Microsoft is retiring its own SMS and voice MFA. Here's your plan.
Microsoft-provided text and phone call authentication in Entra ID ends for most users on 1 February 2027. Passkeys are already being switched on. What changes, when, and what to do now.
On this page
This is the biggest authentication change in Entra ID for years. Microsoft is retiring the SMS and voice call authentication it delivers itself, and is pushing users towards passkeys instead. If any of your users still verify with a text message or a phone call, this affects you.
- 01SMS or voice MFA today
- 021 Sep 2026: passkeys auto-enabled
- 03Registration campaign nudges users
- 041 Feb 2027: blocking prompt
- 051 Jul 2027: admins and external users
What's actually retiring
The change covers Microsoft-provided SMS and voice: the codes and calls Microsoft's own telephony service sends. It applies to SMS and voice in the Authentication Methods Policy, to the legacy MFA settings, and across Entra including self-service password reset.
Two things are not retiring. External MFA methods are unaffected. And organisations that genuinely need SMS or voice can keep it by contracting with a third-party telephony provider through the Microsoft Security Store.
The scope is the public cloud. Government clouds follow later, Azure AD B2C is out of scope, and External ID is getting its own announcement.
The timeline
| Date | What happens |
|---|---|
| 1 Sep 2026 | Passkeys are switched on automatically for users enabled for SMS or voice. A Microsoft-managed registration campaign nudges them to register a passkey at their next MFA sign-in. They can snooze it. |
| 30 Oct 2026 | Third-party telephony providers become configurable in the Microsoft Security Store. |
| 1 Feb 2027 | Retirement for all users except Global Administrators and external users. Anyone whose only method is SMS or voice gets a blocking prompt to register a passkey. |
| 1 Jul 2027 | Retirement for Global Administrators and external users. |
Users won't be locked out. Anyone still relying only on SMS or voice gets a registration prompt they can't skip, and must set up a passkey before carrying on. For a busy service desk, that's still a Monday morning you want to avoid.
- Passkeys auto-enabled; registration nudges start
- Third-party telephony providers available
- Retirement for most users
- Global Admins and external users
What to do now
- Measure your exposure. Microsoft publishes an
entra-sms-voice-usage-analyzerPowerShell script on GitHub. It reports which users are in scope of SMS and voice in your authentication methods policies. Any non-zero result means your tenant is affected. - Decide passkeys or provider. Without a regulatory or operational reason to keep SMS, plan for passkeys. If you do need SMS, line up a telephony provider and move users before their retirement date.
- Plan your passkey rollout. Use passkey profiles to set different rules for admins and standard users, and decide whether synced passkeys (stored in a passkey provider and shared across devices) are acceptable for each group.
- Use the registration campaign. It now supports passkeys, so users are prompted at sign-in rather than chased by email.
- Don't forget the edges. Shared mailboxes with MFA, break-glass accounts, frontline workers without smartphones and guests all need a plan.
Who is affected, in practice
The users who feel this most are the ones who have only SMS or voice registered. Anyone who already has Microsoft Authenticator, a passkey or Windows Hello for Business simply carries on with those. So the real work is finding the SMS-only group and moving them before the deadline.
Typical SMS-only groups are frontline staff without company phones, people who joined before Authenticator was standard, and shared or service-style accounts that someone set up with a phone number years ago.
A rollout plan that works
- Weeks 1 to 2: measure. Run the analyzer script, then export the authentication methods registration report to get a named list of SMS-only users.
- Weeks 2 to 3: decide the exceptions. Agree how you'll handle users with no smartphone: a FIDO2 security key, Windows Hello for Business on a managed PC, or a third-party SMS provider.
- Weeks 3 to 4: communicate. Tell users what a passkey is and what the prompt will look like, before they see it.
- Weeks 4 to 8: campaign. Let the registration campaign prompt people at sign-in. Limit snoozes once most users have registered.
- Ongoing: chase the tail. Contact the remaining SMS-only users directly, and issue Temporary Access Passes where people are stuck.
Need more time?
There's a temporary opt-out that delays the automatic passkey enablement and registration campaign until 1 February 2027, while you set up a provider or migrate users. It's set through Graph:
PATCH https://graph.microsoft.com/beta/policies/authenticationmethodspolicy
Content-Type: application/json
{
"optOutSettings": {
"passkeyDynamicMigration": true
}
}Questions people ask
Will users be locked out on 1 February 2027?
No. Users who still rely only on Microsoft-provided SMS or voice get a blocking prompt to register a passkey and can carry on once they have.
Is SMS still allowed for self-service password reset?
Microsoft's FAQ says the retirement applies across Entra, including SSPR. Organisations that need SMS can use a telephony provider from the Microsoft Security Store.
Does this affect external MFA providers?
No. External MFA methods aren't affected, unless the same users are also enabled for Microsoft's SMS or voice.
Does the opt-out stop the retirement?
No. It only delays automatic passkey enablement and the registration campaign until 1 February 2027.