Microsoft has confirmed it’s phasing out SMS and voice-based MFA across Entra ID and personal Microsoft accounts. From 1 September 2026, anyone still logging in with a text message or phone call gets nudged at every sign-in to set up a passkey instead. From 1 February 2027, that nudge becomes a lock (Microsoft). If you do not have a passkey or authenticator app, you cannot sign-in.
It’s a big change, but the headline isn’t “Microsoft did a thing”, it’s that a company sitting on more sign-in data than almost anyone on earth looked at it and concluded SMS can’t be trusted anymore. If your CRM, your bank, your VPN, or anything else still leans on a text message to keep the wrong people out, the same logic applies.
Why this was never really about Microsoft
We wrote about this last year using a simple analogy – SMS MFA is like closing your front door but leaving it unlocked. Nothing about that has changed, it’s just got more urgent.
The code itself still travels over telecom networks that were never designed to be secure. These codes are unencrypted and easy to intercept if someone takes over your number through a SIM swap. In the UK, Cifas recorded a surge of over 1,000% in unauthorised SIM swaps reported to its National Fraud Database between 2023 and 2024, and that hasn’t slowed down (Efani).
What’s changed since we first wrote about this is how much of the attack is now automated. KnowBe4 found that well over 80% of phishing attacks now show signs of AI involvement, and AI-written phishing emails are matching, sometimes beating, the click-through rates of the human-crafted versions (PhishEye).
The fix hasn’t changed either
Authenticator apps and passkeys sidestep the problem because they don’t rely on a telecom network at all. The code lives on the device itself and setup takes a couple of minutes per person, whichever platform you’re on.
Start with the accounts where a compromise would actually hurt – shared logins, admin accounts, finance systems, anything holding client data.
The accessibility caveat still applies
Some sectors, government services, retail banking, anywhere accessibility legislation guarantees access without requiring a smartphone, will always need some form of fallback.. Microsoft’s own approach reflects this, organisations with a real need can keep SMS or voice running through a paid, customer-managed telecom provider rather than Microsoft’s free service (Our Cloud Network). For everyone else, it shouldn’t be the default anymore.
Our advice
Treat this as a prompt to ask a wider question, where in your business are you still relying on SMS to protect something that matters, and why haven’t you moved it yet.
FAQs
From 1 September 2026, Microsoft starts prompting anyone using SMS or voice MFA to register a passkey instead. From 1 February 2027, that becomes a hard requirement.
From 1 February 2027, any Microsoft account relying only on SMS or voice MFA will be blocked from signing in until a passkey or authenticator app is registered. There’s no grace period after that date.
Both. It covers Entra ID, which includes Microsoft 365 and other business accounts, as well as personal Microsoft accounts.
This specific change only applies to Microsoft accounts. No single body has banned SMS MFA industry-wide. But it’s a strong signal from one of the largest identity providers that SMS is now treated as a legacy fallback, not an acceptable default, and it’s reasonable to expect others to follow.
Only in specific cases. Organisations with a genuine need, typically regulated or accessibility-driven sectors, can keep SMS or voice running through a paid, customer-managed telecom provider. Microsoft’s free SMS MFA service is being withdrawn as the default.
Audit which accounts, particularly shared logins and anything with elevated privileges, still rely on SMS as their only second factor, on any platform, not just Microsoft’s. Move those to an authenticator app or passkey on your own timeline, rather than waiting to be forced into it.
No. Setup per person usually takes a few minutes, scanning a QR code or registering a passkey, and most platforms walk users through it directly at sign-in.