Insights & News
Microsoft Is Retiring SMS and Voice MFA: What to Do Before February 2027
- September 2, 2026
Microsoft is retiring its own SMS and voice call authentication in Microsoft Entra ID on 1 February 2027. From 1 September 2026, users who rely on text message or phone call codes are being automatically enabled for passkeys and prompted to register one when they sign in. If a staff member has SMS or voice as their only registered method when the retirement date arrives, they can be stopped at sign-in until they set up something else. Microsoft published this as administrative notice MC1426371 on 13 July 2026, with no fanfare, which is why many businesses have not heard about it.
Key facts
- 1 September 2026: users enabled for SMS or voice authentication are automatically enabled for passkeys and start receiving prompts to register one during MFA sign-ins.
- 1 February 2027: Microsoft-provided SMS and voice authentication is retired in Microsoft Entra ID.
- There is no opt-out of the retirement itself. Businesses with a legitimate regulatory, accessibility or operational need can contract a customer-managed telecommunications provider through the Microsoft Security Store, paid separately.
- Supported replacements include Microsoft Authenticator push approval, passkeys, FIDO2 security keys, Windows Hello for Business, certificate-based authentication and OATH hardware tokens.
- Nothing is deleted. Accounts and data are untouched. The consequence of doing nothing is users being blocked at sign-in, not data loss.
- This applies to Entra ID work and school accounts, which is what your Microsoft 365 business tenant uses.
Why is Microsoft removing it?
Because SMS and voice are the weakest methods still in common use, and Microsoft has spent several years steering customers away from them. A code read off a screen can be handed to a phishing site, and modern phishing kits relay it to the real sign-in within its validity window, so the second factor is defeated in real time. SIM swapping is the other route, where an attacker persuades a carrier to move the number to a device they control. Neither attack needs technical sophistication.
The direction of travel is towards methods where there is no code to hand over. A passkey is bound cryptographically to the legitimate domain, so a convincing fake login page cannot trigger it. That is a different category of protection rather than a stronger version of the same thing, which is why Microsoft is willing to remove a method that a lot of people still use.
Who in your business is affected?
Anyone whose registered MFA method is a text message or a phone call. In most Australian SMEs that is a minority of staff, but it is rarely nobody, and the people on it are often the ones least comfortable with change: staff without a work smartphone, people who declined to install the Authenticator app on a personal device, field or warehouse staff, and occasionally a director who set it up that way years ago and was never moved.
It is worth checking rather than assuming. Entra ID reports which authentication methods each user has registered, so you can produce a list of everyone who has SMS or voice and nothing else. That list is your actual exposure, and it is usually shorter than people fear and never empty. The users to prioritise are those with a single registered method, because they are the ones who get locked out rather than merely inconvenienced.
What should you move people to?
For most staff, Microsoft Authenticator with number matching is the straightforward answer. It is free, it works on iOS and Android, and number matching stops the accidental approval problem where someone taps yes to a prompt they did not trigger. If a member of staff will not install an app on a personal phone, that is a conversation about providing a work device or issuing a hardware token rather than a reason to keep SMS.
For administrators, finance staff and anyone who can move money, go further and use a phishing-resistant method: a passkey, a FIDO2 security key, or Windows Hello for Business on a managed device. Those accounts are the ones worth the extra effort. For the genuine edge cases, staff with no smartphone at all or an accessibility requirement, OATH hardware tokens are a small physical device that generates codes, and certificate-based authentication is an option in more structured environments.
Register a second method for everyone while you are doing this. A single method means a lost or replaced phone becomes an administrator problem, and the shortcut people reach for at that point is weakening the control to get someone working. See passkeys versus passwords for how passkeys work, and Microsoft 365 MFA setup for the configuration side.
What happens if you do nothing?
Between now and February 2027, affected users get increasingly insistent prompts to register a passkey during sign-in. That is the part worth managing, because an unexplained security prompt that appears mid-task is exactly what trains people either to click through without reading or to ring you in a panic. Both outcomes are avoidable with a short heads-up email.
After 1 February 2027, a user whose only registered method was SMS or voice can be required to register a supported method before they get in. If they are travelling, in front of a client, or without the right device to hand, that becomes a support call at the worst moment. The whole point of doing this early is that the migration happens on your schedule rather than Microsoft's, in a quiet week, with someone available to help. See multi-factor authentication for how we manage this as an ongoing control.
Frequently asked questions
Can we keep using SMS for MFA after February 2027?
Not through Microsoft. The retirement of Microsoft-provided SMS and voice delivery has no opt-out. Organisations with a legitimate regulatory, accessibility or operational requirement can contract a supported third-party telecommunications provider through the Microsoft Security Store, configured by an administrator and paid for separately at the provider's rates. For most Australian SMEs that is more cost and complexity than moving the affected users to the Authenticator app or a hardware token, so it is worth treating as a real exception rather than a default.
Does this mean everyone has to use passkeys?
No. Passkeys are what Microsoft is nudging people towards and they are the strongest option, but they are not the only supported method. Microsoft Authenticator push approval, FIDO2 security keys, Windows Hello for Business, certificate-based authentication and OATH hardware tokens all remain available. The requirement is simply that a user has at least one supported method registered that is not SMS or voice.
Will our staff be locked out of their accounts?
Accounts are not being disabled and no data is being removed. The risk is a sign-in interruption: a user whose only registered method is SMS or voice can be required to set up a supported method before continuing. With a second method already registered, there is nothing to notice. That is why the useful work now is identifying who has only one method and fixing those users first.
How do we find out who is still on SMS or voice?
Entra ID reports the authentication methods registered per user, so an administrator can produce a list of everyone using SMS or voice and, more importantly, everyone for whom it is their only registered method. That second list is the priority. We run this report for clients as part of managing MFA, along with the follow-up to get people moved across before the prompts start arriving unannounced.
If you are not sure who in your business still relies on text message codes, we can run the report, move the affected staff onto a supported method, and give them a heads-up so the prompts are expected rather than alarming. Request a callback and we will sort it before February.
About the author
Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on cybersecurity, including Microsoft 365 hardening, multi-factor authentication and passwordless sign-in, identity and access management, and the Essential Eight, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.
Recent Posts
-
Microsoft Is Retiring SMS and Voice MFA: What to Do Before February 2027 -
Choosing a Password Manager for Small Business -
Passkeys vs Passwords: What Businesses Need to Know -
Password Policy for Australian Small Business -
How to Share Passwords Securely With Staff -
What Is Veeam, and Why 4iT Uses It for Backup -
Sophos Intercept X and MDR: Endpoint Protection That Fights Back -
Sophos Firewall for Business: What It Does and Why It Matters -
Microsoft 365 Backup: Why Your Data Is Not as Safe as You Think -
What Is a Cyber Security Audit? A Guide for Australian SMEs







