Posted by: kurtsh | July 24, 2026

NEWS: Retirement of SMS/Voice Multifactor Authentication in Entra ID

Entra-based SMS/Voice Two-factor Authentication is being retired & will no longer be available as of February 1, 2027.  Customers still using SMS/Voice for two-factor authentication need to move to either Passkey/FIDO2/Authenticator or subscribe to a 3rd party SMS/Voice MFA solution. Starting September 1st, all users enabled for SMS/Voice multi-factor authentication will, by default, be auto-enabled for passkeys and prompted to register one during MFA sign-in.

WHY?
Since 2020, Microsoft has been alerting customers that SMS/Voice multi-factor authentication is inherently vulnerable to attack & puts customers & other users of Microsoft services at risk. It’s specifically called out as being 40% less effective in stopping bad actors compared to other forms of MFA such as the Microsoft Authenticator app.

PLANNING FOR SMS/VOICE MFA RETIREMENT
For organizations still using SMS/Voice, they may plan appropriately by reading the following:

  • Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID | M…
    “On February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability. 
    Organizations that still require SMS or voice authentication methods will have the option to choose one of our telecom partners through the Microsoft Security Store. Customers will be responsible for any associated telecom-related costs charged by the telecom partners.”
  • Prepare for transition to passkeys
    “Microsoft Entra ID is making passkeys the default sign-in experience, so every organization gets phishing-resistant security by default. SMS and voice are no longer positioned as secure authentication methods and will no longer be provided natively in Entra ID.
    Starting September 1, 2026, passkeys become the default authentication experience and will be automatically enabled for users enabled for SMS or voice. From February 1, 2027, Microsoft-provided telecom delivery for SMS and voice will be retired; customers who still require these methods should configure customer-managed providers through the Microsoft Security Store. More information on customer-managed telecoms coming September 18th, 2026.
    Users who already sign in with passkeys, Windows Hello for Business, or another phishing-resistant method can continue using those methods. However, users who remain enabled for SMS or voice may still receive prompts to register passkeys on eligible devices. To check who in your tenant still uses SMS or Voice, see Find active SMS or Voice users in your tenant.”

RETIREMENT SCHEDULE FOR SMS/VOICE MFA
Microsoft will provide a temporary opt-out from passkey enrollment & the Registration Campaign between September 2026 and February 2027. This option gives administrators additional time to prepare users and update authentication policies. After February 1, Microsoft-provided SMS and voice MFA will no longer remain available & users who only registered SMS or voice authentication will not be able to sign in until they configure a supported passkey or another approved authentication method.

The full retirement schedule is as follows:

References:


Categories