SMS and Voice MFA Are Being Retired — And It's the Right Call
- Kostas Tsiolas
- Jul 16
- 6 min read
Microsoft is making passkeys the default in Entra ID and phasing out phishable SMS and voice authentication. Here's why that decision is overdue, what the risks really were, and how to migrate without locking your users out.

Microsoft has set a hard deadline for a method most security teams already distrusted but few had the mandate to remove.
Starting 1 September 2026, passkeys become the default authentication experience in Microsoft Entra ID. On 1 February 2027, Microsoft retires its own SMS and voice authentication entirely. After that date, any user whose only second factor is a text message or a phone call cannot sign in until they register a passkey.
Not discouraged. Retired.
For a decade, "we have MFA" has been treated as a finished sentence. This change forces a more honest one: which MFA — and can an attacker phish it?
Our view is simple. Microsoft is right, and the reasoning matters more than the deadline.
MFA was never one thing
The industry sold multi-factor authentication as a single control. It was always a spectrum.
At one end sit phishing-resistant methods bound to cryptography and to the legitimate service. At the other sit shared secrets — codes that travel over channels an attacker can intercept, redirect, or simply ask the user to hand over. SMS one-time passcodes and voice calls have always lived at that weaker end. They expanded MFA to billions of people who otherwise had none, which was a genuine win. But the security they provide has been eroding for years.
Here is what a text message actually exposes you to:
SIM swapping. An attacker convinces (or bribes) a mobile carrier to port a victim's number to a new SIM. Every "secure" code now arrives on the attacker's device. This has moved from a targeted, high-effort attack to a repeatable service.
Network and interception attacks. The telephony signalling that carries SMS was never designed as a secure channel. Codes can be intercepted in transit without ever touching the victim's phone.
Real-time phishing (adversary-in-the-middle). This is the one that ends the debate. Modern phishing kits proxy the real login page. The victim enters their password and their SMS code into a convincing fake, and the kit relays both to the genuine service in real time — capturing the resulting session. The one-time code being "one-time" makes no difference; it is used once, instantly, by the attacker.
Social engineering. Help desks and users are manipulated into reading out codes or approving prompts. No exploit required — just a plausible story.
None of this is new. What is new is the speed and scale.
The AI era changed the maths
Phishing used to be a numbers game with poor conversion. That has changed.
Microsoft Threat Intelligence reports that AI-enabled phishing campaigns are reaching click-through rates as high as 54%, compared with roughly 12% for traditional campaigns. More than half the recipients of a well-crafted, AI-generated lure now engage with it.
The consequence isn't only that more people get phished. It's what happens after a credential falls. As Microsoft puts it, an AI-driven attack can automate discovery, privilege escalation, and lateral movement far faster than a human working manually. The window between "one user clicked" and "the environment is compromised" is collapsing.
When the entry cost of a successful phish drops and the blast radius expands, a second factor an attacker can relay in real time stops being a control. It becomes a false sense of security — arguably worse than none, because it justifies inaction.
That is the real argument for retirement. Not that SMS is imperfect. That the threat environment has outgrown it.
Why passkeys are the right answer
Passkeys solve the problem at the root rather than patching the symptom.
A passkey is a credential built on public-key cryptography. When it's created, a private key never leaves the user's device and a corresponding public key is registered with the service. There is no shared secret to intercept, no code to read out, nothing to type into a fake page. The credential is cryptographically bound to the legitimate service, so a proxied phishing site simply cannot use it.
That single design choice defeats the entire attack list above — SIM swaps, interception, real-time relay, and social engineering — because there is nothing transferable for an attacker to capture.
Two more points close the business case:
It costs nothing extra. Passkeys are included in every Entra plan. For most organisations, the recommended path — moving users to passkeys — carries no additional licensing cost.
It's the standard Microsoft holds itself to. Microsoft reports it has already reached phishing-resistant authentication coverage across 99.6% of its own users and devices by eliminating legacy methods.
Microsoft's own framing is blunt, and accurate: passkeys work better for users and worse for attackers.
The technical detail worth getting right
For the teams who will actually run this, a few decisions matter more than the headline.
Synced vs device-bound passkeys. Entra ID supports both, and they are not interchangeable:
Synced passkeys live in a platform credential manager (iCloud Keychain, Google Password Manager) and roam across a user's devices. They are convenient and low-cost — the right default for most of the workforce.
Device-bound passkeys (Microsoft Authenticator, Entra passkey on Windows, FIDO2 security keys) stay on a single authenticator and support device attestation. These are the correct choice for privileged accounts and highly regulated contexts, where you need assurance about which authenticator is in use.
Map this to your user groups deliberately. Treating every user the same is how rollouts stall.
The rollout timeline:
Date | What happens |
1 Sep 2026 | Passkeys become the default. Users on SMS/voice are auto-enabled for passkeys and prompted to register at MFA sign-in (they can skip, for now). |
18 Sep 2026 | Microsoft publishes supported telecom providers, pricing, and commercial terms via the Microsoft Security Store. |
30 Oct 2026 | Admins can select and configure a third-party telecom provider (if SMS/voice must be retained). |
1 Feb 2027 | Microsoft-provided SMS/voice is retired. Passkey enrolment is enforced for all in-scope users, with no admin opt-out. Users whose only method is SMS/voice must register a passkey to sign in. |
A temporary opt-out is available between 1 September 2026 and 1 February 2027, to give teams room to configure a telecom provider or migrate to another method. It disappears at enforcement.
Two caveats worth stating plainly. These dates apply to Microsoft Entra ID in the public cloud only — government and sovereign clouds follow separate, not-yet-announced schedules. And if a genuine regulatory or business need requires keeping SMS or voice, Microsoft recommends configuring a customer-managed telecom provider at least four weeks before the February enforcement to allow testing.
For EU organisations, this also lands squarely inside the direction NIS2 is already pushing — stronger authentication and demonstrable access control. This change simply attaches a date to something regulation was going to require anyway.
This isn't a switch you flip
The technology is the easy part. Rollouts break at the edges, and those edges are predictable:
Shared, frontline, and kiosk devices with no personal authenticator
Users without a smartphone
Legacy and line-of-business applications still wired to SMS OTP
Break-glass and emergency-access accounts that need careful, non-phishable recovery
The market data confirms this is where organisations get stuck. A FIDO Alliance and HID survey of IT and security decision-makers found roughly 93% of organisations are somewhere in passkey adoption — but only about 13% have deployed at scale. Intent is nearly universal. Execution is rare. The gap is almost always the edge cases, not the core rollout.
Treat February 2027 as a January problem and you inherit a lockout wave and a help-desk spike at the worst possible moment. Treat it as a governance exercise now and it becomes routine.
What to do before September
Discover. Identify every user and application still dependent on SMS or voice. You cannot migrate what you haven't mapped.
Decide the passkey model per group. Synced for the general workforce; device-bound or FIDO2 for privileged and regulated users.
Run a voluntary registration campaign early. Enrolment by choice, months ahead, is always smoother than enrolment under an enforced prompt.
Solve the edge cases deliberately. Shared devices, no-smartphone users, legacy apps, and break-glass accounts each need a decision — made calmly now, not in a crisis in February.
Decide on telephony honestly. If a real requirement forces you to retain SMS/voice, plan the third-party provider configuration and pilot it. If not, don't recreate the weakness you're being helped to remove.
The business consequence
The cost of inaction here isn't abstract. It's users unable to log in on 1 February 2027, a support queue that spikes on the same day, and — until migration completes — a phishable second factor sitting in front of your most sensitive systems during the most active phishing period the industry has seen.
The cost of acting is a planned, low-drama project spread across the months you've been given. It is genuinely easier to govern this now than to firefight it in thirteen months.
How Nimbus Cyber can help
We help medium and large organisations turn identity changes like this into controlled projects rather than deadline scrambles: discovering where phishable methods still live, designing the passkey rollout across workforce and privileged users, handling the edge cases, and aligning the whole thing with Zero Trust and NIS2 obligations.
If SMS or voice is still in your environment, the best time to plan the exit is before the prompts start appearing for your users.
Talk to us about an identity and authentication readiness review — and walk into September with a plan, not a surprise.
Sources: Microsoft 365 Message Center, Message ID MC1426371 ("Microsoft Entra: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication"); Microsoft Security Blog, "Passkeys are the default authentication method in Entra ID" (July 2026); Microsoft Learn — SMS and voice retirement guidance: https://learn.microsoft.com/entra/identity/authentication/concept-sms-voice-retirement



Comments