Microsoft Is Retiring SMS and Voice MFA: The February 2027 Deadline and What It Costs to Prepare

Microsoft announced on July 13, 2026 that it is retiring Microsoft-provided SMS and voice call authentication in Entra ID entirely, replacing it with passkeys as the default authentication experience across every tenant. For any organisation still relying on phone-based multi-factor authentication as a fallback method, this is a genuine deadline with real licensing and budget implications, not a routine security bulletin to file away.

The Two Dates That Actually Matter

The change rolls out in two distinct phases with different practical consequences. Beginning September 1, 2026, users currently enabled for SMS or voice authentication will begin being automatically enabled for passkeys and prompted to register, and beginning February 1, 2027, Microsoft-provided SMS and voice delivery will be fully retired, after which users whose only available MFA method is SMS or voice will receive a blocking prompt requiring them to register a passkey before they can continue signing in, an enforcement that cannot be disabled.

The February deadline carries the harder consequence. Users whose only remaining MFA method is SMS or voice will face a blocking prompt requiring passkey registration before they can continue signing in, with no opt-out available at that point for any tenant. Organisations that have not migrated affected users by then are not looking at a warning banner. They are looking at a genuine sign-in disruption for every user still relying on phone-based authentication as their sole method.

What Passwordless Actually Requires From Users

Passkey adoption is not simply a policy toggle from an end-user perspective, and underestimating the change management effort involved is a common planning mistake. A passkey needs to live somewhere: a device’s built-in biometric sensor, a password manager capable of syncing passkeys across devices, or a dedicated hardware security key for users without a suitable device. Organisations with a significant frontline or shared-device workforce, where employees do not each have a personal, biometric-capable device, need a genuinely different rollout plan than organisations with a fully desk-based, one-device-per-employee population.

Scoping that population difference explicitly, rather than assuming a single passkey rollout plan fits every user group equally well, is essential groundwork before the September 2026 automatic enrolment begins nudging users toward registration regardless of whether a suitable device or hardware key has actually been provisioned for them yet.

Why Microsoft Is Framing This as a Security Necessity

Microsoft’s own justification for the change has been direct about why a fifteen-year-old fallback method is being retired now rather than left in place indefinitely. The company stated explicitly that SMS and voice will no longer be available as multifactor authentication methods starting February 1, 2027 because they do not offer sufficient levels of security in comparison to passkeys, framing the change specifically as a response to how effectively modern, AI-assisted attacks can intercept or social-engineer around phone-based authentication factors.

That framing matters for how internal stakeholders should understand the urgency. This is not Microsoft deprecating an old feature to simplify its own product line. It is Microsoft making an explicit judgement that phone-based MFA no longer meets the security bar current threats require, which is a considerably stronger internal argument for prioritising the migration than a routine end-of-support notice would carry.

The Cost Detail Easy to Miss

Migrating to passkeys carries no additional licensing cost, since passkey support is included in every Entra plan tier without exception. The cost implication sits specifically with organisations that have a genuine business, regulatory, or operational reason to retain phone-based authentication beyond February 2027. For those organisations, a customer-managed telecom provider configured through the Microsoft Security Store is required to keep SMS or voice functioning at all, and that provider relationship is a paid add-on priced per message, varying by provider and geographic region, rather than a feature Microsoft continues to offer at no additional cost.

Organisations with genuinely no alternative to phone-based authentication, such as specific frontline worker populations without access to a registered device capable of holding a passkey, need to budget for this provider relationship now rather than discovering the requirement in the final weeks before the February deadline. Evaluating providers through the Security Store takes genuine time, and Microsoft has indicated further detail on available providers continues to roll out through the second half of 2026.

Building a Realistic Migration Timeline

Detailed migration guidance from practitioners who have already run this transition with real customers lays out a sequence worth following closely rather than improvising. The recommended approach starts with identifying every user currently enabled for SMS or voice authentication, testing the passkey registration experience directly, and deciding deliberately whether to exercise the temporary opt-out available between September 2026 and February 2027 for organisations that need more control over the migration pace rather than accepting Microsoft’s automatic timeline.

That temporary opt-out is a genuinely useful tool for organisations with a large, distributed user base needing a more carefully sequenced rollout, but it is worth being clear that it only delays the September 1 automatic passkey enablement and registration campaign. It does not move the February 1, 2027 final retirement date, which applies to every tenant with no exception regardless of whether the earlier opt-out was exercised.

Why This Applies Regardless of How Modern Your Authentication Already Is

It is tempting for organisations that already use Microsoft Authenticator or hardware keys as their primary MFA method to assume this retirement does not affect them, since their day-to-day sign-in experience does not rely on SMS or voice at all. That assumption is worth checking rather than accepting, because a user’s primary method being modern does not mean SMS or voice has been fully removed as a registered fallback option in the Authentication Methods Policy for that same user.

A tenant-wide audit of which methods are actually enabled in policy, rather than which methods users happen to use day to day, is the only reliable way to confirm true exposure to this retirement. Fallback methods accumulate quietly over years of onboarding and policy changes, and an organisation confident in its modern authentication posture can still discover a meaningful population of users with SMS or voice sitting enabled as an unused but technically available fallback.

The Self-Service Password Reset Detail Worth Flagging

One detail that frequently gets missed in initial planning is that this retirement covers self-service password reset flows as well as standard sign-in authentication. Any organisation whose SSPR configuration currently relies on SMS or voice as a verification method needs to review that configuration specifically, since a password reset flow that silently stops working in February 2027 tends to surface as a help desk crisis rather than a planned change, precisely because password resets happen at unpredictable moments rather than during a scheduled migration window.

Conclusion

Microsoft’s retirement of SMS and voice authentication is a genuine security-driven deadline with two distinct dates, an automatic passkey nudge beginning September 1, 2026, and a hard, non-negotiable retirement on February 1, 2027 that applies to every tenant without exception. The migration itself costs nothing in licensing terms, since passkey support ships with every Entra plan, but organisations with a genuine ongoing need for phone-based authentication need to budget for a paid, customer-managed telecom provider well before the deadline arrives.

Auditing which users and self-service password reset flows currently depend on SMS or voice, testing the passkey experience directly, and making a deliberate decision about the temporary opt-out window are the practical steps that turn this from a compliance surprise into a properly managed transition well ahead of the February 2027 cutoff.

 

More on the Blog