Microsoft is making significant changes to how users authenticate their accounts in Microsoft 365 and Microsoft Entra ID.
If you currently use text messages (SMS) or phone calls to verify your identity as part of Multi-Factor Authentication (MFA), you will begin seeing prompts from Microsoft encouraging you to move to a more secure authentication method from 1st September 2026. Microsoft plans to fully retire its SMS and voice call MFA services on 1st February 2027, meaning you will need to transition to an alternative authentication method by this date.
Why Is Microsoft Making This Change?
As cyber threats continue to evolve traditional phone-based authentication methods are increasingly vulnerable to attacks such as:
- Phishing
- SIM swapping
- Social engineering
- Interception of verification codes
To improve security, Microsoft is encouraging organisations to adopt phishing-resistant authentication methods, including passkeys, Microsoft Authenticator, Windows Hello for Business, and FIDO2 security keys.
What Happens From 1 September 2026?
Starting from 01st September 2026, if you are currently using SMS or phone call verification as your Microsoft 3665 MFA verification method, you will begin receiving prompts from Microsoft to register a passkey when you complete MFA. These prompts are designed to help users transition in advance of the retirement date.
At this time:
- You will still be able to use SMS or phone call verification.
- You may start seeing registration prompts for passkeys.
- No immediate action is required, but Microsoft strongly recommends registering a more secure authentication method.
What Happens On 1 February 2027?
From 01st February 2027, Microsoft will stop all SMS and voice call authentication services within Microsoft 365 and Entra ID.
For most organisations, this means users should already be using one of the following authentication methods:
- Passkeys
- Microsoft Authenticator App
- Windows Hello for Business
- FIDO2 Security Keys
Users who only have SMS or voice configured may be required to register a passkey before they can continue signing in.
What Is a Passkey?
A passkey is a modern authentication method that replaces verification codes with a more secure and user-friendly experience.
Passkeys use your device’s built-in security features, such as:
- Face recognition
- Fingerprint authentication
- Device PIN
Because passkeys cannot be intercepted or reused in the same way as text message codes, they provide significantly stronger protection against phishing attacks.
What Should You Do Now?
We recommend that customers:
- Review the MFA methods currently used within their organisation.
- Identify any users relying on SMS or phone call verification.
- Register Microsoft Authenticator or passkeys where possible.
- Ensure users are familiar with the new sign-in experience ahead of February 2027.
Taking action early will help avoid disruption and ensure a smooth transition.
Need Help?
If you’re unsure which authentication methods are currently being used in your Microsoft 365 environment or would like assistance planning your transition away from SMS and phone call verification, contact your IT Support provider who should be able to assist you.
If you are a Techsol customer, contact our Support Team and we will help assess your current setup and recommend the best approach for your organisation.
Get in touch with our experts on 03300 245447 or info@techsol.co.uk.


