Microsoft Entra ID Retires SMS & Voice Authentication: Why Passkeys Are the New Default

July 23, 2026
|
Duration:
4
min READ

Microsoft has announced that its telecom delivery for SMS and voice authentication for Microsoft Entra ID will be fully retired on February 1, 2027. Starting September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra ID, automatically prompting users using weak MFA methods to register a passkey. Organizations should begin planning their transition to phishing-resistant authentication now to ensure a smooth migration before the February 2027 deadline.

Why Microsoft Is Sunsetting SMS & Voice

For years, SMS texts and phone calls served as the standard entry-level multi-factor authentication (MFA). However, modern attackers routinely bypass telephony-based MFA through SIM swapping, Man-in-the-Middle (MitM) reverse proxies, and social engineering.

The tipping point is the rise of AI-driven cyberthreats. Generative AI tools allow bad actors to scale personalized, convincing phishing attacks with alarming speed. According to Microsoft Threat Intelligence, AI-assisted phishing campaigns have reached click-through rates as high as 54%, compared to roughly 12% for traditional phishing campaigns.

Because SMS and voice authentication rely on shared secrets, they remain vulnerable to phishing, social engineering, SIM-swapping, and other account takeover techniques. Retiring these methods helps organizations move toward phishing-resistant authentication that provides stronger protection for Microsoft Entra ID environments.

Microsoft Entra ID’s Mandatory Passkey Rollout Timeline

Organizations have roughly six months before Microsoft begins automatically pushing users toward passkey registration.

Here are the key milestones every IT and security leader needs to track:

  1. Auto-Enablement and Registration Prompts Begin (September 1, 2026)
    Passkeys become the default authentication experience in Microsoft Entra ID. Users whose only MFA method is SMS or voice will automatically be prompted to register a passkey upon their next sign-in if no other option (Authenticator app/FIDO key/etc) has been selected.
  2. Telecom Provider Partner Details Released (September 18, 2026)
    Microsoft releases documentation, commercial terms, and supported third-party carrier options in the Microsoft Security Store for organizations requiring legacy telephony fallback.
  3. Security Store Configuration Opens (October 30, 2026)
    Administrators can select, configure, and test third-party telecom integrations through the Microsoft Security Store for essential fallback groups or edge cases.
  4. Native SMS and Voice Authentication Retired (February 1, 2027)
    Microsoft officially ends native telecom delivery for SMS and voice MFA. Any organization without a third-party carrier integrated will see SMS/voice capabilities shut off.
  5. Mandatory Passkey Enforcement (After February 1, 2027)
    Automatic passkey registration prompts become mandatory for all users in all tenants without an opt-out option prior to signing in.

Why Your Passkey Strategy Needs to Start Right Now

February 2027 might sound far off, but implementing enterprise-wide passkeys requires deliberate planning across identity architecture, device readiness, and change management. Waiting until automated nudges begin in September 2026 risks user confusion, helpdesk spikes, and operational bottlenecks.

Key Microsoft Entra ID Passkey Steps to Take Immediately

  • Audit Current Usage: Run Microsoft Entra ID sign-in logs to identify all user groups still relying on SMS or voice authentication.
  • Define Allowed Passkey Types: Determine whether your compliance model requires hardware device-bound passkeys (FIDO2 keys) or permits synced platform passkeys.
  • Establish Emergency Access: Ensure break-glass accounts and identity recovery workflows are transitioned to phishing-resistant credentials.
  • Launch Change Communication: Prepare end users for the new sign-in flow well before automated registration prompts go live.

Will this change impact Self-Service Password Reset (SSPR)?

Yes, many organizations use SMS or voice verification as part of Self-Service Password Reset (SSPR) and account recovery workflows. Because Microsoft is retiring Microsoft-provided telecom delivery for SMS and voice authentication, organizations should review any password reset, recovery, or identity verification processes that depend on phone-based verification. Customers that must continue using SMS or voice after the retirement date will need to configure a supported telecom provider through the Microsoft Security Store.

How MajorKey Accelerates Your Phishing-Resistant Journey

Transitioning an enterprise identity infrastructure from legacy MFA to passwordless FIDO2 passkeys requires deep technical expertise and strategic execution. At MajorKey, our identity and access management experts specialize in guiding organizations through complex Microsoft Entra ID modernizations.

We can help you:

  • Assess your current Microsoft Entra ID tenant security posture and user authentication profiles.
  • Design a custom, phishing-resistant authentication roadmap tailored to your security requirements.
  • Configure Microsoft Entra Conditional Access policies, FIDO2 key policies, and registration campaigns.
  • Deliver tailored user enablement and support desk training to ensure a smooth, zero-friction rollout.

Don't wait for Microsoft's automated enforcement to dictate your deployment schedule. Contact MajorKey today to build and execute your phishing-resistant passkey strategy.


Frequently Asked Questions

Why is Microsoft Entra ID sunsetting SMS and voice authentication?

Microsoft is retiring native SMS and voice MFA because telephony-based channels rely on unencrypted, shared secrets that can be intercepted, spoofed, or socially engineered. In an era where AI-driven phishing campaigns achieve click-through rates as high as 54%, SMS codes and automated phone calls no longer provide adequate protection.

When do I need to switch to passkeys in Microsoft Entra ID?

Beginning on February 1, 2027, users who rely only on SMS or voice authentication may be prompted to register a passkey or another approved authentication method before the can continue signing in. Users who have already registered a supported authentication method, such as a passkey, Microsoft Authenticator, or another approved method, will not be impacted by this change.

What happens if our organization must keep SMS or voice for compliance or operational reasons?

While native Microsoft-provided telecom delivery ends on February 1, 2027, organizations with regulatory, technical, or operational dependencies can transition to third-party telecom carriers. Starting October 30, 2026, administrators can select, configure, and manage supported third-party providers through the Microsoft Security Store. Note that organizations will contract directly with carriers and be responsible for any associated telecom fees.

Can Microsoft Entra ID users opt out of passkeys after the February 1, 2027 deadline?

No. After February 1, 2027, Microsoft will permanently retire native SMS/voice delivery and enforce passkey registration across all tenants in the public cloud. Automatic prompts will become blocking for non-compliant users, and temporary opt-out mechanisms will no longer be available.

What are passkeys?

Passkeys are phishing-resistant, passwordless credentials built on open FIDO2 and W3C WebAuthn standards. Instead of transmitting a shared secret (like a password or SMS code) over a network, passkeys use public-key cryptography: a private key stays securely encrypted on the user's local device, while Microsoft Entra ID registers the matching public key.

What types of passkeys does Microsoft Entra ID support?

  • Device-Bound Passkeys: Hardware-isolated credentials stored on a single physical device that cannot be exported or synchronizeded across devices. Examples include FIDO2 security keys (like YubiKeys), Microsoft Authenticator device-bound passkeys, and Microsoft Entra passkeys,  on Windows (such as Windows Hello for Business and Microsoft Authenticator device-bound passkeys).
  • Synced Passkeys: Encrypted credentials stored in platform credential managers that sync across a user's ecosystem for convenience, such as Apple iCloud Keychain or Google Password Manager.

How will Microsoft Entra ID’s automatic passkey registration prompt affect my end users?

Starting September 1, 2026, Microsoft Entra ID will begin auto-enabling passkeys for users enabled for SMS or voice MFA. When these users sign in, they will receive an automated registration prompt ("nudge") guiding them to set up a passkey on their device. During the rollout window, users can temporarily skip the prompt, but after February 1, 2027, passkey registration will become mandatory before sign-in can proceed.

What is SIM swapping?

SIM swapping is an identity theft technique where an attacker tricks or bribes a mobile carrier customer service representative into porting a target victim’s phone number to an attacker-controlled SIM card. Once transferred, the bad actor receives all incoming phone calls and text messages meant for the victim, allowing them to easily intercept one-time SMS passcodes and hijack accounts without ever needing physical access to the victim’s device.

What are Man-in-the-Middle (MitM) Proxies?

A Man-in-the-Middle (MitM) or Adversary-in-the-Middle (AiTM) reverse proxy (such as Evilginx) is an automated attack platform that sits invisibly between a user and a legitimate login portal. When a victim attempts to log in, the proxy mirrors the authentic sign-in page in real time. As the user enters their password and two-factor SMS code, the proxy captures both inputs and steals the active session cookie, thereby granting the attacker complete access to the account while bypassing traditional MFA entirely.

Authors
No items found.

Recent Blogs

Blog

Modernizing PAM for the Identity Era: Expanding Beyond Traditional Privileged Accounts

Modernizing PAM for the Identity Era: Expanding Beyond Traditional Privileged Accounts

Learn why modern PAM strategies must extend beyond administrator accounts to include machine identities, cloud entitlements, Just-in-Time access, and Zero Standing Privilege. Dan Ross shares practical guidance for building a scalable privileged access program.

Blog

Make AI Boring

Make AI Boring

As AI becomes more deeply embedded across the enterprise, leaders must focus on the decisions, tradeoffs, and accountability required to scale responsibly.

Blog

What You Need to Know About Microsoft Entra ID’s SSPR Update and How to Mitigate its Operational Risks

Microsoft Entra ID’s SSPR Update and How to Mitigate its Operational Risks

What C-suite leaders need to know about the upcoming Microsoft Entra ID SSPR changes, its operational risks, and how to mitigate them.

Blog

Why IAM Becomes the Critical Path in Application Delivery

Why IAM Becomes the Critical Path in Application Delivery

IAM isn't why most projects start, but it's often why they stall. Learn how proactive identity governance accelerates application delivery.

Blog

TLS Certificates Are Privileged Credentials, CISOs Must Treat Them That Way

TLS Certificates Are Privileged Credentials, CISOs Must Treat Them That Way

Learn why CISOs must treat TLS certificates as machine identities to reduce outages, enforce governance, and strengthen Zero Trust.

Blog

Identity Modernization Is Dead. Long Live AI Readiness!

Identity Modernization Is Dead. Long Live AI Readiness!

AI readiness succeeds when healthcare organizations take an identity-first approach rather than a model-first one.

Blog

Evidence-Based Identity Governance for Streamlined Audits in Healthcare

Evidence-Based Identity Governance for Streamlined Audits in Healthcare

Auditors don’t just ask who has access today. Identity governance needs to be reframed as a continuous regulatory defense, not a periodic compliance exercise.

Blog

The Cost of Waiting: How Access Delays Erode Clinical Efficiency

The Cost of Waiting: How Access Delays Erode Clinical Efficiency

A modern identity strategy ensures access is there when it’s needed, protects clinical operations, and delivers measurable business value without disrupting care.

Blog

Identity Modernization: The Foundation for AI Readiness in Healthcare

Identity Modernization: The Foundation for AI Readiness in Healthcare

In a healthcare setting, AI failures can cause real harm. A strong identity foundation serves as the operational foundation for AI.

Blog

Decentralized Identity Explained: A Practical Q&A for 2026

Decentralized Identity Explained: A Practical Q&A for 2026

Explore the key concepts, benefits, challenges, and emerging trends shaping decentralized identity in 2026 and beyond.

Blog

IGA and Change Management: A Guide to Successful Engagements

IGA and Change Management: A Guide to Successful Engagements

When effective change management is integrated with IGA implementations from the start, organizations reduce resistance, increase alignment, and ensure new identity processes take root in a sustainable, scalable way.

Blog

Outcome‑Driven IAM: Why Identity Programs Win on Results, Not Tools

Outcome‑Driven IAM: Why Identity Programs Win on Results, Not Tools

Why IAM programs fail despite strong tools, and how outcome‑driven IAM delivers measurable risk reduction, audit readiness, and business value.

Blog

Breaking Down Identity Silos: Why Fragmented Systems Create Risk and Complexity

Breaking Down Identity Silos: Why Fragmented Systems Create Risk and Complexity

Learn about the challenges created by identity silos, the trade-offs between consolidation and governance, and how organizations can determine the most effective path forward.

Blog

Identity Proofing 101: A Practical Guide for Modern Organizations

Identity Proofing 101: A Practical Guide for Modern Organizations

Discover why identity proofing is a foundational security control for modern organizations.

Blog

Preparing your Organization for AI-Driven Identity Threats

Preparing your Organization for AI-Driven Identity Threats

Learn how AI‑driven identity threats are evolving and why governing AI agents as managed, privileged identities is key to secure, responsible AI adoption.

Blog

KPIs for App Onboarding: What to Measure and Why It Matters

KPIs for App Onboarding: What to Measure and Why It Matters

The most useful KPIs for app onboarding include percent of applications onboarded, time‑to‑onboard, and realized business value or ROI. These metrics give stakeholders clear visibility into progress and help keep the onboarding program accountable and predictable.

No items found.
No items found.
No items found.