Microsoft Is Retiring SMS and Voice MFA: What To Do Next?

If anyone in your business receives a text message or phone call to verify their Microsoft 365 sign-in, you need to take action.

Microsoft is moving users away from SMS and voice authentication towards more secure sign-in methods.

The change has already started. From 1 September 2026, Microsoft began prompting affected users to register a passkey. From 1 February 2027, Microsoft's own SMS and voice authentication service will be retired.

It is important to plan the change properly so employees have a working replacement before their existing authentication method is removed.

What does your business need to do?

If you still have employees using SMS or phone calls to authenticate, you have two options:

1. Manage the change yourselves

Your internal team can identify the people affected, decide what they should move to, communicate the change and support employees through the migration.

2. Ask The HBP Group to manage the change for you (Recommended)

We can manage the migration from start to finish, helping you identify affected users, agree the right approach and move employees across without unnecessary disruption.

Whichever route you choose, the important thing is to start planning before Microsoft retires its SMS and voice service on 1 February 2027.

If you are wondering what happens if you do nothing, whether you can continue using SMS, or what to do if an employee does not want to use their personal phone, please refer to our FAQs below.

Option 1: managing the change yourselves

Moving one person to a new authentication method is relatively straightforward.

Managing the change across a business involves a little more planning.

If you decide to handle the migration internally, we recommend working through the following steps.

1. Identify who is affected

First, establish which employees are still using a text message or phone call to verify their Microsoft 365 sign-in. This gives you a clear picture of how many people need to be moved and helps you plan the rollout.

2. Decide what each person will move to

Microsoft is encouraging organisations to move users towards more secure, phishing-resistant methods such as passkeys.

For most employees, a passkey using Microsoft Authenticator will be the most appropriate replacement.

The important thing is to decide the right approach before removing anyone's existing authentication method.

3. Identify any exceptions

Not everybody will necessarily follow the same process.

For example, some employees may not have a suitable smartphone or may not want to use a personally owned phone for work authentication.

Identify these people early so an alternative can be agreed before you begin the wider rollout.

4. Communicate the change

Let affected employees know:

  • why their current sign-in method is changing;
  • what they need to do;
  • when they need to do it; and
  • where they can get help if they have a problem.

Keeping the communication simple will make the rollout much easier.

5. Help employees set up their new authentication method

Employees moving to Microsoft Authenticator will need to download the app, connect their Microsoft 365 account and register their passkey. 

We have a separate step-by-step guide which takes employees through the setup process:

How to Download and Set Up Microsoft Authenticator for Microsoft 365 > 

Microsoft also provides instructions showing employees how to set up a passkey in Microsoft Authenticator.

Your Microsoft 365 administrator will need to make sure passkeys are available for the appropriate users. Microsoft explains how administrators can enable passkeys in Microsoft Entra ID.

However, you should not assume that the same option will work for everybody.

Some employees may not have a suitable smartphone or may not want to use a personally owned phone for work authentication.

The important thing is to identify those situations before you begin the migration, or employees could be left not being able to work.

6. Check that everything works

Before removing SMS or voice authentication, make sure each employee can successfully use their new method.

This is an important step. You do not want somebody discovering that their new authentication method has not been set up correctly when they are trying to access Outlook, Teams or another Microsoft 365 service.

7. Only then remove SMS or voice

Once you know the replacement is working, the employee's old authentication method can be removed.

Doing things in this order reduces the risk of people being unable to access the systems they need to work.

Option 2: The HBP Group manages the migration for you

If you would rather not manage all of this internally, we can take care of the change for you.

We are already helping more lots of SMEs manage this change and have completed this process internally too, so we understand the steps involved and the issues that can come up along the way.

We can help you:

  • identify which employees are affected;
  • determine the right authentication method for each person;
  • identify anyone who needs an alternative approach;
  • plan and communicate the rollout;
  • support employees through the change;
  • check that their new authentication method is working; and
  • make sure SMS or voice is only removed once they are ready.

This means you do not have to coordinate the migration across your business or deal with the individual issues that can arise along the way.

If you would like us to manage the migration for you, speak to your Account Manager or get in touch with our team.

____

FAQs

What Happens If We Don’t Make a Change?

From 1 February 2027, Microsoft’s own SMS and voice authentication service will no longer be available.

If SMS or voice is an employee’s only available authentication method and your organisation has not configured an alternative telecom provider, Microsoft says the employee will be required to register a passkey before they can continue signing in.

That does not mean everybody using SMS will suddenly be locked out on 1 February.

However, employees could be faced with an unexpected setup process at the point they are trying to access Microsoft 365.

Making the change in advance means your business controls the communication, timing and testing rather than dealing with authentication issues as they arise.

What If an Employee Does Not Want To Use Their Personal Phone?

This should be identified before you begin moving users.

Some employees may not have a suitable smartphone. Others may not want to install a work-related authentication app on a personally owned device.

That does not mean they have to continue using Microsoft’s SMS service.

Depending on the employee and your Microsoft 365 setup, alternatives could include:

  • A company-owned mobile device
  • A physical security key
  • Another supported authentication method
  • A different arrangement for employees working in restricted environments

Identifying these employees early gives you time to agree an appropriate alternative without delaying the wider migration.

If you are a customer of The HBP Group, speak to your Account Manager and we can help you work through the available options.

Can We Keep Using SMS or Voice?

It will be possible for organisations with a genuine business, operational or regulatory need to continue using SMS or voice authentication.

However, Microsoft itself will no longer provide the messages or calls.

Instead, organisations will need to use a customer-managed telecommunications provider through the Microsoft Security Store.

This will be a paid service and will require additional setup and management.

For most organisations, moving employees to a stronger authentication method is likely to be the more appropriate long-term approach.

If you believe your organisation needs to retain SMS or voice, speak to your Account Manager so we can discuss the available options.

Are There Any Other Options Available?

Yes. Microsoft Authenticator with a passkey will be the best option for many businesses, but there are alternatives where a smartphone is not suitable.

FIDO2 security keys

A FIDO2 security key is a small physical device, usually connected by USB or NFC, that allows somebody to authenticate without using a mobile phone. They are phishing-resistant and can be a good option for employees who cannot or do not want to use a personal device.

Find out more about FIDO2 security keys >

Hardware authentication tokens

Hardware OATH tokens are physical devices that generate a temporary authentication code. They can be useful in specific situations where a smartphone or FIDO2 security key is not suitable.

Because they still rely on a temporary code, they are not phishing-resistant, so we would normally treat them as an alternative for specific exceptions rather than the first option for most employees.

Find out more about hardware OATH tokens >

Tony Pearson

Posted by Tony Pearson

Tony Pearson is Chief Service Delivery Officer at The HBP Group, with over 25 years of experience leading high-performing service delivery teams. Having spent nearly three decades at HBP, including more than 26 years as Group Operations Director, he brings extensive expertise in IT operations, customer experience, and service improvement. Tony shares insights on cybersecurity, service delivery best practice, and the real-world decisions UK businesses face when managing IT risk.

The HBP Group Gradient Bar