Microsoft SMS MFA retirement

      Preparing for Microsoft’s SMS MFA Retirement

      The Microsoft SMS MFA retirement is an important upcoming authentication change that organisations using Microsoft 365 should begin preparing for.

      From 1 February 2027, Microsoft will retire its own telecommunications delivery service for SMS and voice authentication in Microsoft Entra ID. This means Microsoft will no longer directly provide the text messages and telephone calls currently used by some organisations for multi-factor authentication (MFA) and self-service password reset.

      The change forms part of Microsoft’s move towards stronger, phishing-resistant authentication, with passkeys becoming its recommended default authentication method. Although the retirement date is still some way off, organisations should use the time available to understand whether any users remain dependent on SMS or voice authentication and plan any necessary changes.

      What Is the Microsoft SMS MFA Retirement?

      SMS and voice authentication have traditionally allowed users to verify their identity by receiving a code through a text message or an automated telephone call. These methods provide an additional security layer beyond a username and password, but they are more vulnerable to phishing, social engineering and account compromise than newer authentication methods.

      Microsoft is therefore moving organisations towards phishing-resistant options such as passkeys, Windows Hello for Business and FIDO2 security keys.

      According to Microsoft’s official SMS and voice authentication retirement guidance, users whose only available MFA method is SMS or voice may be required to register a passkey during sign-in after the retirement takes effect. Organisations that have not prepared affected users could therefore experience disruption to account access.

      This change does not mean that every Microsoft 365 user will be affected. Its impact will depend on the authentication methods currently enabled and used within each organisation.

      Why Is Microsoft Retiring SMS and Voice Authentication?

      Cyber criminals frequently target identities because gaining access to a legitimate user account can allow them to bypass other security controls.

      Passwords and authentication codes can be captured through phishing campaigns or manipulated through social engineering. SMS and voice calls therefore provide weaker protection against phishing and account compromise than passkeys and other phishing-resistant authentication methods.

      Passkeys are designed to reduce reliance on passwords and one-time verification codes. They use cryptographic credentials associated with a user’s device or authentication method, making them significantly harder to intercept through a conventional phishing attack.

      The retirement also reflects a broader shift in identity security. Organisations are increasingly treating account access as a central part of their wider cyber security strategy rather than relying on passwords as the primary means of protection.

      Which Organisations Could Be Affected?

      Your organisation may be affected by the Microsoft SMS MFA retirement if users currently:

      • Receive MFA verification codes by SMS text message
      • Approve sign-ins through an automated telephone call
      • Depend on SMS or voice authentication for self-service password reset
      • Have SMS or voice enabled as their only available authentication method
      • Have not registered an alternative authentication method

      Many organisations already use the Microsoft Authenticator app, Windows Hello for Business, FIDO2 security keys or passkeys. Even in these environments, it is worth checking whether individual users, shared working arrangements or legacy authentication policies still rely on SMS or voice.

      You can learn more about the role of multi-factor authentication in protecting business accounts and the different authentication options available to organisations.

      What Happens From 1 February 2027?

      From 1 February 2027, organisations that have not configured a customer-managed telecommunications provider will no longer be able to use Microsoft-provided SMS or voice delivery for MFA.

      Microsoft has stated that organisations with a legitimate business, regulatory or technical requirement to continue using SMS or voice may have the option to use a customer-managed provider through the Microsoft Security Store. This would be an alternative arrangement rather than a continuation of Microsoft’s existing delivery service.

      Users whose only MFA method is SMS or voice may encounter a blocking prompt requiring them to register a passkey before they can continue accessing their account. This makes it important to identify affected users and introduce alternative methods before the retirement date rather than waiting for sign-in problems to occur.

      How Should Organisations Prepare?

      There is no need to treat this as an immediate emergency. However, organisations should begin reviewing their current Microsoft Entra ID authentication configuration well ahead of February 2027.

      A sensible preparation plan should include:

      1. Reviewing the authentication methods enabled in Microsoft Entra ID
      2. Identifying users who are enabled for or actively using SMS and voice authentication
      3. Determining whether any users depend on these methods as their only way to complete MFA
      4. Assessing suitable phishing-resistant authentication alternatives
      5. Considering accessibility, device and operational requirements
      6. Planning user communications, testing and support
      7. Migrating affected users before the retirement deadline

      Starting the review early allows time to test new methods with different user groups and resolve practical issues before they affect access to business systems.

      Organisations that need a broader view of their identity, device and security configuration may also benefit from a Microsoft 365 security assessment. This can help identify weaknesses or misconfigurations across Microsoft Entra ID, MFA, Conditional Access and other Microsoft 365 security controls.

      How Akita Can Help

      Akita supports organisations with Microsoft 365 security, identity management and Microsoft Entra ID configuration.

      If you are unsure whether your organisation will be affected by the Microsoft SMS MFA retirement, our team can help you:

      • Review your current authentication configuration
      • Identify users who depend on SMS or voice authentication
      • Assess appropriate alternative authentication methods
      • Review related Microsoft Entra ID and Conditional Access policies
      • Develop a practical migration plan
      • Support user communication, testing and implementation

      The appropriate approach will depend on your organisation’s users, devices, existing Microsoft 365 setup and security requirements. The aim should be to strengthen authentication without creating unnecessary barriers for employees.

      Preparing Ahead of the February 2027 Deadline

      The Microsoft SMS MFA retirement is part of the wider move towards passwordless and phishing-resistant authentication.

      While most organisations do not need to make immediate changes, now is the right time to establish whether SMS or voice authentication is still in use. A planned review and migration will reduce the likelihood of sign-in disruption and give users time to adopt a suitable alternative method.

      If you would like help reviewing your Microsoft 365 authentication setup, contact the Akita team to discuss your current configuration and the next steps.

      Contact Us
      Back to feed