Microsoft is retiring its SMS and voice authentication service from 1 February 2027. If any of your employees currently receive a text message or phone call to authenticate into Microsoft 365, your business will need to move them to another authentication method or they will be left not being able to log in to their work account.
The first changes begin from 1 September 2026, so businesses should start planning now rather than waiting until SMS and voice are switched off.
For most organisations, this should be a manageable change. However, this is not simply about replacing SMS with another form of MFA.
Microsoft is moving towards phishing-resistant authentication, with passkeys becoming the default authentication experience in Microsoft Entra ID.
There are also practical decisions to make, particularly around personal mobile phones, employees who cannot use smartphones and how the change will be introduced across your business.
In this article, we'll explain:
- What Microsoft is changing and when
- What businesses should use instead
- How to choose the right authentication method
- How to manage the migration
If you are an existing customer and would like to talk through what this change means for your business, speak to your Account Manager.
If you are not currently a customer of THE HBP Group, get in touch with our team and we can talk you through the options available.
What Is Changing With Microsoft SMS and Voice MFA?
Microsoft currently allows users to authenticate into Microsoft 365 by receiving a text message or phone call.
That Microsoft-provided SMS and voice authentication service is being retired.
At the same time, Microsoft is moving affected users towards stronger authentication methods, with passkeys becoming the default experience for users currently enabled for SMS or voice.
The key dates are:
1 September 2026: Users enabled for SMS or voice will be automatically enabled for passkeys and Microsoft will begin prompting them to register a passkey when they complete MFA.
If your business does not want Microsoft to begin this process automatically, affected users need to be moved out of SMS or voice in the Authentication Methods Policy before this date.
1 February 2027: Microsoft's own SMS and voice authentication delivery will stop.
If an employee's only available MFA method is SMS or voice, Microsoft says they will receive a blocking prompt requiring them to register a passkey before they can continue signing in.
There is no opt-out from that enforcement.
If your business still uses Microsoft-provided SMS or voice authentication, action will be required before 1 February 2027.
If you need to keep SMS or voice for any reason, there is a how-to at the end of this article explaining the alternative Microsoft is making available.
Microsoft is making this change because SMS and voice are among the weaker authentication methods available. Text messages and telephone calls can be vulnerable to phishing, SIM-swap attacks, social engineering, interception and replay attacks.
Microsoft is therefore moving customers towards authentication methods that do not rely on a temporary code that somebody can potentially be tricked into providing.
For businesses, the important point is that SMS and voice should no longer be treated as the long-term authentication method for Microsoft 365. Microsoft's preferred direction is phishing-resistant authentication, with passkeys as the recommended default.
Does Microsoft Authenticator Still Have a Role?
Yes. For many businesses, Microsoft Authenticator will form part of the migration away from SMS and voice.
It can be used to store a passkey for an employee's Microsoft account, allowing them to authenticate without receiving an SMS or telephone call.
A standard Microsoft Authenticator approval and a passkey are not exactly the same thing, so the method your business chooses should form part of your wider Microsoft 365 and Entra ID authentication configuration.
Whichever method you choose, make sure every affected employee has registered and successfully tested their replacement authentication method before SMS or voice is removed.
What Should Businesses Use Instead?
There is not necessarily one authentication method that will suit every employee.
The right option depends on the devices people use, whether they can use a mobile phone for work and how your Microsoft 365 environment is configured.
For most businesses, there are three practical routes to consider:
Option 1: Passkeys Using Microsoft Authenticator (Recommended)
Best suited to employees who can use a compatible smartphone for work authentication.
A passkey stored in Microsoft Authenticator is likely to be the most straightforward option for many businesses.
Instead of receiving a temporary code, the employee authenticates securely using their device, typically with a fingerprint, facial recognition or device PIN.
Because there is no temporary code to copy or enter into a fraudulent website, passkeys are phishing-resistant.
What does the employee need?
They will need:
- A compatible iPhone or Android smartphone
- Microsoft Authenticator installed
- Their work or school Microsoft account added to Authenticator
- A passkey registered for that account
Microsoft currently states that passkeys in Microsoft Authenticator require iOS 17 or later or Android 14 or later, so employees using older phones may need another option.
How do I set it up?
Our step-by-step guide to downloading and setting up Microsoft Authenticator for Microsoft 365 explains how employees can install the app and connect their Microsoft account.
Microsoft also provides instructions showing employees how to set up a passkey in Microsoft Authenticator.
Your Microsoft 365 administrator will need to make sure passkeys are available for the appropriate users. Microsoft explains how administrators can enable passkeys in Microsoft Entra ID.
For most employees who are comfortable using a smartphone for work authentication, this is the option we would look at first.
Option 2: FIDO2 Security Keys (Where a Phone Is Not Suitable)
Best suited to employees who cannot or do not want to use a mobile phone for authentication.
A FIDO2 security key is a small physical device that normally connects to a computer using USB or communicates with a compatible device using NFC.
Instead of entering a temporary code, the employee uses the physical key to authenticate.
Microsoft describes FIDO2 security keys as device-bound passkeys, making them a phishing-resistant alternative for employees who need a separate physical authentication device.
They can be particularly useful for employees who cannot use personal phones, controlled working environments, users with elevated privileges and organisations with stronger security or regulatory requirements.
Microsoft provides administrator guidance for enabling passkeys and FIDO2 security keys, along with user guidance explaining how to register and sign in with a FIDO2 security key.
If a physical alternative to a mobile phone is required, we would generally investigate a FIDO2 security key first.
Option 3: Hardware OTP Tokens (For Specific Exceptions)
Best suited to specific technical or operational exceptions where neither a smartphone passkey nor FIDO2 security key is appropriate.
A hardware OTP token is a physical device that displays a temporary authentication code, usually changing every 30 or 60 seconds.
This removes the need for a smartphone, Microsoft Authenticator, SMS message or telephone call.
Microsoft Entra ID supports compatible OATH-TOTP hardware tokens, and organisations can purchase them from third-party suppliers. Microsoft explains how OATH hardware tokens work with Microsoft Entra ID here.
There is, however, an important difference:
A traditional OTP hardware token is not phishing-resistant.
The employee still reads a temporary code and enters it into a sign-in screen, so we would not normally recommend replacing SMS with hardware OTP tokens across an entire business.
They are better treated as an exception where a stronger option is not practical.
How do I set it up?
Hardware OTP tokens normally require involvement from your Microsoft 365 administrator.
The token needs to be purchased, assigned to the correct employee and registered within Microsoft Entra ID. Microsoft provides technical guidance for administrators managing OATH hardware tokens in Microsoft Entra ID.
They also need ongoing management if a token is lost, damaged or needs replacing.
There will always be employees who need a different approach, which is why you should understand who currently relies on SMS or voice before changing your authentication settings.
Every affected employee should have their replacement authentication method registered, tested and working before their existing SMS or voice method is removed.
What About Employees Who Do Not Want To Use Their Personal Phone?
This is an important practical issue to address before making changes.
Some employees will be comfortable using a personal smartphone for work authentication. Others may not want to install a work-related application or hold a work authentication method on a device they personally own.
Businesses therefore need to decide what alternatives will be available, which could include:
- A company-owned device
- A FIDO2 security key
- Another supported authentication method
- A different arrangement for specific working environments
Do not switch SMS authentication off for an employee until you have confirmed that they can successfully authenticate using their replacement method.
Removing SMS first could leave somebody unable to sign in and unable to work.
How Should Your Business Manage the Change?
You can either manage the migration internally or ask The HBP Group to manage the process for you.
Whichever route you choose, the priorities are the same: identify affected users, communicate with them in advance and make sure their new authentication method works before SMS or voice is removed.
Option 1: Let The HBP Group Manage the Change
For many customers, this will be the simplest option.
We can review your Microsoft 365 environment, identify who is affected, agree the most appropriate authentication methods and manage the Microsoft configuration and user migration.
Where appropriate, that means moving users towards passkeys and other phishing-resistant authentication methods, rather than simply replacing SMS with another weaker MFA method.
We are already supporting more than 100 businesses that need to make this change and have also completed the process internally.
If you would like The HBP Group to manage the migration for your business, speak to your Account Manager or get in touch with our team.
Option 2: Manage the Change Within Your Own Business
Businesses can also manage the migration themselves.
Start by identifying everybody who currently relies on SMS or voice and decide which authentication method each person will use instead.
Where possible, a phishing-resistant method such as a passkey should be the preferred destination.
Before changing settings, explain to employees:
- What is changing
- Which authentication method they should use
- Whether a mobile phone or personal device is involved
- What alternatives are available
- What they need to do
- Who to contact if they have a problem
You should also identify exceptions, such as employees without suitable smartphones, workplaces where phones are restricted or users who need a different technical or accessibility arrangement.
A Sensible Migration Process
We recommend working through the change in this order:
- Identify users currently relying on SMS or voice.
- Decide which authentication method each employee should use.
- Explain the change and identify any exceptions.
- Configure the required methods in Microsoft Entra ID.
- Help employees register their replacement method.
- Confirm every employee can authenticate successfully.
- Remove SMS and voice only when the replacement methods are working.
Do not remove an employee's existing authentication method until you know their replacement works.
The Bottom Line
Microsoft-provided SMS and voice MFA will retire on 1 February 2027.
From 1 September 2026, Microsoft will begin automatically enabling affected users for passkeys and prompting them to register.
Our advice is:
- Identify affected users now.
- Use passkeys as the preferred replacement wherever appropriate.
- Plan alternatives for employees who cannot use them.
- Communicate with employees before Microsoft starts prompting them.
- Test every replacement method before removing SMS or voice.
Do not wait until 1 February 2027 to discover who cannot sign in.
How The HBP Group Can Help
Moving every affected user without disrupting access can feel daunting, but we are already supporting more than 100 businesses through this change and have completed the process internally too.
If your business still uses SMS or voice MFA, speak to your Account Manager or get in touch with our team. We can help you manage the migration before Microsoft's deadlines.
____
FAQs
What Are Passkeys?
A passkey is a modern authentication credential that allows somebody to sign in securely without relying on a traditional password or one-time SMS code.
Depending on the device, an employee may authenticate using a fingerprint, facial recognition, device PIN or compatible security key.
Passkeys use cryptography rather than a reusable password or temporary code, which is why they should be the first replacement method considered for most organisations.
What Is Phishing-Resistant Authentication?
Phishing-resistant authentication is designed to prevent attackers from stealing an authentication code through a fraudulent sign-in page.
Methods such as passkeys use cryptographic authentication tied to the legitimate service rather than a temporary code that an employee can read, copy or type elsewhere.
Microsoft's change is therefore not simply about replacing one MFA method with another. The direction is towards authentication methods that are significantly harder to steal through phishing.
What Happens If We Don't Make a Change?
From 1 September 2026, employees enabled for SMS or voice may start seeing Microsoft prompts asking them to register a passkey.
From 1 February 2027, Microsoft's own SMS and voice authentication service will stop. If SMS or voice is an employee's only available method, Microsoft says they will receive a blocking passkey registration prompt before they can continue signing in.
Making the change in advance means you control the communication, timing and testing rather than dealing with authentication problems after Microsoft begins enforcing the change.
Is This Just an IT Setting?
No. Authentication directly affects whether employees can access services such as Outlook, Teams, SharePoint, OneDrive and other applications connected to Microsoft Entra ID.
Changing a technical setting can be quick. Making sure every affected employee can still authenticate and work afterwards is the part that needs to be planned properly.
How Can We Keep SMS or Voice If We Still Need It?
If your organisation has a genuine business, operational or regulatory reason to retain SMS or voice, Microsoft is providing an alternative.
Microsoft-provided telecom delivery is being retired, but organisations will be able to use a customer-managed telecom provider through the Microsoft Security Store.
Microsoft says information about available providers, pricing and commercial terms is due from 18 September 2026, with configuration available from 30 October 2026.
This will be a paid service, with costs depending on the provider, location and usage.
We would only recommend this route where there is a genuine reason SMS or voice must remain. For most organisations, moving affected employees to stronger, phishing-resistant authentication will be the better long-term option.
Posted by Tony Pearson