Microsoft Is Retiring SMS and Voice MFA: What To Do Next?

Microsoft is retiring SMS and voice authentication for Microsoft 365, meaning businesses with employees who currently use text messages or phone calls to verify their identity will need to move them to another authentication method. From September 2026, affected users may start being prompted to register a passkey, and Microsoft’s SMS and voice authentication service will stop completely on 1 February 2027.

For most businesses, this will be a manageable change. The important thing is to plan it properly and make sure employees have a working replacement before their current authentication method is removed.

You have two options:

1. Manage the change yourselves

You can identify affected employees, choose the right replacement authentication method, communicate the change and manage the migration internally.

2. Ask The HBP Group to manage the change for you

We can identify who is affected, help you decide what each employee should move to and manage the migration with you.

This is the approach we recommend.

If you are an existing customer and would like to talk through what this means for your business, speak to your Account Manager.

If you are not currently a customer of The HBP Group, get in touch with our team and we can talk you through your options.

What Is Microsoft Changing?

Microsoft currently allows some people to confirm their identity when signing in to Microsoft 365 by receiving a text message or telephone call.

Microsoft is retiring this service and moving customers towards more secure ways of signing in.

There are two important dates to be aware of:

1 September 2026: Affected employees may start seeing Microsoft prompts asking them to register a passkey as an alternative way of signing in.

1 February 2027: Microsoft’s own SMS and voice authentication service will stop.

If anyone in your business still uses SMS or voice authentication, you will need to move them to another method.

The key is to make the change before an employee finds themselves having to deal with it unexpectedly while trying to access Microsoft 365.

Does This Affect Your Business?

This change affects your business if any employees currently receive a text message or telephone call when confirming their identity for Microsoft 365.

You may not immediately know who is using these methods, particularly if different authentication options have been introduced over time.

The first step is therefore to identify who is affected.

If nobody uses SMS or voice authentication, you may not need to make any changes as a result of this announcement.

If employees are still using them, you will need to decide what they should use instead and make sure their replacement method is working before SMS or voice is removed.

The HBP Group can help you identify which users are affected if you are unsure.

Why Is Microsoft Making This Change?

SMS messages and telephone calls have been widely used for authentication for many years, but stronger methods are now available.

Temporary codes sent by text can potentially be obtained through techniques such as phishing and social engineering.

Microsoft is therefore moving customers towards authentication methods that are harder for an attacker to steal or trick somebody into handing over.

For businesses, the important point is simple:

SMS and voice should no longer be treated as the long-term way for employees to authenticate into Microsoft 365.

What Should Employees Use Instead?

There is not necessarily one authentication method that will suit every employee.

For many employees, Microsoft Authenticator will form part of the replacement sign-in process.

Instead of receiving a temporary code by text message, an employee can use their phone to securely confirm their identity.

Employees who are moving to Microsoft Authenticator can follow our step-by-step guide to downloading and setting up Microsoft Authenticator for Microsoft 365, which explains how employees can install the app and connect their Microsoft account.

Microsoft also provides instructions showing employees how to set up a passkey in Microsoft Authenticator.

Your Microsoft 365 administrator will need to make sure passkeys are available for the appropriate users. Microsoft explains how administrators can enable passkeys in Microsoft Entra ID.

However, you should not assume that the same option will work for everybody.

Some employees may not have a suitable smartphone, may work somewhere mobile phones are restricted or may not want to use a personally owned phone for work authentication.

The important thing is to identify those situations before you begin the migration.

If You Want To Manage the Change Yourselves

Moving one employee to a new authentication method is relatively straightforward.

Managing the change across an entire business takes more planning.

If you decide to manage the migration internally, we recommend working through the following steps.

1. Identify who is affected

Find everyone who currently receives a text message or telephone call when authenticating into Microsoft 365.

This gives you a clear picture of how many employees need to move.

2. Decide what each employee will use instead

For many employees, Microsoft Authenticator may be the appropriate replacement.

Other employees may require a different option depending on their device, role or working environment.

3. Identify exceptions early

Find employees who cannot follow the standard approach.

This could include people who do not want to use their personal phone, employees without a suitable smartphone or people working in environments where mobile devices are restricted.

Dealing with these situations early will make the wider rollout much easier.

4. Communicate the change

Tell affected employees what is changing, what they need to do, when they need to do it and where they can get help.

Doing this before employees start encountering Microsoft prompts should reduce confusion.

5. Set up the new authentication method

Employees moving to Microsoft Authenticator will need to download the app and connect it to their Microsoft 365 account.

Rather than repeating those instructions here, employees can follow our step-by-step Microsoft Authenticator setup guide.

6. Check that everything works

Make sure each employee can successfully authenticate using their new method.

Do not assume that because somebody has completed the setup process, everything is working correctly.

7. Only then remove SMS or voice

Once the replacement authentication method has been successfully tested, the employee’s old SMS or voice method can be removed.

The important principle is simple: do not remove somebody’s existing authentication method until you know their replacement works.

It is often the coordination around the change — identifying users, handling exceptions, communicating with employees and checking everyone has migrated successfully — that takes the most time.

If you would rather not manage that process internally, The HBP Group can take care of it for you.

If you are wondering what happens if you do nothing, whether you can continue using SMS, or what to do if an employee does not want to use their personal phone, please refer to our FAQs below.

Let The HBP Group Manage the Change

For many customers, the simplest option will be for The HBP Group to manage the migration with you.

We can:

  • Identify which employees are still using SMS or voice
  • Help determine the right replacement method for each person
  • Identify employees who need an alternative approach
  • Help you plan and communicate the rollout
  • Support employees through the change
  • Check that their replacement authentication method is working
  • Make sure SMS or voice is only removed once the employee is ready

That means you do not have to coordinate the migration across your business or deal with the individual issues that may arise along the way.

Moving every affected user without disrupting access can feel daunting, but we are already supporting lots of UK businesses through this change and have completed the process internally too.

If your business still uses SMS or voice authentication, speak to your Account Manager or get in touch with our team. We can help you manage the migration before Microsoft’s deadlines.


____

FAQs

What Happens If We Don’t Make a Change?

From 1 February 2027, Microsoft’s own SMS and voice authentication service will no longer be available.

If SMS or voice is an employee’s only available authentication method and your organisation has not configured an alternative telecom provider, Microsoft says the employee will be required to register a passkey before they can continue signing in.

That does not mean everybody using SMS will suddenly be locked out on 1 February.

However, employees could be faced with an unexpected setup process at the point they are trying to access Microsoft 365.

Making the change in advance means your business controls the communication, timing and testing rather than dealing with authentication issues as they arise.

What If an Employee Does Not Want To Use Their Personal Phone?

This should be identified before you begin moving users.

Some employees may not have a suitable smartphone. Others may not want to install a work-related authentication app on a personally owned device.

That does not mean they have to continue using Microsoft’s SMS service.

Depending on the employee and your Microsoft 365 setup, alternatives could include:

  • A company-owned mobile device
  • A physical security key
  • Another supported authentication method
  • A different arrangement for employees working in restricted environments

Identifying these employees early gives you time to agree an appropriate alternative without delaying the wider migration.

If you are an HBP customer, speak to your Account Manager and we can help you work through the available options.

Can We Simply Keep Using SMS or Voice?

It will be possible for organisations with a genuine business, operational or regulatory need to continue using SMS or voice authentication.

However, Microsoft itself will no longer provide the messages or calls.

Instead, organisations will need to use a customer-managed telecommunications provider through the Microsoft Security Store.

This will be a paid service and will require additional setup and management.

For most organisations, moving employees to a stronger authentication method is likely to be the more appropriate long-term approach.

If you believe your organisation needs to retain SMS or voice, speak to your Account Manager so we can discuss the available options.

Tony Pearson

Posted by Tony Pearson

Tony Pearson is Chief Service Delivery Officer at The HBP Group, with over 25 years of experience leading high-performing service delivery teams. Having spent nearly three decades at HBP, including more than 26 years as Group Operations Director, he brings extensive expertise in IT operations, customer experience, and service improvement. Tony shares insights on cybersecurity, service delivery best practice, and the real-world decisions UK businesses face when managing IT risk.

The HBP Group Gradient Bar