Skip to content
Braincap
← All articles

Microsoft is retiring SMS and voice MFA: passkeys become the default in Entra ID

by Claudiu Hulea · IT Management Consultant

Illustration: SMS and phone-call MFA retiring, a passkey becoming the default method in Microsoft Entra ID

On July 13, 2026, Microsoft notified all Entra ID tenants of an important security change: passkeys become the default authentication method in Microsoft Entra, and Microsoft-provided SMS and voice MFA retire on February 1, 2027. If your organisation uses Microsoft 365 / Entra ID and has users on SMS or voice, you have a firm deadline — and, before it, a date on which Microsoft acts on your behalf if you do not act first.

What is changing

  • Passkeys become the default authentication experience for users currently enabled for SMS or voice.
  • Microsoft-provided telecom delivery for SMS and voice is retired. Customer-managed telecom providers, configured through the Microsoft Security Store, are not affected.

The timeline: the dates that matter

  • September 1, 2026 — Users enabled for SMS or voice are automatically enrolled in passkeys and will be nudged to register a passkey the next time they complete MFA. If you do not want this, you must move them out of SMS/voice in the Authentication Methods Policy before this date.
  • February 1, 2027Microsoft-provided SMS and voice are fully retired in Entra ID. Customer-managed telecom providers are unaffected.
  • After February 1, 2027 — Users whose only MFA method is SMS or voice get a blocking prompt until they register a passkey. There is no opt out from this enforcement; it applies to all tenants.

If no users in your tenant are enabled for SMS or voice, there is nothing to do. If you do have them, the only path is to move every one of them onto a phishing-resistant method before February 1, 2027 — and acting before September 1, 2026 gives you control over the timing and spares your users the blocking prompts.

Why it is changing

SMS and voice are among the most vulnerable authentication methods available today. They offer significantly weaker protection against:

  • phishing — a code received by SMS can be requested and coaxed out on a fake page, in real time;
  • SIM-swap — an attacker who takes over your phone number receives the codes instead of you;
  • replay attacks — an intercepted code can be reused.

Passkeys remove the problem at the root: there is no longer a code that can be intercepted, requested, or reused. The credential is cryptographically bound to the device and the real domain, so it cannot be used on a phishing site. It is, in fact, exactly the direction regulators require — DORA, NIS2, and PSD2 SCA all push toward phishing-resistant MFA. Microsoft is simply turning the recommendation into the default.

What to do now

The deadline looks distant, but migrating authentication for hundreds or thousands of users is not an evening’s work. Concrete steps, in order:

  1. Find the affected users. Identify who in the tenant still has SMS or voice as an MFA method. Without that list, you do not know how big the problem is.
  2. Move them to passkeys. Enable passkeys and run a registration campaign before the September 1, 2026 auto-enablement, so you move people on your schedule, planned, rather than in the wave of Microsoft prompts.
  3. Communicate the change. Tell users what is changing, when, and what they need to do — a passkey not registered in time becomes, after February 2027, a user blocked at login.
  4. Evaluate a customer-managed telecom provider only if warranted. If you have a genuine regulatory or operational need to keep SMS/voice, configure a customer-managed provider through the Microsoft Security Store (options and pricing from September 18, 2026; configuration from October 30, 2026). For most organisations, passkeys is the answer, not an exception to maintain.

For a regulated entity in Romania

If you are a bank, non-bank lender, insurer, or any entity under DORA or NIS2, this change works in your favour: it removes a weak method and pushes you toward exactly what auditors ask for — phishing-resistant authentication. The risk is not passkeys, it is inertia: a tenant left on SMS/voice until the final week wakes up with users blocked at login and a migration done in crisis, not by plan. The window to act without pressure closes on September 1, 2026.

At Braincap we help with the inventory of MFA methods in your tenant, the passkey migration plan, and the registration campaign — plus a security audit that checks the rest of your identity surface, not just MFA. Get in touch and we start from what you have in Entra today.


Source: Microsoft Security Blog — “Passkeys are the default authentication method in Entra ID” (July 13, 2026). The dates and steps above reflect Microsoft’s official communication at the time of publication; check your tenant’s Message Center for any updates.

Frequently asked questions

When are SMS and voice retiring from Microsoft MFA?

On February 1, 2027, Microsoft-provided SMS and voice MFA methods are fully retired in Entra ID. Customer-managed telecom providers (configured through the Microsoft Security Store) are not affected. The key earlier milestone is September 1, 2026, when users enabled for SMS or voice are automatically enrolled in passkeys.

What happens on September 1, 2026?

Users who have SMS or voice as an MFA method are automatically enrolled in passkeys and will be nudged to register a passkey the next time they complete MFA. If you do not want this, you must move those users out of SMS/voice in the Authentication Methods Policy before this date.

Can I still use SMS or voice after February 1, 2027?

Only if you configure your own customer-managed telecom provider through the Microsoft Security Store — provider options and pricing are published from September 18, 2026, and configuration is available from October 30, 2026. Otherwise, Microsoft-provided SMS and voice disappear, and users whose only MFA method is SMS or voice will get a blocking prompt to register a passkey before they can sign in. There is no opt out from this enforcement.

Why is Microsoft moving to passkeys?

Because SMS and voice are among the weakest authentication methods available: they are vulnerable to phishing, to SIM-swap (hijacking the phone number), and to replay attacks. Passkeys are phishing-resistant credentials — there is no code that can be intercepted or coaxed out of a user. It is the same direction regulators require (DORA, NIS2, PSD2 SCA): phishing-resistant MFA.

What should I do now as an administrator?

Three steps, before September 1, 2026: (1) identify which users in your tenant still have SMS or voice as an MFA method; (2) enable passkeys and run a registration campaign to move users on your schedule, not Microsoft's; (3) tell users what is changing and what they need to do. Evaluate a customer-managed telecom provider only if you have a genuine regulatory need to keep SMS/voice.

Related articles