Newsletter
Stay up to date with our monthly newsletter.
Covering the latest thought leadership, events, and news about identity security
What We Do
Partners
© MajorKey 2026

Microsoft has announced that its telecom delivery for SMS and voice authentication for Microsoft Entra ID will be fully retired on February 1, 2027. Starting September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra ID, automatically prompting users using weak MFA methods to register a passkey. Organizations should begin planning their transition to phishing-resistant authentication now to ensure a smooth migration before the February 2027 deadline.
For years, SMS texts and phone calls served as the standard entry-level multi-factor authentication (MFA). However, modern attackers routinely bypass telephony-based MFA through SIM swapping, Man-in-the-Middle (MitM) reverse proxies, and social engineering.
The tipping point is the rise of AI-driven cyberthreats. Generative AI tools allow bad actors to scale personalized, convincing phishing attacks with alarming speed. According to Microsoft Threat Intelligence, AI-assisted phishing campaigns have reached click-through rates as high as 54%, compared to roughly 12% for traditional phishing campaigns.
Because SMS and voice authentication rely on shared secrets, they remain vulnerable to phishing, social engineering, SIM-swapping, and other account takeover techniques. Retiring these methods helps organizations move toward phishing-resistant authentication that provides stronger protection for Microsoft Entra ID environments.
Organizations have roughly six months before Microsoft begins automatically pushing users toward passkey registration.
Here are the key milestones every IT and security leader needs to track:
February 2027 might sound far off, but implementing enterprise-wide passkeys requires deliberate planning across identity architecture, device readiness, and change management. Waiting until automated nudges begin in September 2026 risks user confusion, helpdesk spikes, and operational bottlenecks.
Yes, many organizations use SMS or voice verification as part of Self-Service Password Reset (SSPR) and account recovery workflows. Because Microsoft is retiring Microsoft-provided telecom delivery for SMS and voice authentication, organizations should review any password reset, recovery, or identity verification processes that depend on phone-based verification. Customers that must continue using SMS or voice after the retirement date will need to configure a supported telecom provider through the Microsoft Security Store.
Transitioning an enterprise identity infrastructure from legacy MFA to passwordless FIDO2 passkeys requires deep technical expertise and strategic execution. At MajorKey, our identity and access management experts specialize in guiding organizations through complex Microsoft Entra ID modernizations.
We can help you:
Don't wait for Microsoft's automated enforcement to dictate your deployment schedule. Contact MajorKey today to build and execute your phishing-resistant passkey strategy.
Microsoft is retiring native SMS and voice MFA because telephony-based channels rely on unencrypted, shared secrets that can be intercepted, spoofed, or socially engineered. In an era where AI-driven phishing campaigns achieve click-through rates as high as 54%, SMS codes and automated phone calls no longer provide adequate protection.
Beginning on February 1, 2027, users who rely only on SMS or voice authentication may be prompted to register a passkey or another approved authentication method before the can continue signing in. Users who have already registered a supported authentication method, such as a passkey, Microsoft Authenticator, or another approved method, will not be impacted by this change.
While native Microsoft-provided telecom delivery ends on February 1, 2027, organizations with regulatory, technical, or operational dependencies can transition to third-party telecom carriers. Starting October 30, 2026, administrators can select, configure, and manage supported third-party providers through the Microsoft Security Store. Note that organizations will contract directly with carriers and be responsible for any associated telecom fees.
No. After February 1, 2027, Microsoft will permanently retire native SMS/voice delivery and enforce passkey registration across all tenants in the public cloud. Automatic prompts will become blocking for non-compliant users, and temporary opt-out mechanisms will no longer be available.
Passkeys are phishing-resistant, passwordless credentials built on open FIDO2 and W3C WebAuthn standards. Instead of transmitting a shared secret (like a password or SMS code) over a network, passkeys use public-key cryptography: a private key stays securely encrypted on the user's local device, while Microsoft Entra ID registers the matching public key.
Starting September 1, 2026, Microsoft Entra ID will begin auto-enabling passkeys for users enabled for SMS or voice MFA. When these users sign in, they will receive an automated registration prompt ("nudge") guiding them to set up a passkey on their device. During the rollout window, users can temporarily skip the prompt, but after February 1, 2027, passkey registration will become mandatory before sign-in can proceed.
SIM swapping is an identity theft technique where an attacker tricks or bribes a mobile carrier customer service representative into porting a target victim’s phone number to an attacker-controlled SIM card. Once transferred, the bad actor receives all incoming phone calls and text messages meant for the victim, allowing them to easily intercept one-time SMS passcodes and hijack accounts without ever needing physical access to the victim’s device.
A Man-in-the-Middle (MitM) or Adversary-in-the-Middle (AiTM) reverse proxy (such as Evilginx) is an automated attack platform that sits invisibly between a user and a legitimate login portal. When a victim attempts to log in, the proxy mirrors the authentic sign-in page in real time. As the user enters their password and two-factor SMS code, the proxy captures both inputs and steals the active session cookie, thereby granting the attacker complete access to the account while bypassing traditional MFA entirely.