Text Codes Won't Save You: Why SMS Login Codes Aren't Enough
First Contact is a managed IT service provider (MSP) based in Whitefield, Manchester, founded in 2001, offering IT support, cybersecurity and Microsoft 365 for growing businesses.
Your phone number is the least secret thing you own. It's on your business card, your van, and probably a chip shop loyalty scheme. So why are we trusting it to guard the keys to the business?
Microsoft has noticed too. It's switching off its own text and voice login codes for Microsoft 365, with the main deadline landing on 1 February 2027. We've already covered what that means in our post on Microsoft retiring SMS and voice MFA. This one is about why they're doing it.
If you've only got a minute Getting a code by text feels safe, and it's better than no code at all. But criminals have three easy ways round it: tricking you into reading it out, taking over your phone number, or catching the message before you do. Microsoft is retiring its own text and voice codes anyway, so the move is coming whether you plan for it or not. Switch to an authenticator app or passkey where you can. It takes five minutes and closes all three doors.
The myth: "A text code keeps me safe"
You log in, your phone buzzes, you type in six digits. It feels like a bouncer checking your wristband. Job done.
Except the bouncer will hand over the wristband to anyone who asks nicely.
The fact: "A text code keeps most people out. Not the ones who are trying."
Here's how it goes wrong, no technical degree required:
They ask you for it. A fake login page looks like the real one. You type in your password, your phone buzzes, you type in the code. You've just handed both to a stranger.
They become you. Criminals can convince a mobile provider to move your number to a new SIM card. Now the codes go to them. Your phone shows "No Service" and you assume it's the signal.
They see it first. Codes sit on lock screens and pass through networks no one in your business controls.
None of this is rare or clever. It's routine. And it's the reason Microsoft has decided a text code isn't good enough to keep guarding its own sign-ins.
What to use instead: "Codes that never travel"
An authenticator app creates the code on your phone itself. Nothing is sent, so nothing can be caught, and moving your number to a new SIM does nothing. Passkeys and physical security keys go a step further, because there's no code to hand over at all.
The order of play: passkey or security key if the service offers it, authenticator app if not, text code only if it's all you've got. Microsoft is heading the same way, with passkeys becoming the default for Microsoft 365 sign-ins. And until you've switched, keep the text code turned on. Better a wobbly lock than an open door.
Key takeaway: "Safe" is a sliding scale
A text code isn't a lie, it's a starter. Treat it like a padlock on a garden shed: fine for the lawnmower, not for the company accounts. Upgrade the logins that matter most (email, banking, Microsoft 365) this week, and the rest can follow.
Not sure which of your accounts are still on text codes? That's exactly the sort of thing we sort out for Manchester businesses every day.
FAQs
Is Microsoft really getting rid of text message login codes?
Microsoft is retiring the text and voice codes it provides for Microsoft 365 sign-ins, with the main date set for 1 February 2027. After that, anyone whose only method is a text or a call will have to set up a passkey to get in. Our earlier post on Microsoft retiring SMS and voice MFA has the full story.
Is text message two-factor authentication better than nothing?
Yes, by a long way. It stops the bulk of automated attacks. It just isn't the strongest option, and for important accounts you should aim higher.
What is a SIM swap?
It's when a criminal persuades your mobile provider to move your phone number onto a SIM card they control. From then on, your calls and text codes go to them instead of you.
What should my business use instead of text codes?
An authenticator app is the easy first step. Passkeys and security keys are stronger still where they're supported. Microsoft 365, Google and most banks now offer at least one of them.
Do small businesses really get targeted?
Yes. Attackers go where the defences are lightest, and smaller firms often have fewer. The attacks are automated, so size doesn't put you off their list.