Microsoft is ending support for SMS and voice multi-factor authentication in Entra ID, replacing them with phishing-resistant passkeys. Relying on phone codes already exposes your organization to interception and SIM-swapping risks. Preparing your business now ensures uninterrupted sign-ins and protects your shared operational resilience.
Why Legacy Authentication Methods Are Retiring
For years, text messages and automated phone calls served as the standard second factor for logging into corporate accounts. While they were an improvement over single passwords, cybercriminals have adapted. Modern attack techniques—such as SIM swapping, phone number porting, and automated phishing proxies—allow malicious actors to intercept or bypass SMS verification codes with ease.
How much operational damage could an attacker inflict if they intercepted a single text message code and accessed your network?
Protecting an organization's digital perimeter is not merely a technical chore; it is a shared duty to safeguard your employees, clients, and vendor partners. Continuing to rely on outdated verification channels leaves an open invitation for automated attacks. That is an unacceptable risk.
To address these vulnerabilities, Microsoft is transitioning all Microsoft Entra ID tenants to passkeys. Passkeys use cryptographic key pairs tied directly to an individual's device. Because passkeys are cryptographically bound to specific domain names, they cannot be tricked by deceptive phishing websites.
Key Timeline Dates for Your Transition
Microsoft is carrying out this transition in phases to allow organizations adequate time to prepare their teams and update their authentication policies.
- September 1, 2026 - Users currently enabled for SMS or voice authentication will be automatically enabled for passkeys. Upon their next sign-in, they will receive a prompt encouraging them to register a passkey.
- February 1, 2027 - Microsoft-provided SMS and voice authentication delivery will be fully retired across Microsoft Entra ID.
- After February 1, 2027 - Any user whose only registered authentication method is SMS or voice will encounter a mandatory blocking prompt. They will be unable to proceed to their account until they register a passkey.
Is it wise to wait until your staff faces unexpected login blocks during an active workday? No.
Recommended Action Steps for Business Leaders
Transitioning your workforce away from SMS-based authentication requires methodical execution to prevent operational friction.
- Audit Your Tenant - Identify which users across your Microsoft Entra ID tenant are currently using SMS or voice for authentication.
- Enable Passkeys and Drive Adoption - Enable passkeys in your authentication policy and launch an internal registration campaign to drive adoption before automatic prompts take effect.
- Communicate Changes Clearly - Notify your staff about the change, explaining why passkeys are being introduced and what steps they must take.
- Evaluate Custom Telecom Options - If your business has explicit regulatory or operational requirements to retain SMS or voice, configure a customer-managed telecom provider through the Microsoft Security Store before the deadline.
Taking care of these requirements ahead of schedule keeps your daily operations moving without interruption. Problem solved.
If you need guidance auditing your Microsoft Entra ID policies or rolling out passkeys across your organization, call us today at (410) 531-6727.
Comments