Microsoft has announced that its telecom delivery for SMS and voice authentication for Microsoft Entra ID will be fully retired on February 1, 2027. Starting September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra ID, automatically prompting users using weak MFA methods to register a passkey. Organizations should begin planning their transition to phishing-resistant authentication now to ensure a smooth migration before the February 2027 deadline.
Why Microsoft Is Sunsetting SMS & Voice
For years, SMS texts and phone calls served as the standard entry-level multi-factor authentication (MFA). However, modern attackers routinely bypass telephony-based MFA through SIM swapping, Man-in-the-Middle (MitM) reverse proxies, and social engineering.
The tipping point is the rise of AI-driven cyberthreats. Generative AI tools allow bad actors to scale personalized, convincing phishing attacks with alarming speed. According to Microsoft Threat Intelligence, AI-assisted phishing campaigns have reached click-through rates as high as 54%, compared to roughly 12% for traditional phishing campaigns.
Because SMS and voice authentication rely on shared secrets, they remain vulnerable to phishing, social engineering, SIM-swapping, and other account takeover techniques. Retiring these methods helps organizations move toward phishing-resistant authentication that provides stronger protection for Microsoft Entra ID environments.
Microsoft Entra ID’s Mandatory Passkey Rollout Timeline
Organizations have roughly six months before Microsoft begins automatically pushing users toward passkey registration.
Here are the key milestones every IT and security leader needs to track:
- Auto-Enablement and Registration Prompts Begin (September 1, 2026)
Passkeys become the default authentication experience in Microsoft Entra ID. Users whose only MFA method is SMS or voice will automatically be prompted to register a passkey upon their next sign-in if no other option (Authenticator app/FIDO key/etc) has been selected. - Telecom Provider Partner Details Released (September 18, 2026)
Microsoft releases documentation, commercial terms, and supported third-party carrier options in the Microsoft Security Store for organizations requiring legacy telephony fallback. - Security Store Configuration Opens (October 30, 2026)
Administrators can select, configure, and test third-party telecom integrations through the Microsoft Security Store for essential fallback groups or edge cases. - Native SMS and Voice Authentication Retired (February 1, 2027)
Microsoft officially ends native telecom delivery for SMS and voice MFA. Any organization without a third-party carrier integrated will see SMS/voice capabilities shut off. - Mandatory Passkey Enforcement (After February 1, 2027)
Automatic passkey registration prompts become mandatory for all users in all tenants without an opt-out option prior to signing in.
Why Your Passkey Strategy Needs to Start Right Now
February 2027 might sound far off, but implementing enterprise-wide passkeys requires deliberate planning across identity architecture, device readiness, and change management. Waiting until automated nudges begin in September 2026 risks user confusion, helpdesk spikes, and operational bottlenecks.
Key Microsoft Entra ID Passkey Steps to Take Immediately
- Audit Current Usage: Run Microsoft Entra ID sign-in logs to identify all user groups still relying on SMS or voice authentication.
- Define Allowed Passkey Types: Determine whether your compliance model requires hardware device-bound passkeys (FIDO2 keys) or permits synced platform passkeys.
- Establish Emergency Access: Ensure break-glass accounts and identity recovery workflows are transitioned to phishing-resistant credentials.
- Launch Change Communication: Prepare end users for the new sign-in flow well before automated registration prompts go live.
Will this change impact Self-Service Password Reset (SSPR)?
Yes, many organizations use SMS or voice verification as part of Self-Service Password Reset (SSPR) and account recovery workflows. Because Microsoft is retiring Microsoft-provided telecom delivery for SMS and voice authentication, organizations should review any password reset, recovery, or identity verification processes that depend on phone-based verification. Customers that must continue using SMS or voice after the retirement date will need to configure a supported telecom provider through the Microsoft Security Store.
How MajorKey Accelerates Your Phishing-Resistant Journey
Transitioning an enterprise identity infrastructure from legacy MFA to passwordless FIDO2 passkeys requires deep technical expertise and strategic execution. At MajorKey, our identity and access management experts specialize in guiding organizations through complex Microsoft Entra ID modernizations.
We can help you:
- Assess your current Microsoft Entra ID tenant security posture and user authentication profiles.
- Design a custom, phishing-resistant authentication roadmap tailored to your security requirements.
- Configure Microsoft Entra Conditional Access policies, FIDO2 key policies, and registration campaigns.
- Deliver tailored user enablement and support desk training to ensure a smooth, zero-friction rollout.
Don't wait for Microsoft's automated enforcement to dictate your deployment schedule. Contact MajorKey today to build and execute your phishing-resistant passkey strategy.
Frequently Asked Questions
Why is Microsoft Entra ID sunsetting SMS and voice authentication?
Microsoft is retiring native SMS and voice MFA because telephony-based channels rely on unencrypted, shared secrets that can be intercepted, spoofed, or socially engineered. In an era where AI-driven phishing campaigns achieve click-through rates as high as 54%, SMS codes and automated phone calls no longer provide adequate protection.
When do I need to switch to passkeys in Microsoft Entra ID?
Beginning on February 1, 2027, users who rely only on SMS or voice authentication may be prompted to register a passkey or another approved authentication method before the can continue signing in. Users who have already registered a supported authentication method, such as a passkey, Microsoft Authenticator, or another approved method, will not be impacted by this change.
What happens if our organization must keep SMS or voice for compliance or operational reasons?
While native Microsoft-provided telecom delivery ends on February 1, 2027, organizations with regulatory, technical, or operational dependencies can transition to third-party telecom carriers. Starting October 30, 2026, administrators can select, configure, and manage supported third-party providers through the Microsoft Security Store. Note that organizations will contract directly with carriers and be responsible for any associated telecom fees.
Can Microsoft Entra ID users opt out of passkeys after the February 1, 2027 deadline?
No. After February 1, 2027, Microsoft will permanently retire native SMS/voice delivery and enforce passkey registration across all tenants in the public cloud. Automatic prompts will become blocking for non-compliant users, and temporary opt-out mechanisms will no longer be available.
What are passkeys?
Passkeys are phishing-resistant, passwordless credentials built on open FIDO2 and W3C WebAuthn standards. Instead of transmitting a shared secret (like a password or SMS code) over a network, passkeys use public-key cryptography: a private key stays securely encrypted on the user's local device, while Microsoft Entra ID registers the matching public key.
What types of passkeys does Microsoft Entra ID support?
- Device-Bound Passkeys: Hardware-isolated credentials stored on a single physical device that cannot be exported or synchronizeded across devices. Examples include FIDO2 security keys (like YubiKeys), Microsoft Authenticator device-bound passkeys, and Microsoft Entra passkeys, on Windows (such as Windows Hello for Business and Microsoft Authenticator device-bound passkeys).
- Synced Passkeys: Encrypted credentials stored in platform credential managers that sync across a user's ecosystem for convenience, such as Apple iCloud Keychain or Google Password Manager.
How will Microsoft Entra ID’s automatic passkey registration prompt affect my end users?
Starting September 1, 2026, Microsoft Entra ID will begin auto-enabling passkeys for users enabled for SMS or voice MFA. When these users sign in, they will receive an automated registration prompt ("nudge") guiding them to set up a passkey on their device. During the rollout window, users can temporarily skip the prompt, but after February 1, 2027, passkey registration will become mandatory before sign-in can proceed.
What is SIM swapping?
SIM swapping is an identity theft technique where an attacker tricks or bribes a mobile carrier customer service representative into porting a target victim’s phone number to an attacker-controlled SIM card. Once transferred, the bad actor receives all incoming phone calls and text messages meant for the victim, allowing them to easily intercept one-time SMS passcodes and hijack accounts without ever needing physical access to the victim’s device.
What are Man-in-the-Middle (MitM) Proxies?
A Man-in-the-Middle (MitM) or Adversary-in-the-Middle (AiTM) reverse proxy (such as Evilginx) is an automated attack platform that sits invisibly between a user and a legitimate login portal. When a victim attempts to log in, the proxy mirrors the authentic sign-in page in real time. As the user enters their password and two-factor SMS code, the proxy captures both inputs and steals the active session cookie, thereby granting the attacker complete access to the account while bypassing traditional MFA entirely.