Microsoft is retiring SMS and voice authentication for Microsoft 365 business users
Posted on 17 August 2026 by Beaming SupportLove it or loathe it, multi-factor authentication (MFA) is now an essential part of protecting the accounts your business relies on.
Banks, email providers, online retailers and streaming services may all ask for additional proof that you are who you say you are. This often happens when you sign in from a new device or location. That proof might be a code sent by text message, a phone call, an app notification or a passkey.
Microsoft Entra ID currently supports several authentication methods, but important changes are coming for businesses that still rely on SMS messages or voice calls.
What is changing?
From 1 September 2026, passkeys will become the default authentication experience in Microsoft Entra ID.
Users who are enabled for SMS or voice authentication will also be enabled for passkeys. When they next sign in and complete MFA, Microsoft may prompt them to register a passkey.
From 1 February 2027, Microsoft will retire its own SMS and voice delivery services for Entra ID authentication. Businesses that still have a genuine operational or regulatory need for these methods will need to arrange a customer-managed telecoms provider through the Microsoft Security Store.
What does this mean for your business?
If your employees currently receive an SMS message or phone call to approve a Microsoft sign-in, you should identify those users and begin planning their move to a phishing-resistant authentication method.
- Options include:
- A passkey stored securely on a device.
- A synced passkey held in a supported credential manager.
- Windows Hello for Business.
- A FIDO2 hardware security key.
- Users whose only authentication method is SMS or voice could experience sign-in disruption after 1 February 2027 if no alternative has been configured.
Why is Microsoft making this change?
SMS codes and voice calls can be targeted through techniques such as phishing and SIM-swap attacks.
Passkeys use cryptographic authentication instead of a code that someone can intercept, copy or persuade a user to disclose. This makes them more resistant to phishing and can provide a simpler sign-in experience once they have been set up correctly.
Prepare your users before the deadline.
Although the change improves security, any new sign-in process can create uncertainty for users. Leaving the transition until the deadline could lead to confusion, additional support requests and avoidable interruptions.
Businesses should:
- Identify users who still rely on SMS or voice authentication.
- Choose the appropriate replacement method for each group.
- Test the new process with a small number of users.
- Give employees clear instructions before asking them to make the change.
- Complete the transition ahead of 1 February 2027.
Beaming can help you review your current Microsoft authentication arrangements, plan the transition and support your users through the change. Our knowledgeable team provides practical advice to help your business stay secure and productive.
Talk to Beaming about preparing your business for Microsoft’s authentication changes.