Service Advisory – Microsoft Is Retiring SMS and Voice Call Authentication
Aug 19, 2026
Microsoft is shutting down SMS text codes and automated voice calls as a way to verify sign-ins across Microsoft 365 and Azure (Entra ID). The transition starts September 1, 2026 — about two weeks from now — and Microsoft-provided SMS/voice authentication stops working entirely on February 1, 2027. If your organization uses text or phone codes for multi-factor authentication (MFA) or password resets, your users will be moved to passkeys, and you have a narrow window to control how that happens on your own terms rather than Microsoft’s.
Key Dates
September 1, 2026 — Passkeys become Microsoft’s default authentication method. Any user currently set up for SMS or voice codes is automatically enrolled for passkeys and begins seeing registration prompts at sign-in.
September 18, 2026 — Microsoft publishes its list of approved third-party telecom providers in the Microsoft Security Store, for organizations that need to keep SMS/voice for business or regulatory reasons.
October 30, 2026 — Organizations can begin contracting directly with those approved providers to keep SMS/voice running past the cutoff. This carries an ongoing per-message cost; migrating to passkeys does not.
February 1, 2027 — Hard deadline. Microsoft-provided SMS and voice authentication is fully retired. Any user whose only MFA method is SMS or voice hits a mandatory, non-skippable prompt to register a passkey before they can sign in — no opt-out, no grace period.
Who’s Affected
This applies to every Microsoft Entra ID tenant (Microsoft 365 and Azure, commercial/public cloud) that currently uses Microsoft-provided SMS or voice authentication for MFA or self-service password reset. It does not apply to Azure AD B2C tenants or Microsoft Entra External ID (Microsoft has said those will get a separate announcement later) or to government/non-public-cloud environments, which are on a different timeline. If none of your users rely on SMS or voice codes today, this advisory doesn’t require action from you — though it’s worth confirming that with a quick check (see step 1 below).
Why This Matters
Microsoft isn’t retiring SMS and voice authentication as routine housekeeping — it’s a direct response to how weak these methods have become as a defense. SMS and voice codes can be intercepted through SIM-swap attacks, redirected through social engineering against carriers, or phished with fake login pages, and attackers have gotten faster and more automated at all three. Passkeys close that gap by design: they’re tied to a physical device or secure credential store (Windows Hello, Microsoft Authenticator, a FIDO2 key, or a phone’s built-in passkey manager) and can’t be intercepted or redirected the way a text message can.
The practical risk for most organizations isn’t the retirement itself — it’s letting it happen passively. Users auto-enrolled into passkeys on September 1 will encounter registration prompts with no context, which typically shows up as a spike in help desk tickets rather than a smooth transition.
What You Need to Do
Check your exposure now. Microsoft publishes a PowerShell script (the entra-sms-voice-usage-analyzer, on GitHub) that identifies exactly which users in your tenant are enrolled in SMS or voice authentication. Run it before September 1 so you know your real numbers, not an estimate.
Choose your path. For nearly all organizations, migrating to passkeys is the right call — it’s free, it’s more secure, and it’s where Microsoft is pushing everyone regardless. Keeping SMS/voice alive through a third-party provider (available October 30, 2026) should be reserved for a genuine, documented regulatory or operational need, since it comes with an ongoing per-message cost.
Roll out passkeys on your schedule, not Microsoft’s. Pick a method (Windows Hello, Microsoft Authenticator, or a hardware security key), pilot it with a small group, and give users a real onboarding path before Microsoft’s automatic enrollment reaches them.
Communicate before the prompts appear. A short heads-up email now, explaining what a passkey is and why it’s changing, prevents confused users from flooding your help desk in September.
Don’t wait for the February 2027 deadline expecting a grace period. There isn’t one — once it hits, any user still on SMS/voice-only is locked out of sign-in until they register a passkey. Migrating proactively is the only way to control the timing of that disruption.
Check your exposure now. Microsoft publishes a PowerShell script (the entra-sms-voice-usage-analyzer, on GitHub) that identifies exactly which users in your tenant are enrolled in SMS or voice authentication. Run it before September 1 so you know your real numbers, not an estimate.
Choose your path. For nearly all organizations, migrating to passkeys is the right call — it’s free, it’s more secure, and it’s where Microsoft is pushing everyone regardless. Keeping SMS/voice alive through a third-party provider (available October 30, 2026) should be reserved for a genuine, documented regulatory or operational need, since it comes with an ongoing per-message cost.
Roll out passkeys on your schedule, not Microsoft’s. Pick a method (Windows Hello, Microsoft Authenticator, or a hardware security key), pilot it with a small group, and give users a real onboarding path before Microsoft’s automatic enrollment reaches them.
Communicate before the prompts appear. A short heads-up email now, explaining what a passkey is and why it’s changing, prevents confused users from flooding your help desk in September.
Don’t wait for the February 2027 deadline expecting a grace period. There isn’t one — once it hits, any user still on SMS/voice-only is locked out of sign-in until they register a passkey. Migrating proactively is the only way to control the timing of that disruption.
The Bottom Line
This is a security-driven change with a real, non-negotiable deadline, and the first phase starts in a couple of weeks. Organizations that plan their passkey rollout now will control the experience for their users; organizations that don’t will have it decided for them on Microsoft’s schedule.
Not sure where your organization stands, or want help mapping out the rollout? Sign up for a free 15-minute consultation with a Navigator Networks expert, and we’ll help you get ahead of the September 1 deadline.