first priority should be understanding your current environment. Review authentication registration reports, sign-in logs, and authentication methods to determine how many users are still relying on SMS or voice authentication. Many organizations discover that their adoption of Microsoft Authenticator or passkeys is much lower than expected.
Next, begin encouraging users to adopt stronger authentication methods before Microsoft automatically prompts them. Internal communication, documentation, and user education will make the eventual transition significantly smoother.
Organizations should also determine whether SMS authentication will remain a business requirement after February 2027. If the answer is yes, now is the time to begin evaluating supported telecom providers and understanding the operational changes that will be required.
Finally, review existing Conditional Access policies and authentication strategies. Many organizations still have policies that effectively treat SMS as a primary authentication method. This announcement provides a good opportunity to modernize those policies and place phishing-resistant authentication methods at the center of your identity strategy.
My Thoughts
I think this is another sensible step in Microsoft’s overall identity strategy. SMS and voice authentication served the industry incredibly well, dramatically improving account security compared to passwords alone. However, attackers have adapted. SIM swapping, phishing proxies, and social engineering have all demonstrated that phone-based authentication is no longer sufficient as the default authentication experience for modern organizations.
That doesn’t mean SMS no longer has a place. There will continue to be environments where operational requirements make phone-based authentication necessary, and Microsoft has recognized that by continuing to support SMS through third-party providers. What is changing is Microsoft’s expectation that organizations move toward stronger, phishing-resistant authentication wherever possible.
For IT administrators, the most important takeaway isn’t the retirement date itself. It’s recognizing that this announcement is another signal that passwordless authentication is no longer an emerging technology—it’s becoming the foundation of Microsoft’s identity platform.
Organizations that start planning now will have a much smoother transition than those that wait until users begin encountering authentication issues in 2027.