Microsoft is drawing a much harder line against SMS and voice-based authentication. According to reporting from Windows Latest, Microsoft has warned administrators that the AI era requires stronger, phishing-resistant sign-in methods and that SMS or voice authentication will be blocked for Microsoft Entra ID users beginning February 1, 2027. Personal Microsoft account users are also expected to be moved away from SMS over time, although Microsoft has not published the same hard cutoff date for consumer accounts.
For IT teams, this is not just another security recommendation to place on a long-term roadmap. It is a forced migration with a defined enterprise deadline, and the operational work starts well before 2027. Organizations that still depend on text messages or phone calls for multi-factor authentication should treat this as an authentication inventory now, not in January 2027.
What Microsoft is changing
The Windows Latest report says Microsoft is notifying Entra ID tenants that SMS and voice are no longer considered strong enough for modern account protection. Starting September 1, Microsoft will begin pushing passkey registration for users who still rely on SMS or voice authentication. Then, on February 1, 2027, those methods are scheduled to be fully retired for Entra ID sign-ins.
The key point for administrators is that this is not described as an optional security baseline. Microsoft’s message reportedly says there is no opt-out from the enforcement and that it applies to all tenants. In practice, that means organizations need to plan for help desk capacity, user communications, device readiness, break-glass procedures, and policy cleanup before the block arrives.
Why SMS and voice MFA are falling out of favor
SMS-based one-time codes helped many organizations move beyond passwords, but they were never truly phishing-resistant. Attackers can trick users into reading out codes, entering codes into fake sign-in pages, or approving workflows they do not understand. Voice calls face similar problems, and both channels can be affected by SIM swapping, number porting fraud, call forwarding abuse, and social engineering against mobile carriers or users.
Microsoft’s concern, as summarized by Windows Latest, is that AI-assisted phishing makes these older weaknesses easier to exploit at scale. AI does not need to magically read a user’s phone. The more realistic risk is that attackers can generate better lures, imitate familiar business language, create convincing fake support interactions, and rapidly customize campaigns for different roles, departments, or geographies.
That matters because MFA methods are not equal. A code that a user can copy from a text message into a fake web page is still a shareable secret. A passkey, by contrast, is designed to be bound to the legitimate service and the user’s device or security key, making credential theft dramatically harder.
What passkeys change
Passkeys use modern public-key cryptography rather than a reusable password or a one-time code delivered over a phone network. During sign-in, the service verifies a cryptographic response from the user’s device, security key, or platform authenticator. The private key does not leave the device, and the sign-in is tied to the real domain or application flow.
For Windows and Microsoft 365 environments, passkeys can reduce several common attack paths: fake login pages, MFA code replay, password spraying followed by SMS interception, and help desk-driven reset abuse. They also improve the user experience once deployed well, because users can sign in with Windows Hello, a hardware security key, or another approved authenticator flow instead of waiting for a text or phone call.
That said, passkeys are not a magic switch. They require device compatibility, user education, recovery planning, and policy design. A rushed rollout can create lockouts or frustrate users who work across shared devices, older systems, regulated environments, or remote access tools that have not been updated.
Recommended action plan for IT administrators
First, identify every user and administrator account still using SMS or voice authentication in Entra ID. Pay special attention to privileged roles, service desk accounts, executives, contractors, frontline workers, and any user population that depends on personal phones.
Second, define your target authentication methods. For most organizations, that will mean passkeys backed by Windows Hello for Business, FIDO2 security keys for specific users or high-assurance scenarios, and Microsoft Authenticator where appropriate. Avoid replacing SMS with another weak or confusing fallback unless it is part of a documented transition plan.
Third, communicate early. Users need to know why the change is happening, what they need to register, how to recognize legitimate Microsoft prompts, and where to get help. The message should be practical rather than alarmist: SMS codes are being phased out because attackers can phish and replay them, while passkeys are designed to resist that kind of theft.
Fourth, test with a pilot group before broad enforcement. Include users with different devices, operating systems, job roles, and remote work patterns. Document enrollment steps, recovery procedures, and edge cases before you scale the rollout.
Finally, clean up legacy authentication policies. If SMS and voice remain enabled as fallback methods until the deadline, monitor their use and progressively reduce dependency. The goal is to make February 2027 uneventful because the organization has already moved.
What consumers should know
The same direction applies to personal Microsoft accounts used for Windows, Outlook, Xbox, OneDrive, and other Microsoft services. Microsoft has been steering consumers toward passwordless sign-in and away from SMS for both authentication and recovery. There may not be a consumer deadline matching the Entra ID date yet, but waiting is not a good security strategy.
If you use a personal Microsoft account, consider setting up a passkey now and reviewing your recovery options. Make sure your account has current recovery information, remove old phone numbers you no longer control, and be cautious of messages that ask you to share codes or approve unexpected sign-ins.
Microsoft’s deadline gives enterprises time, but not unlimited time. The safest approach is to treat SMS and voice MFA as legacy technology: useful in the past, increasingly risky now, and scheduled for retirement in modern Microsoft identity environments.
Source: Windows Latest source