Skip to main content
Breaking News

Microsoft Moves MFA Beyond SMS

Microsoft is accelerating the shift toward phishing-resistant authentication, making passkeys the default authentication experience in Microsoft Entra ID

3 min read0 views
Microsoft Moves MFA Beyond SMS
Sharefin

Microsoft is accelerating the shift toward phishing-resistant authentication, making passkeys the default authentication experience in Microsoft Entra ID and preparing to retire Microsoft-provided SMS and voice authentication on February 1, 2027. The change reflects a broader cybersecurity reality: passwords and telecom-based authentication are increasingly vulnerable in an AI-driven threat environment.

SMS and voice-based MFA once represented an important additional security layer, but attackers have developed techniques involving phishing, SIM swapping, social engineering, credential interception and replay attacks. Generative AI can further scale convincing impersonation and phishing campaigns, increasing pressure on organizations to adopt authentication methods that do not depend on secrets users can disclose.

Beginning September 1, 2026, Entra ID users currently enabled for SMS or voice will automatically become enabled for passkeys and will be encouraged to register one when completing MFA. This gives enterprises a limited transition window to identify affected employees, communicate the change and manage migration proactively.

Key Takeaways:

1. Passkeys become the default authentication direction for Microsoft Entra ID.

2. September 1, 2026: SMS/voice-enabled users begin automatic passkey enablement.

3. February 1, 2027: Microsoft-provided SMS and voice authentication retire.

4. No opt-out: Affected users relying solely on these methods must register another supported method to continue signing in.

5. Passkeys resist phishing by replacing transferable passwords and OTPs with cryptographic authentication.

6. Enterprises should migrate early, identifying affected users and running passkey registration campaigns before enforcement.

7. Identity security is entering a new phase: phishing-resistant authentication, Zero Trust and continuous verification will increasingly replace reliance on passwords and telecom-delivered OTPs.

The bigger deadline arrives on February 1, 2027, when Microsoft-provided SMS and voice authentication will be retired. Users relying solely on these methods will face a blocking prompt requiring passkey registration before continuing to sign in. Microsoft says there will be no opt-out from this enforcement across affected Entra tenants.

Passkeys fundamentally improve authentication because they use public-key cryptography and are bound to legitimate services, making them resistant to conventional credential phishing. Instead of entering an OTP that can potentially be intercepted or socially engineered, users authenticate through cryptographic credentials associated with their device or security key.

For CISOs, this is more than an authentication upgrade. Organizations should identify SMS- and voice-dependent accounts, enable passkeys, launch registration campaigns, review recovery processes and ensure privileged accounts receive particular attention. Enterprises with regulatory or operational reasons for retaining telecom authentication will need to evaluate customer-managed providers available through the Microsoft Security Store.

The strategic message is clear: the era of OTP-centric security is beginning to close. As AI makes impersonation and social engineering faster and more convincing, identity itself becomes a critical cybersecurity perimeter. Enterprises that migrate early toward phishing-resistant credentials, Zero Trust and continuous identity verification will be better prepared for the next generation of identity attacks.