Microsoft-provided SMS and voice authentication retire on 1 February 2027. Here's what organisations using Microsoft Entra ID need to know.

For years, multi-factor authentication (MFA) based on text messages and phone calls has helped protect user accounts. Microsoft is now moving towards passkeys as its default authentication method, meaning organisations need to prepare for the change.
At a glance

What is changing?
Microsoft is making passkeys the default authentication experience within Microsoft Entra to improve security and support modern, AI-enabled services at scale.
From 1 September 2026, users currently enabled for SMS or voice authentication will automatically be enabled for passkeys and prompted to register one when completing MFA. Users can postpone registration initially.
From 1 February 2027, Microsoft will no longer provide SMS and voice authentication. Organisations that still require these methods will need to connect their own telecom provider through the Microsoft Security Store.
Microsoft is also moving passkey registration campaigns into a managed state, meaning enrolment prompts will automatically appear for users in eligible tenants.
Why is Microsoft making the change?
Security is the main driver. Passwords, SMS codes and voice verification remain vulnerable to phishing, interception and social engineering attacks.
Passkeys are designed to be phishing-resistant. Instead of relying on shared secrets or one-time codes, they use a cryptographic credential tied to both the user and their device. This removes the risk of authentication codes being intercepted or fraudulently obtained. Passkeys are also included within existing Microsoft Entra licences, so there is no additional licensing cost.
Key dates
1 September 2026 Rollout begins. Passkeys are automatically enabled for SMS and voice users, and registration prompts start appearing at sign-in.
18 September 2026 Review telecom provider options available through the Microsoft Security Store.
30 October 2026 Organisations that need to retain SMS or voice authentication should select their preferred provider.
1 February 2027 Microsoft-provided SMS and voice authentication are retired. Passkey enablement becomes enforced for users in scope.
Who is affected?
Any organisation using Microsoft Entra ID with users enabled for SMS or voice authentication will be impacted.
If no action is taken, organisations relying solely on Microsoft-provided SMS or voice methods could experience sign-in disruption after 1 February 2027, potentially affecting access to email, Teams and business-critical applications.
Four actions to take now
- Prepare for passkeys by planning user communications and managing registration campaigns.
- Review whether SMS or voice authentication is still required across your organisation.
- Implement a customer-managed telecom provider if telephony-based authentication remains necessary. Microsoft recommends completing setup at least four weeks before the deadline to allow for testing.
- Use the temporary opt-out period if needed, which runs from 1 September 2026 until 1 February 2027. After that, passkey enablement is enforced.
How C5 can help
As the Channel Islands' largest provider of technology solutions, C5 Alliance can help organisations plan and execute a smooth transition.
Our Professional Services team can assess your current authentication setup, design a passkey adoption plan, configure telecom providers where required, and prepare Conditional Access policies and user communications.
Our Managed Services team provides ongoing identity and access management, user support, monitoring and proactive guidance on Microsoft roadmap changes as organisations continue their journey towards passwordless authentication.
Let's talk before the deadline
Every organisation has different users, applications and compliance requirements. A short conversation can help you understand your options and build a plan that fits your needs.



