Quick answer: Microsoft is retiring SMS text and automated phone-call multi-factor authentication (MFA) for Microsoft 365. Starting September 1, 2026, affected users will begin seeing prompts to register a passkey. On February 1, 2027, Microsoft-provided SMS and voice MFA stops working for good. Advanced Business Solutions is already identifying affected clients and managing the transition.
What is changing with Microsoft MFA?
Microsoft is not eliminating multi-factor authentication. It is retiring one specific delivery method: the text messages and automated phone calls many organizations currently use to verify sign-ins and reset passwords. Microsoft is replacing that method with passkeys, a phishing-resistant credential built on cryptographic key pairs instead of a code that can be intercepted, spoofed, or socially engineered.¹ Microsoft has said this shift is a direct response to how effectively AI-driven phishing now defeats text-based verification.When do these changes take effect?
Three dates matter, and the last one is the hard deadline:| Date | What happens |
|---|---|
| September 1, 2026 | Passkeys become the default. Users enabled for SMS or voice MFA are auto-enabled for passkeys and prompted at their next sign-in. |
| October 30, 2026 | Organizations that still need SMS or voice can configure a customer-managed telecom provider via the Microsoft Security Store. |
| February 1, 2027 | Microsoft-provided SMS and voice MFA stops working. No opt-out. Users with only that method are blocked until they register a passkey. |
What should my business do to prepare?
Here are ways your business can begin the transition:- Identify every employee who still relies on text or phone-call verification
- Select the right replacement (passkey, Microsoft Authenticator, Windows Hello, or a physical security key)
- Update Microsoft 365 settings and enrolled devices
- Communicate with your team before Microsoft’s own prompts start appearing
What should employees know?
Employees may start seeing Microsoft prompts asking them to set up a new sign-in method. They should never approve an authentication request they did not initiate themselves, and should contact IT support if a prompt looks unfamiliar or unexpected.Key takeaways
- MFA is not going away. Microsoft is replacing its weakest delivery method with a stronger one.
- The hard deadline is February 1, 2027. There is no opt-out and no extension.
- Employees using text or phone-call verification today will need to register a passkey or another approved method before that date.
- ABS can manage this transition end to end, including identifying who is affected and preparing devices and settings ahead of time.
Frequently Asked Questions
Is Microsoft getting rid of MFA?
No. Microsoft is retiring one delivery method, SMS and voice, and replacing it with passkeys and other phishing-resistant options. MFA itself remains required.
What if our organization still needs SMS or phone-based verification?
Microsoft will allow SMS and voice to continue through a customer-managed telecom provider available in the Microsoft Security Store, configurable starting October 30, 2026. ABS can help evaluate whether that is the right fit.
What happens if we miss the deadline?
Nothing is deleted or locked out permanently, but any employee whose only MFA method is text or phone call will hit a blocking prompt at sign-in and must register a passkey before they can continue working.
Contact Advanced Business Solutions:
- Phone: 502-896-2557
- Web: AdvancedBusinessSolutions.com
- Office: 1745 Payne Street, Louisville, KY 40206
Source
- Microsoft Learn, “Passkeys by default and retirement of Microsoft-provided SMS and voice authentication – Microsoft Entra ID” —
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement











