Microsoft Entra authentication update: Passkeys by default and SMS/voice retirement
Move to phishing-resistant authentication before Microsoft retires SMS and voice authentication
Microsoft is notifying all Microsoft Entra ID tenants about an important authentication security change. As cyber threats continue to evolve, stronger, phishing-resistant authentication is becoming the new standard. To help improve security, passkeys will become the default authentication method in Microsoft Entra, and Microsoft-provided SMS and voice authentication will be retired on February 1, 2027.
For more information about Microsoft's move to phishing-resistant authentication, see the Microsoft Security Blog announcement.
What's changing
Passkeys become the default authentication experience for users who currently use SMS or voice authentication.
Microsoft-provided SMS and voice authentication will be retired on February 1, 2027.
Organizations using customer-managed telecom providers through the Microsoft Security Store are not affected by this retirement.
Why this change is happening
SMS and voice authentication are among the least secure multifactor authentication (MFA) methods available today. They are significantly more vulnerable to phishing, SIM-swap, and replay attacks than phishing-resistant methods such as passkeys. Transitioning to passkeys helps provide stronger security by default and better protects user accounts.
Timeline and impact
September 1, 2026 – Users currently enabled for SMS or voice authentication will automatically be enabled for passkeys and prompted to register one the next time they complete MFA. If you do not want users automatically enabled for passkeys, remove SMS and voice from your Authentication Methods Policy before this date.
February 1, 2027 – Microsoft-provided SMS and voice authentication will no longer be available in Microsoft Entra ID. Customer-managed telecom providers remain supported.
After February 1, 2027 – Users whose only available MFA methods are SMS or voice will be required to register a passkey before they can continue signing in. This enforcement applies to all Microsoft Entra ID tenants and cannot be disabled.
What you need to do
If your tenant has no users enabled for SMS or voice authentication, no action is required.
If you do have users relying on SMS or voice authentication, you should migrate them to a phishing-resistant authentication method before February 1, 2027. Microsoft recommends using passkeys as the preferred authentication method.
To prepare:
Identify affected users. Determine which users are currently enabled for SMS or voice authentication.
Migrate users to passkeys. Enable passkeys and launch a registration campaign to encourage adoption before automatic enablement begins on September 1, 2026.
Communicate with users. Inform users about the upcoming changes, important dates, and the steps they need to complete.
Use a customer-managed telecom provider only if necessary. If your organization must continue using SMS or voice authentication for regulatory or operational reasons, configure a supported customer-managed telecom provider through the Microsoft Security Store before February 1, 2027. Provider options and pricing will be available beginning September 18, 2026, with configuration support available beginning October 30, 2026.
Summary
To avoid disruption, all users currently relying on Microsoft-provided SMS or voice authentication should be migrated to a phishing-resistant authentication method before February 1, 2027. Beginning the transition before September 1, 2026 allows your organization to manage the rollout on its own schedule and helps avoid mandatory registration prompts for end users.