MS-Authenticator

Microsoft Is Retiring Text and Phone-Call MFA Codes: What Microsoft 365 Users Need to Know

If you currently receive a text message or automated phone call when signing into Microsoft 365, your sign-in process is about to change.  Microsoft is moving away from SMS text messages and voice calls as built-in multi-factor authentication (MFA) methods and making passkeys the preferred sign-in method. The transition begins September 1, 2026, with Microsoft-provided SMS and voice authentication scheduled to retire on February 1, 2027.

For businesses using Microsoft 365, now is the time to make the change rather than waiting until an employee is unable to sign in.

Why Is Microsoft Making This Change?

Multi-factor authentication adds an important layer of protection to your Microsoft 365 account, but not every MFA method offers the same level of security.  Text messages and automated phone calls have helped improve account security for years, but they still rely on the cellular telephone network. That creates vulnerabilities attackers can exploit through methods such as phishing, SIM-swapping, and the interception or redirection of authentication codes.

Microsoft is moving users toward phishing-resistant authentication methods, particularly passkeys.  Unlike a six-digit code that can potentially be copied, intercepted, or given to someone through a convincing phishing attack, a passkey uses cryptographic credentials associated with your device or secure credential provider. Microsoft specifically describes passkeys as resistant to phishing, SIM-swap, and replay attacks.  For many users, Microsoft Authenticator will provide the easiest path to using a passkey, but other Authenticators like Google Authenticator will also be an option if you already have another secure Authenticator App of choice.

Important Dates for Microsoft 365 Users

September 1, 2026

Microsoft will begin automatically enabling passkey registration for users who currently have SMS or voice authentication enabled.  After completing MFA during sign-in, affected users may begin seeing prompts encouraging them to register a passkey. Microsoft will make its passkey registration campaign the default for these users.

You do not need to wait for that prompt. Setting up your new authentication method ahead of time can help prevent problems later.

February 1, 2027

Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID.  Organizations relying on Microsoft's built-in text message or automated calling service will need to have their users moved to another authentication method before this date.  Microsoft recommends phishing-resistant options such as passkeys, Windows Hello, and FIDO2 security keys.

After February 1, 2027

If SMS or voice is your only available MFA method and your organization has not configured another supported option, Microsoft will require you to register a passkey before you can continue signing in. Unlike the earlier registration reminders, this prompt will be blocking. You will need to complete registration before accessing your account.

What Should You Do Now?

The easiest way to avoid an interruption is to update your authentication method before the deadline.

If your organization has directed you to use Microsoft Authenticator:

  1. Install or open the Microsoft Authenticator app on your smartphone.
  2. Follow the instructions in our How to Register for MFA guide.
  3. Complete the registration process and confirm that your new authentication method works.

For most users, setup takes only a few minutes.

There is no benefit to waiting until February. Completing the change now means you can verify everything works while your existing authentication method is still available.

What If I Don't Know Which MFA Method I Use?

If Microsoft sends a numeric code to your phone by text message when you sign in, you are using SMS authentication.  If Microsoft calls your telephone and asks you to approve the sign-in, you are using voice authentication.

If you aren't sure, don't guess. ComSolutions can help determine which authentication methods are registered to your account and help you make the transition.

ComSolutions Can Help You Prepare

Authentication changes can seem minor until they prevent someone from accessing Outlook, Teams, SharePoint, OneDrive, or another system they need to work.  ComSolutions can help your organization identify users who are still relying on SMS or phone-call authentication, prepare Microsoft 365 for the transition, register supported authentication methods, and assist employees who have trouble completing setup.  If you're a ComSolutions client and have questions about the upcoming change, contact our support team for assistance.  Making the switch now takes only a few minutes and can prevent a much bigger interruption later.