
Microsoft is retiring SMS and voice call MFA in Entra ID. The first change lands September 1, 2026, and the retirement finishes February 1, 2027 for most users and July 1, 2027 for global administrators and external users.
If someone in your tenant uses a text message as their only second factor, they'll eventually hit a registration prompt they can't skip. No code, no sign-in.
You have time to do this calmly. You don't have time to ignore it.
What's actually changing?
Microsoft is ending its own telephony delivery for MFA codes. Starting September 1, 2026, passkeys become the default sign-in experience and users on SMS or voice get auto-enabled and nudged to register one. On the retirement dates, Microsoft-provided SMS and voice stop working as authentication methods entirely.
The word "Microsoft-provided" matters. This is about who sends the text, not about phones in general.
The three dates
Straight from Microsoft's retirement notice:
- September 1, 2026: Passkeys become the default. Users enabled for SMS or voice are auto-enabled for passkeys and nudged to register at MFA sign-in. Nothing breaks yet.
- February 1, 2027: Microsoft-provided SMS and voice retire for all users except global administrators and external users. Internal guest accounts are in this group too.
- July 1, 2027: Same retirement for global administrators and external users.
Microsoft is blunt about the endgame: "There is no opt out for enforcement." After a user's retirement date, if SMS or voice is their only method, they get a blocking passkey registration prompt before they can sign in.
Does this affect password resets too?
Yes. Per Microsoft's retirement FAQ, it applies across Entra, self-service password reset included. That catches a lot of small businesses off guard, because SSPR is often where the phone number lives.
It's also the second identity deadline on the calendar this year. Our post on the Entra ID SSPR registration change covers the November 7, 2026 one, which is a separate change with its own timeline. Handle both in the same project and you'll only annoy your staff once.
Who this actually hurts
Not the people you'd guess. Office staff with a company phone and the Authenticator app already installed are fine.
The users who break are the ones nobody thinks about. The warehouse supervisor who never set up the app. The part-time bookkeeper who comes in Tuesdays. The owner's assistant who's had the same flip phone since 2019. The service account somebody registered to a desk phone years ago and forgot.
Every one of those is a help desk call on a Monday morning, and every one of them is avoidable if you find them first.
What to do in the next 30 days
- Find out who's affected. Microsoft publishes an SMS and voice usage analyzer, a PowerShell tool that reports which users and groups are still in scope and exports the list to CSV. Run it before you plan anything else. Guessing at the number is how projects like this go sideways.
- Sort that list by risk. Anyone with admin rights, access to banking, or access to client data goes first.
- Register a second method now. Authenticator app or passkey, per user, before the nudges start. A user with two working methods never sees a blocking prompt.
- Decide what to do about the holdouts. Shared devices, no-smartphone staff, and field workers need a plan that isn't "we'll figure it out in January."
- Tell people what's coming. One short email beats fifty confused calls. Staff who expect a prompt will follow it. Staff who don't will assume it's phishing, which, to be fair, is exactly what we've trained them to think.
Can you delay it?
Partly. Microsoft offers a temporary opt-out from the automatic passkey migration, available September 1, 2026 through February 1, 2027, set through a Graph API call against the authentication methods policy.
That opt-out pauses the auto-migration. It does not pause the retirement. When February 1 arrives, SMS and voice stop working whether you opted out or not, and you'll have spent five months not fixing the problem.
Use it only if you have a real conflict with a rollout already underway. Otherwise let the migration run.
What about staff who genuinely can't use a passkey?
There's a supported path. Microsoft lets organizations configure a customer-managed telecom provider through the Microsoft Security Store, which keeps SMS and voice available for legitimate business, regulatory, or technical needs. Users migrated to one of those providers don't get the blocking prompt.
Two catches. You have to set it up before the retirement date, and you have to migrate every affected user yourself. It's a real option for a clinic with shared workstations or a plant floor with no personal phones, but it's a project, not a checkbox.
The part worth saying out loud
This deadline is doing you a favor. CISA's phishing-resistant MFA guidance puts SMS and voice at the bottom of its list and describes them as "vulnerable to phishing, SS7, and SIM swap attacks," recommending they be used "only as a last resort MFA option." Microsoft is now enforcing what CISA has advised for years.
We wrote about the alternative in passkeys vs MFA, and the short version hasn't changed. A passkey can't be read aloud to a stranger on the phone, and it can't be typed into a fake login page.
Microsoft says migrating from Microsoft-provided SMS and voice to passkeys carries no additional cost. So the upgrade is free. The only expense is planning it before it plans itself.
Frequently asked questions
Do I have to buy anything to use passkeys?
No. Microsoft states that migrating Microsoft-provided SMS and voice users to passkeys incurs no additional cost. Passkeys work through the Microsoft Authenticator app on a phone, through Windows Hello on a managed PC, or through a hardware security key if you'd rather not involve personal devices.
What happens to a user whose only method is SMS on February 1, 2027?
They get a blocking passkey registration prompt at sign-in and can't skip it. They aren't locked out permanently, but they can't work until they complete registration. If they're remote, on a personal device, or unfamiliar with passkeys, that becomes a support call.
Does this break third-party MFA or our on-premises setup?
No. The retirement covers Microsoft-provided SMS and voice delivery. Third-party MFA providers and customer-managed telecom providers configured through the Microsoft Security Store are unaffected, as long as you migrate affected users to them before the retirement date.
Our admins are on SMS. Do we get until July 2027?
Technically yes. Global administrators and external users retire July 1, 2027 rather than February 1. Treat that as a trap rather than a reprieve. Admin accounts are the ones attackers want, and they're the accounts that should have moved off SMS years ago.
We use SMS for password resets, not sign-in. Are we fine?
No. The retirement applies across Entra, including self-service password reset. If your SSPR policy depends on a text message, it needs a different method registered before the date that applies to those users.
Get ahead of it
We're running this migration for clients across NY, NJ, CT, PA, and Southwest Florida right now: pull the affected-user list, register second methods, and handle the exceptions before the prompts start. If you'd like us to look at your tenant, book a complimentary assessment and we'll tell you how many users you're actually dealing with. Our Microsoft 365 management team can run the whole thing if you'd rather not.
Discuss multi-factor authentication deployment for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.



