Microsoft Is Phasing Out SMS MFA. What Does That Mean for Your Business?

Are Your Users Ready for Passkeys?
September 30, 2026 Caleb Hahn MFA, Passkeys
← Back to Blogs
5 MIN READ

For many business leaders, turning on multifactor authentication (MFA) felt like crossing an important cybersecurity milestone. Employees entered their passwords, received a text message with a code, and security improved significantly.

For years, that approach was considered a practical and effective way to reduce account compromise.

Now Microsoft is signaling that the future of authentication looks very different.

Beginning in 2026 and continuing through 2027, Microsoft is making passkeys the default authentication experience within Entra ID and retiring Microsoft-provided SMS and voice authentication services. Organizations that still rely heavily on text-message authentication should begin evaluating what these changes mean for users, business processes, and long-term security planning.

For many small and midsize organizations, this is not simply a technology update. It is part of a larger shift away from passwords and text-based authentication toward phishing-resistant identity protection.

Why Microsoft Is Moving Away from SMS Authentication

When multifactor authentication first became widely adopted, text messages offered a relatively simple way to add security.

The concept was straightforward. Even if someone stole a password, they would still need access to the employee’s phone to receive a verification code.

Unfortunately, attackers adapted.

Today, cybercriminals routinely target authentication processes through phishing websites, social engineering, SIM-swapping attacks, and credential theft. While SMS-based MFA remains more secure than password-only authentication, it is increasingly viewed as a weaker authentication method compared to newer alternatives.

Microsoft’s recent announcement reflects a broader industry movement toward phishing-resistant authentication methods that are far more difficult to intercept, steal, or manipulate.

For business leaders, the important takeaway is not that SMS MFA suddenly became ineffective. Rather, security standards continue to evolve, and major technology providers are adjusting their platforms accordingly.

What Is Changing?

Microsoft’s published timeline outlines several important milestones.

Beginning September 1, 2026, users enabled for SMS or voice authentication may be automatically encouraged to register passkeys as part of Microsoft’s broader passkey adoption strategy.

On February 1, 2027, Microsoft-provided SMS and voice authentication services will be retired for most users. Organizations that continue relying on these methods will need to transition users to phishing-resistant authentication methods or implement alternative telephony providers.

Additional retirement milestones for administrators and certain external users follow later in 2027.

The practical implication is that businesses using Microsoft 365 should begin understanding their current authentication landscape well before these deadlines arrive.

How Passkeys Fit into the Picture

The centerpiece of Microsoft’s strategy is increased passkey adoption.

A passkey replaces traditional password-based authentication with cryptographic credentials stored on a trusted device. Rather than entering a password and waiting for a text message, users authenticate using their device, often through a fingerprint, facial recognition, or another built-in security mechanism.

From a user perspective, the process is often faster and simpler.

From a security perspective, the benefits are more significant.

Because passkeys are resistant to phishing, SIM-swapping, replay attacks, and many forms of credential theft, they reduce several of the most common pathways attackers use to compromise business accounts. Microsoft has specifically positioned passkeys as its preferred phishing-resistant authentication method moving forward.

Why This Matters for Small and Mid-Sized Businesses

Large enterprises often have dedicated identity management teams responsible for authentication strategy.

Most organizations in Eugene, Springfield, and throughout Lane County do not.

Instead, authentication decisions are frequently made by business owners, office managers, practice administrators, CFOs, or trusted IT partners. As a result, platform changes like this can easily go unnoticed until they begin affecting employee sign-in processes.

Organizations should consider several questions:

  • How many employees currently use text-message MFA?
  • Are there legacy applications that depend on older authentication methods?
  • What procedures exist if an employee loses a phone or replaces a device?
  • Are there compliance, insurance, or regulatory requirements that affect authentication practices?
  • Has the organization established a long-term identity security strategy?

These questions become increasingly important as Microsoft continues moving customers toward passwordless and phishing-resistant authentication methods.

Preparing for the Transition

Most businesses do not need to make dramatic changes immediately.

However, leadership teams should understand that authentication is increasingly becoming a governance issue rather than simply an IT issue.

A thoughtful approach may include:

  • Reviewing current Microsoft 365 authentication methods
  • Identifying users who rely exclusively on SMS-based MFA
  • Evaluating passkey readiness across devices and workflows
  • Reviewing cyber insurance and compliance expectations
  • Updating user onboarding and account recovery procedures
  • Communicating upcoming changes to employees before they become mandatory

Organizations that begin planning early typically experience fewer disruptions than those forced to react to platform changes later.

Looking Ahead

Microsoft’s announcement is part of a broader industry shift away from passwords and text-based authentication toward phishing-resistant identity protection. The retirement of Microsoft-provided SMS and voice authentication signals that organizations should no longer view text-message MFA as their long-term authentication strategy.

For business leaders, the goal is not to chase every new security trend. It is to understand how changes from major technology providers may affect operations, risk management, compliance obligations, and employee productivity.

Organizations throughout Eugene, Springfield, and the greater Willamette Valley should use the coming transition period to evaluate their authentication practices, document recovery procedures, and develop a practical roadmap for stronger identity security.

Emerald Technology Group helps businesses assess Microsoft 365 security, understand evolving identity requirements, and plan authentication changes in ways that align with operational realities. As Microsoft continues its push toward passkeys and phishing-resistant authentication, thoughtful planning today can help avoid unnecessary disruptions tomorrow.

Share this post

What to read next

Back to Blogs