Entra-based SMS/Voice Two-factor Authentication is being retired & will no longer be available as of February 1, 2027. Customers still using SMS/Voice for two-factor authentication need to move to either Passkey/FIDO2/Authenticator or subscribe to a 3rd party SMS/Voice MFA solution. Starting September 1st, all users enabled for SMS/Voice multi-factor authentication will, by default, be auto-enabled for passkeys and prompted to register one during MFA sign-in.
WHY?
Since 2020, Microsoft has been alerting customers that SMS/Voice multi-factor authentication is inherently vulnerable to attack & puts customers & other users of Microsoft services at risk. It’s specifically called out as being 40% less effective in stopping bad actors compared to other forms of MFA such as the Microsoft Authenticator app.
- Nov 10, 2020 – It’s Time to Hang Up on Phone Transports for Authentication | Microsoft Community Hub
“Today, I want to do what I can to convince you that it’s time to start your move away from the SMS and voice Multi-Factor Authentication (MFA) mechanisms. These mechanisms are based on publicly switched telephone networks (PSTN), and I believe they’re the least secure of the MFA methods available today. That gap will only widen as MFA adoption increases attackers’ interest in breaking these methods and purpose-built authenticators extend their security and usability advantages. Plan your move to passwordless strong auth now – the authenticator app provides an immediate and evolving option.” - Jul 17, 2023 – Advancing Modern Strong Authentication | Microsoft Community Hub
“A recent MFA research study from Microsoft concludes that SMS is 40% less effective in stopping bad actors compared to the Microsoft Authenticator app.”
PLANNING FOR SMS/VOICE MFA RETIREMENT
For organizations still using SMS/Voice, they may plan appropriately by reading the following:
- Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID | M…
“On February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability.
Organizations that still require SMS or voice authentication methods will have the option to choose one of our telecom partners through the Microsoft Security Store. Customers will be responsible for any associated telecom-related costs charged by the telecom partners.” - Prepare for transition to passkeys
“Microsoft Entra ID is making passkeys the default sign-in experience, so every organization gets phishing-resistant security by default. SMS and voice are no longer positioned as secure authentication methods and will no longer be provided natively in Entra ID.
Starting September 1, 2026, passkeys become the default authentication experience and will be automatically enabled for users enabled for SMS or voice. From February 1, 2027, Microsoft-provided telecom delivery for SMS and voice will be retired; customers who still require these methods should configure customer-managed providers through the Microsoft Security Store. More information on customer-managed telecoms coming September 18th, 2026.
Users who already sign in with passkeys, Windows Hello for Business, or another phishing-resistant method can continue using those methods. However, users who remain enabled for SMS or voice may still receive prompts to register passkeys on eligible devices. To check who in your tenant still uses SMS or Voice, see Find active SMS or Voice users in your tenant.”
RETIREMENT SCHEDULE FOR SMS/VOICE MFA
Microsoft will provide a temporary opt-out from passkey enrollment & the Registration Campaign between September 2026 and February 2027. This option gives administrators additional time to prepare users and update authentication policies. After February 1, Microsoft-provided SMS and voice MFA will no longer remain available & users who only registered SMS or voice authentication will not be able to sign in until they configure a supported passkey or another approved authentication method.
The full retirement schedule is as follows:
- August 1, 2026: API support for temporary opt-outs to be made available.
- September 1, 2026: Users will begin receiving passkey registration prompts during MFA challenges.
- September 18, 2026: Supported telecom provider options to be published.
- October 30, 2026: Organizations continuing to use SMS or voice must pre-configure a supported provider.
- February 1, 2027: Microsoft-provided SMS and voice authentication will cease operation.
References:
