Your Six-Digit Text Code Is on Its Way Out: Microsoft Retires SMS and Voice MFA
- Jeremy Ross
- 2 days ago
- 4 min read
First Contact is a managed IT service provider (MSP) based in Whitefield, Manchester, founded in 2001, offering IT support, cybersecurity and Microsoft 365 management for growing businesses.
If you've only got a minute: Microsoft is switching off SMS and voice call MFA. From September 2026 it starts nudging everyone toward passkeys, and by February 2027 the text-message code is gone for good, no exceptions. If you're a First Contact client, this has already been sorted. If you're not, now's the time to sort it.
There's a particular kind of faith you place in a text message. You type your password, you wait, a six-digit code lands on your phone like a small miracle, and you get on with your day. It's the digital equivalent of a bouncer checking your ID by squinting at it from across the room. Works most of the time. Not exactly Fort Knox.
Turns out Microsoft agrees. They've decided the text message code has had a good run and it's time to retire it, permanently.
They Built the Whole System Around a Text Message: The Problem with SMS and Voice MFA
SMS and voice MFA were never really about security. They were about convenience. Everyone has a phone, everyone can receive a text, job done. The trouble is that the same qualities that make it convenient make it exploitable. Phone numbers can be hijacked through SIM-swap attacks. Text messages can be intercepted. Voice calls are practically an invitation for a confident scammer with a script. And now that AI can automate social engineering at scale, the weak link isn't theoretical anymore, it's a live target.
Microsoft has looked at this and decided it's no longer willing to be the one handing out the weak link. So they're switching it off.
Here's the actual timeline. From 1 September 2026, anyone still using SMS or voice for MFA starts getting automatically enrolled into passkeys, with a nudge to register one at every sign-in. If your organisation genuinely needs to keep SMS or voice running for regulatory or operational reasons, you'll need to set up a paid telecom provider through the Microsoft Security Store to keep it alive. Then on 1 February 2027, Microsoft-provided SMS and voice authentication disappears entirely. There's no opt-out. If that's the only MFA method someone has on their account, they'll hit a blocking prompt demanding they register a passkey before they can log in at all. Mid-shift, mid-deadline, doesn't matter.
For a business with even a modest headcount, that's not a small housekeeping task. That's every employee, every device, every "wait, what's a passkey" conversation, all compressed into a window that will feel a lot shorter than it looks on a calendar.
We Sorted It Before It Was a Problem: What We Did
This is exactly the sort of change we like to have handled before a client even hears about it on the news. Every First Contact client already has modern, phishing-resistant MFA in place, think Microsoft Authenticator and passkey-based sign-in, not a text message with a countdown timer. We moved everyone off SMS and voice years ago, back when a few clients quietly wondered if we'd gone slightly overboard insisting on it . When Microsoft announced the retirement, we checked our tenants confirmed everyone had migrated, and went back to improving their systems in ways they probably won't think to thank us for until 2029.
What Changed
This is exactly the sort of change we like to have handled before a client even hears about it on the news. Every First Contact client already has modern, phishing-resistant MFA in place, think Microsoft Authenticator and passkey-based sign-in, not a text message with a countdown timer. We moved everyone off SMS and voice years ago, back when a few clients thought we'd stayed up watching too many Mission Impossible films. It's why when Microsoft announced the retirement, we checked our clients systems, confirmed everyone had migrated, and went back to improving their systems in ways they probably won't think to thank us for until 2029.
Key Takeaway
Security changes like this tend to arrive quietly and then land all at once. Microsoft has given everyone a runway, but a runway only helps if someone's actually flying the plane. If your MFA setup is something nobody's looked at since it was switched on, this is as good a prompt as any to check. And if you'd rather it just be handled, that's rather the point of having us around.
If you've only got a minute (recap): Microsoft switches off SMS and voice MFA for good by February 2027, starting with automatic passkey nudges from September 2026. First Contact clients are already migrated. If you're not, get ahead of it before Microsoft does it for you.
FAQs
Is Microsoft really getting rid of SMS authentication? Yes. Microsoft-provided SMS and voice call authentication for Entra ID is being retired on 1 February 2027, with automatic passkey enrolment starting from 1 September 2026.
Why is Microsoft removing SMS and voice MFA? SMS and voice codes are vulnerable to SIM-swap attacks, interception, and increasingly convincing AI-assisted social engineering. Microsoft considers them no longer reliable enough to be the default second factor.
What happens if my business doesn't switch from SMS MFA in time? Anyone whose only MFA method is SMS or voice will be blocked at sign-in and forced to register a passkey on the spot, which is a far worse experience than doing it on your own schedule.
What should I switch to instead of SMS MFA? Microsoft Authenticator and passkey-based sign-in (FIDO2) are the recommended replacements. Both are phishing-resistant and don't depend on a mobile network to work.
Do I need to do anything if I'm already a First Contact client? No. This has already been handled across our client base as part of standard security management.