
Marketing & Operations
Claudia Sterling

SMS and voice codes feel secure because they've always been there. They aren't, and Microsoft has just put a date on their retirement. Here's what's changing, why it matters, and what your business needs to do about it.
Microsoft just put an expiry date on SMS and voice MFA
Microsoft has confirmed that Microsoft-provided SMS and voice authentication in Entra ID will retire on 1 February 2027. From 1 September 2026, passkeys become the default sign-in method, and anyone still enabled for SMS or voice will be automatically enrolled and nudged to register one the next time they complete MFA.
It’s easy to read that as a routine platform update. It isn’t. Microsoft is quietly retiring the authentication method that most businesses have leaned on for over a decade, because it no longer holds up against the way accounts actually get broken into today.
Why SMS and voice were never as safe as they felt
A text message code feels secure. It arrives on a phone only you should have, you type six digits, and you’re in. That sense of safety was always slightly misplaced. SMS and voice have been the weakest form of multi factor authentication on offer for years, tolerated because they were easy to roll out, not because they were hard to beat.
SIM swapping
An attacker convinces or bribes a mobile provider, or exploits weak identity checks, to move a victim’s phone number onto a SIM the attacker controls. From that point, every SMS code and every voice call meant for that number goes straight to the attacker instead. This isn’t a rare, exotic attack. It’s a commercially traded service used against everyone from cryptocurrency holders to company directors, and it requires no access to the victim’s actual phone.
Weaknesses in the telecoms network itself
SMS and voice rely on decades old telecoms signalling infrastructure that was never built with security as a first principle. Researchers, and criminal groups, have repeatedly shown that text messages and calls can be intercepted in transit, without the attacker ever touching the victim’s handset. The weakness sits in the network the message travels through, not in anything the user did wrong.
Real time phishing relay
Modern phishing kits sit between a victim and the real login page. The victim types their username, password, and one time code into what looks like a genuine site. The kit captures all three instantly and replays them to the real service before the code expires. Because an SMS or voice code is just a number a human reads out and types in, it can be phished exactly like a password. Speed is the only thing separating a stolen password from a stolen SMS code.
The real problem: no cryptographic binding
Underneath all three attacks sits the same structural flaw. An SMS or voice code has no cryptographic link to the device or the website it’s meant to protect. It’s just a string of digits, and anything that can be read out loud or typed in can be intercepted, redirected, or relayed, with the receiving service none the wiser.
A passkey works differently. It uses public key cryptography bound to the specific device and the specific website. The private key never leaves the device, and a passkey created for your bank’s real login page simply will not work on a convincing fake one, even if a user is completely fooled into visiting it. That’s why Microsoft, along with the NCSC and other national cyber agencies, now classifies SMS and voice as phishable and passkeys as phishing resistant. It isn’t a matter of degree. It’s a different category of protection.
The key dates you need to know
Microsoft has set out a clear, staged timeline rather than an overnight switch off.
1 September 2026: users still enabled for SMS or voice are automatically enabled for passkeys and nudged to register one at their next MFA sign in
1 February 2027: Microsoft-provided SMS and voice delivery is fully retired across Entra ID
After 1 February 2027: anyone whose only MFA method is still SMS or voice gets a blocking prompt to register a passkey before they can sign in at all, with no opt out, applied to every tenant
What this means for your business
None of this needs to be a fire drill if you start now rather than waiting for the September nudge to land on its own. A few practical steps make the difference between a controlled rollout and a rushed one.
Find out exactly who in your organisation is still enabled for SMS or voice authentication
Enable passkeys and run your own registration campaign ahead of September 2026, so you control the pace rather than leaving it to an automatic nudge
Tell staff clearly what’s changing, when, and what they personally need to do
If you have a genuine regulatory or operational reason to keep SMS or voice, plan now to configure a customer-managed telecom provider through the Microsoft Security Store, available from late 2026, rather than assuming it will simply carry on working
The direction of travel is clear
This isn’t Microsoft being difficult for the sake of it. It’s company policy finally catching up with what security researchers have been saying for years: SMS and voice MFA are barely better than no MFA at all against a determined, targeted attacker. Passkeys are the first mainstream authentication method that removes the weaknesses SMS and voice always had.
If you’re not sure who in your organisation is still relying on a text message to log in, that’s worth finding out now, while you still have well over a year to make the change on your own terms rather than Microsoft’s.




