MBPS Blog

Microsoft Entra SMS Retirement: Move to Passkeys Before 2027

If your team signs in to Microsoft 365 by typing a code from a text message, that method is going away. Microsoft is retiring its own SMS and voice authentication in Entra ID on February 1, 2027, and passkeys become the default sign in experience starting September 1, 2026. Here is what changes, when it changes, and what to do about it.

Business professional typing on a laptop showing a passkey sign in prompt at an office desk

By Alex Wolfram

The Microsoft Entra SMS retirement is the biggest change to everyday sign in that most Microsoft 365 customers will see this decade, and it comes with a hard deadline. Microsoft will stop delivering its own text message and phone call passcodes in Entra ID on February 1, 2027. Before that, on September 1, 2026, passkeys become the default authentication experience for anyone currently using SMS or voice. If a single person in your company verifies a login with a text, this lands on your desk.

The workable news is that you have time, and most of the effort is planning and communication rather than a technical lift. Companies that start now will move people over on their own schedule. Companies that wait will have staff hitting a blocking prompt on a Monday morning with a customer on the phone.

What Microsoft actually announced

Microsoft notified every Entra ID tenant that passkeys are becoming the default authentication method and that Microsoft provided SMS and voice delivery is being retired. Two separate things are changing here, and it helps to keep them apart.

  • Passkeys become the default. Users who are enabled today for SMS or voice will be automatically enabled for passkeys and nudged to register one the next time they complete multifactor authentication.
  • Microsoft stops sending the texts and calls. The telecom delivery behind SMS and voice codes goes away. Organizations that already route those messages through a customer managed telecom provider configured in the Microsoft Security Store are not affected.

Nothing else about your multifactor setup changes. Microsoft Authenticator push approvals, authenticator app codes, Windows Hello for Business, and FIDO2 security keys all keep working the way they do today. If your users are already on the Authenticator app, you are in good shape.

The dates that matter

There are four dates worth putting on a calendar right now.

  • September 1, 2026. Users enabled for SMS or voice are automatically enabled for passkeys and prompted to register one when they next complete MFA. If you do not want that automatic nudge, you need to move those users out of SMS and voice in the Authentication Methods Policy before this date.
  • September 18, 2026. Microsoft publishes the list of customer managed telecom providers, along with pricing, in the Microsoft Security Store.
  • October 30, 2026. You can select and configure one of those telecom providers.
  • February 1, 2027. Microsoft provided SMS and voice are fully retired. From this point, any user whose only available MFA method is SMS or voice gets a blocking prompt to register a passkey before they can finish signing in. Microsoft has stated there is no opt out, and it applies to all tenants.

That last point is the one to underline. This is not a recommendation with a grace period. After February 1, 2027, an employee with nothing but a phone number on their account cannot get into their email until they register a passkey.

Why Microsoft is dropping SMS and voice

SMS and voice are the weakest multifactor methods still in common use. They were a huge improvement over passwords alone, and for years they were the practical way to get MFA onto every employee. That tradeoff no longer holds up.

Three attack patterns break them. SIM swapping lets an attacker convince a mobile carrier to move a phone number to a device they control, at which point every code goes to them. Adversary in the middle phishing sites relay the code in real time, so the victim types a valid code into a fake page and the attacker uses it seconds later on the real one. And malware on a phone can read incoming messages directly.

Passkeys close all three. A passkey is a cryptographic credential tied to the specific website or application it was created for. There is no code to read, relay, or repeat, and the credential simply will not work on a lookalike domain. That property is why the Cybersecurity and Infrastructure Security Agency has recommended phishing resistant MFA over SMS for several years. Microsoft is simply making the recommended path the default one.

Who this affects in your business

Before you plan anything, find out how exposed you actually are. In most small and mid sized companies, the people still on SMS fall into a few predictable groups.

  • Long tenured staff who set up MFA years ago with a phone number and were never asked to change.
  • Field and shop floor workers who use a personal phone and never installed the Authenticator app.
  • Executives and owners who opted out of app installs during rollout.
  • Shared, kiosk, and frontline accounts tied to a company mobile number.
  • Vendors, contractors, and seasonal staff added to the tenant in a hurry.

That last group is where most surprises live. Guest and contractor accounts rarely appear in an MFA rollout project and often sit on the oldest configuration in the tenant.

What to do about the Microsoft Entra SMS retirement

Five steps, in order. None of them require downtime, and the first three can be done in an afternoon in a small tenant.

Step 1: Find out who is still on SMS or voice

Start with a real list, not an estimate. Microsoft has published a usage analyzer script for exactly this purpose, and the Entra admin center also reports registered authentication methods per user. Export the list, then sort it by department so you know who you are actually talking to. Pay particular attention to accounts where SMS or voice is the only registered method, because those are the accounts that will be blocked in February 2027.

Step 2: Turn on passkeys and choose the right kind

Passkeys come in two flavors, and the choice matters more than most guides admit. Synced passkeys live in a password manager such as iCloud Keychain or Google Password Manager and follow the user across their devices, which makes recovery easy. Device bound passkeys live on one specific device, through Windows Hello for Business, Microsoft Authenticator, or a physical FIDO2 security key, and cannot be copied off it.

For most offices, Windows Hello for Business on company laptops plus Microsoft Authenticator on phones covers nearly everyone. Reserve hardware security keys for administrators, finance staff, and anyone with access to banking or payroll. If you have shared workstations or people without a company device, hardware keys are usually the cleanest answer there too.

Step 3: Run a registration campaign before September 1, 2026

Entra ID includes a registration campaign feature that prompts users to set up a stronger method during sign in. Turning it on and targeting a security group of your SMS and voice users gets most of the migration done quietly, without a help desk ticket per person. Running it before September 1, 2026 means the change happens on your timeline instead of Microsoft automatic enablement.

Step 4: Tell your people what is changing

This is the step companies skip, and it is the one that decides how many calls your help desk takes. Send three messages: an awareness note now explaining what a passkey is and why it is safer, an action note when the registration campaign turns on, and a reminder before the February deadline. Keep each one short and show a screenshot of the actual prompt they will see. People approve prompts they recognize and call for help about prompts they do not.

Step 5: Only evaluate a telecom provider if you truly need one

If you work under a compliance regime that specifically requires an out of band SMS channel, or you have a genuine operational scenario where nothing else works, you can keep SMS by configuring a customer managed telecom provider through the Microsoft Security Store once options appear on September 18, 2026. That is a narrow case. For most businesses, adding a paid telecom provider to preserve the weakest authentication method is spending money to stay less secure.

What happens if you do nothing

Nothing at all until September 1, 2026. Then your SMS users start seeing passkey registration prompts they were not warned about, and some of them will call you or dismiss the prompt repeatedly. After February 1, 2027, anyone still holding only a phone number gets a blocking prompt and cannot reach email, Teams, or files until they complete registration. If that lands during a busy week, you are doing emergency identity work instead of your job.

There is also a quieter cost. Every month you leave SMS in place is a month a SIM swap or a relay attack can take an account. We have seen how quickly one compromised mailbox turns into a wire fraud attempt, and this is the same door that a phishing attack walks through. Removing SMS closes it.

Your checklist

  • Export the list of users with SMS or voice registered, flag anyone with no other method.
  • Enable passkeys in the Authentication Methods Policy.
  • Decide the standard for laptops, phones, and privileged accounts.
  • Order hardware security keys for admins, finance, and shared workstations.
  • Turn on a registration campaign targeting your SMS and voice group.
  • Send the awareness message, then the action message, then the reminder.
  • Re run the report in October 2026 and again in December to catch stragglers.
  • Decide by October 30, 2026 whether any user segment genuinely needs a telecom provider.

Handled well, this is a scheduling and communication project. Handled late, it is an outage. If you would rather not own the reporting, the policy changes, and the user hand holding, that is exactly the kind of work we take off your plate. Call MBPS at (888) 656-MBPS or request a free assessment and we will tell you where your tenant stands before September.

Frequently asked questions

Does the Microsoft Entra SMS retirement affect Microsoft Authenticator?

No. Authenticator push approvals and time based codes in the app are unaffected and continue to work. Only Microsoft provided SMS text messages and voice calls are being retired. If your users already approve sign ins in the Authenticator app, no action is needed for them.

What is a passkey, in plain terms?

A passkey is a login credential stored on your device or in your password manager that you unlock with a fingerprint, a face scan, or a PIN. Instead of sending a code that anyone could intercept, your device proves who you are directly to the site. Because the credential is tied to the real site, a fake login page cannot use it.

What about employees who do not have a smartphone?

Give them a FIDO2 hardware security key. It is a small USB or NFC device, costs roughly the price of a nice lunch, and requires no phone, no app, and no cell signal. This is also the right answer for shared workstations, warehouse terminals, and anyone who does not want work software on a personal device.

Can we keep SMS after February 1, 2027?

Only by configuring a customer managed telecom provider through the Microsoft Security Store, which becomes available to select on October 30, 2026. Microsoft will not deliver the messages itself after February 1, 2027, and there is no opt out from the blocking prompt for users who have no other method. For nearly every business, migrating is cheaper and safer than keeping SMS alive.

How long does the migration usually take?

For a company of 25 to 100 people, expect a few hours of configuration and reporting, then four to six weeks of registration campaign running in the background while people get prompted during normal sign ins. The calendar time comes from user adoption, not from the technical work. Starting before September 1, 2026 gives you that runway without pressure. Pairing it with a broader zero trust approach makes the effort go further.

Check our other posts

Talk to an IT team that answers

Phoenix and Las Vegas businesses trust MBPS for fast, predictable IT support.