StormDotCom Logo
Back to Cyber Security & Compliance

Cyber Security & Compliance

Microsoft Is Ending SMS Authentication: What This Means for Your Business

From September 2026, Microsoft is making passkeys the default sign-in method across Microsoft 365 and Entra ID — and from February 2027, SMS and voice codes will stop working entirely. Here is what is changing and what you need to do.

Published: August 20268 min read

Key dates at a glance

All dates are official Microsoft policy as published in Microsoft Entra documentation.

September 1, 2026Passkeys become the default
  • Microsoft automatically enables the Registration Campaign in all Entra ID tenants
  • Users still on SMS or voice codes are prompted to register a passkey at each login
  • SMS and voice codes still function during this transition window
  • Admins can apply a temporary opt-out to delay the campaign until February 2027
  • Passkey registration in Microsoft Authenticator and Windows Hello becomes available by default
September 30, 2026Custom controls retired
  • Microsoft retires Custom controls in Entra ID Conditional Access
  • Organisations using Custom controls to integrate third-party MFA providers must migrate to External MFA
  • Custom controls reach end of life in May 2027
February 1, 2027SMS and voice authentication stop working
  • Microsoft permanently retires its native SMS and voice OTP delivery from Entra ID
  • Any user still relying on a text message or phone call code will be unable to log in
  • No opt-out available — applies to every Microsoft 365 / Entra ID tenant worldwide
  • Users must have already registered a passkey or alternative strong authentication method

For years, the standard approach to securing a Microsoft 365 login was a password plus a six-digit SMS code sent to a mobile number. It was better than a password alone — but not by as much as most people assumed. Now Microsoft is retiring that approach entirely and replacing it with passkeys: a fundamentally stronger, phishing-resistant technology that does away with one-time codes altogether.

This is not a distant roadmap item. The first milestone is 1 September 2026, and full retirement of SMS and voice authentication is set for 1 February 2027. If your business runs on Microsoft 365, these dates affect every user in your organisation.

Why SMS authentication is being retired

SMS was never designed as a security mechanism. Text messages can be intercepted through SIM-swapping — where an attacker convinces a mobile operator to transfer your number to their SIM card — or through SS7 protocol vulnerabilities, which allow sophisticated attackers to reroute messages in transit. Both attack types have been used against business accounts in South Africa.

Beyond interception, SMS codes are still vulnerable to phishing. A convincing fake login page can capture both your password and the SMS code in real time, because the attacker can relay them to the real site before the code expires. Passkeys break this attack entirely.

SIM swapping

An attacker tricks your mobile operator into transferring your number, then receives all your SMS codes.

SS7 interception

Weaknesses in the global mobile signalling protocol allow SMS messages to be rerouted and read.

Real-time phishing

A fake login page captures your password and SMS code simultaneously, relaying both to the real site before the code expires.

Social engineering

Support staff at mobile operators can be manipulated. No technical attack required — just a convincing story.

What is a passkey?

A passkey is a cryptographic credential stored securely on your device — your phone, laptop, or a hardware security key. When you sign in, your device proves your identity using a private key that never leaves the device and cannot be intercepted in transit. There is no code to type, no message to intercept, and no fake login page that can steal it.

Microsoft supports passkeys through three mechanisms:

Windows Hello for Business

Uses a PIN or biometric (fingerprint, face) on your Windows device to authenticate — no password or code needed.

Microsoft Authenticator

The Authenticator app on iOS or Android can store and use a passkey, approving logins with a face scan or fingerprint.

FIDO2 hardware keys

Physical security keys (such as a YubiKey) that you plug in or tap. The strongest option, typically used for high-privilege admin accounts.

What changes — and when

Microsoft is rolling out these changes in two stages through Microsoft Entra ID, the identity platform that underpins Microsoft 365 sign-ins.

1 September 2026 — Passkeys become the default

Microsoft automatically enables a Registration Campaign in all Entra ID tenants. Users who are still signed in with SMS or voice codes will be prompted — during their normal login flow — to register a passkey. Existing SMS-based logins continue to work during this period, but users will be nudged at each sign-in to make the switch. Admins can apply a temporary opt-out through February 2027 to delay the campaign.

1 February 2027 — SMS and voice codes stop working

Microsoft permanently retires its native SMS and voice OTP delivery from Entra ID. Any user still relying on a text or phone call code will be unable to complete their login. There is no opt-out from this stage — it applies to every tenant worldwide.

A note on third-party SMS providers

Microsoft is retiring its own SMS delivery only. Organisations that have configured a third-party SMS provider through Entra ID — rather than relying on Microsoft's built-in delivery — are not directly affected by the February 2027 retirement. However, migrating to passkeys is still the recommended path, as passkeys are inherently more secure than any SMS-based approach.

What your business needs to do

The transition is manageable with the right preparation. The key actions are:

  1. 1

    Deploy Microsoft Authenticator to all staff

    The Authenticator app is the simplest path to passkeys for most users. It is free, available on iOS and Android, and can store a passkey that works with Face ID or fingerprint. Rollout should happen before September 2026 to avoid disruption during the Registration Campaign.

  2. 2

    Enable Windows Hello for Business

    For staff on Windows devices, Windows Hello for Business uses a PIN or biometric to authenticate without any phone at all. This is especially valuable for shared workstations or environments where phones are not practical.

  3. 3

    Review your Conditional Access policies

    Passkey registration is subject to Conditional Access in Entra ID. Your policies may need adjusting to ensure registration flows work correctly — particularly for remote or off-site staff who cannot access your network during the transition.

  4. 4

    Identify any SMS-dependent users before February 2027

    Run a sign-in report in the Entra ID portal to identify which users are currently authenticating by SMS or voice. Any who have not switched by February 2027 will be locked out at the next login attempt.

How StormDotCom is managing this for our clients

We proactively manage and monitor Microsoft 365 tenants for our clients, which means this transition is already in our scope. We use Augmentt — a dedicated Microsoft 365 management platform — to monitor authentication method usage across all our client tenants, identify users still relying on SMS, and track Secure Score changes as passkey adoption improves security posture.

For clients on our managed service, we will be coordinating the rollout of Microsoft Authenticator passkeys and Windows Hello for Business well ahead of the September 2026 deadline — and ensuring no user is left behind before the February 2027 hard cutoff. If you are not on a managed plan and want to make sure your environment is ready, the best first step is a Microsoft 365 health review.

The bottom line

Passkeys are a genuine security improvement — not a cosmetic change. The weaknesses that SMS authentication carries are real, well-documented, and actively exploited. Microsoft's decision to retire it is overdue. The good news is that with the right preparation, the transition is straightforward and most users will find passkeys simpler to use than typing a six-digit code.

Key Takeaways

  • 📅1 September 2026: passkeys become the default — users on SMS will be prompted to switch
  • 🚫1 February 2027: Microsoft-provided SMS and voice OTP stops working permanently
  • Passkeys cannot be intercepted, SIM-swapped, or stolen via phishing
  • Microsoft Authenticator and Windows Hello for Business are the main passkey paths
  • Act before September 2026 — users not prepared will face login friction at the deadline

Is Your Microsoft 365 Ready for the Passkey Deadline?

We manage and monitor Microsoft 365 tenants for our clients — including the passkey transition ahead of the September 2026 and February 2027 deadlines. Book a Microsoft 365 health review and we'll confirm where your users stand and what needs to happen before the cutoff.

Book a Microsoft 365 Health Review