Microsoft Is Ending SMS & Voice MFA: Prepare Your Business Before the Deadline

Microsoft Is Retiring SMS & Voice MFA What Your Business Needs to Do Before February 2027

If your business uses Microsoft 365 and your employees still receive text messages or phone calls to verify their identity when signing in, an important change is coming.

Microsoft is retiring its native SMS and voice authentication services for Microsoft Entra ID beginning February 1, 2027.

The change is part of Microsoft’s broader effort to move organizations away from authentication methods that are increasingly vulnerable to phishing and account compromise and toward more secure authentication methods.

For businesses, the takeaway is simple:

Don’t wait until February to figure this out.

Now is the time to review how you and your employees authenticate into Microsoft 365 and begin transitioning users who still rely on SMS or voice verification.

What’s Changing With Microsoft MFA?

Multi-factor authentication (MFA) adds an additional layer of security beyond a username and password.

For years, many Microsoft 365 users have completed MFA by receiving a text message containing a verification code or answering an automated phone call.

Microsoft is now moving away from those methods.

Beginning September 1, 2026, Microsoft will begin automatically enabling passkeys for users currently enabled for SMS or voice authentication and prompting eligible users to register a passkey.

Then, on February 1, 2027, Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID.

Organizations with a legitimate business, regulatory, or operational requirement to continue using SMS or voice will have an option to use a customer-managed telecommunications provider through Microsoft’s Security Store. For most organizations, however, Microsoft’s recommendation is to transition users toward stronger authentication methods before the deadline.

Why Is Microsoft Moving Away From Text Messages and Phone Calls?

The answer is security.

SMS and voice verification were significant improvements over relying on passwords alone, but cybercriminals have developed increasingly sophisticated ways to intercept, manipulate, or socially engineer these authentication methods.

Microsoft now describes SMS and voice as among the more vulnerable authentication methods available and is pushing organizations toward authentication that is more resistant to phishing and account compromise.

That matters because a stolen password isn’t necessarily enough to compromise an account protected by strong MFA.

The harder it is for an attacker to obtain or reproduce that second authentication factor, the harder it becomes to gain access to your email, Microsoft 365 environment, company files, and other business systems.

Where Does Microsoft Authenticator Fit In?

Microsoft is increasingly emphasizing phishing-resistant authentication methods such as passkeys, Windows Hello for Business, and FIDO2 security keys.

However, Microsoft Authenticator remains an important and recommended upgrade for organizations and users currently relying on SMS or voice MFA.

Authenticator can verify sign-ins through the Microsoft Authenticator app rather than relying on a text message or telephone call. Microsoft specifically recommends migrating users from SMS and voice authentication to Microsoft Authenticator as one way to improve the security of their authentication methods.

For many ROC Business Technologies customers, setting up Microsoft Authenticator now is a straightforward way to strengthen account security and begin moving away from legacy SMS and voice verification.

How to Set Up Microsoft Authenticator

 

You don’t need to wait for Microsoft—or ROC—to prompt you.

Most Microsoft 365 users can review their security information and add Microsoft Authenticator themselves.

Step 1: Install Microsoft Authenticator

Install the Microsoft Authenticator app on your mobile device if you don’t already have it.

Microsoft Authenticator is available for both Apple iOS and Android devices.

Step 2: Open Your Microsoft Security Info Page

From your computer, visit:

Microsoft Security Info

Sign in using your Microsoft 365 work or school account.

This page displays the authentication methods currently associated with your Microsoft account.

Step 3: Add Microsoft Authenticator

Select:

Add sign-in method

Then choose:

Microsoft Authenticator

Select Add and follow the prompts.

Step 4: Connect the App

Microsoft will display a QR code on your computer.

Open Microsoft Authenticator on your mobile device and add your Work or school account.

Use the Authenticator app to scan the QR code displayed on your computer.

You may be asked to give Microsoft Authenticator permission to access your phone’s camera. The camera is necessary to scan the QR code; Microsoft also provides a manual setup option if you cannot use the camera.

Step 5: Complete the Verification

Follow Microsoft’s prompts to test and verify the connection.

Once verification is complete, Microsoft Authenticator will appear among the registered sign-in methods on your Security Info page.

Microsoft’s current instructions for adding a work or school account to Authenticator follow this Security Info → Add sign-in method → Microsoft Authenticator workflow.

Already Using Microsoft Authenticator?

Good.

If Microsoft Authenticator is already registered with your Microsoft 365 account, you don’t need to set it up again simply because of this announcement.

However, this is a good opportunity to visit your Microsoft Security Info page and review which authentication methods are currently registered to your account.

Businesses should also determine whether employees are still relying on SMS or voice authentication so those users can be transitioned well ahead of Microsoft’s deadline.

What Happens If You Do Nothing?

This is the part businesses should pay attention to.

Beginning February 1, 2027, Microsoft-provided SMS and voice authentication will no longer be available in Microsoft Entra ID.

According to Microsoft’s current transition plan, users whose only available MFA method is SMS or voice will be required to register a passkey during sign-in before they can continue accessing their account.

That creates the possibility of unnecessary sign-in disruptions for employees and additional IT support requests if organizations wait until the deadline.

There’s very little upside to waiting.

Preparing users now gives your organization time to make the transition deliberately rather than dealing with authentication changes when someone is trying to get into their email before an important meeting.

This Is Also a Good Time to Review Your Company’s MFA Strategy

Microsoft’s change is bigger than simply replacing one authentication method with another.

It’s a reminder that identity has become one of the most important layers of business cybersecurity.

Your employees’ Microsoft accounts may provide access to email, OneDrive, SharePoint, Teams, customer information, financial documents, and other sensitive company data.

Strong authentication helps protect those systems even when an employee’s password is compromised.

Businesses should be asking:

  • Which employees are still using SMS or voice MFA?
  • Are employees using Microsoft Authenticator or another modern authentication method?
  • Are stronger phishing-resistant options appropriate for certain users or administrators?
  • Are former employees and unused accounts being removed properly?
  • Are Microsoft 365 security policies configured consistently across the organization?

Those questions are increasingly important as phishing, credential theft, and identity-based attacks continue to target businesses of every size.

Need Help With Microsoft 365 Security?

If you’re able to access your Microsoft Security Info page, we encourage you to follow the steps above and register Microsoft Authenticator directly.

Set Up or Review Your Microsoft Security Information

If you receive an error, cannot access your existing authentication method, or aren’t sure whether your organization’s Microsoft 365 environment is configured correctly, ROC Business Technologies can help.

ROC helps businesses throughout Papillion, Nebraska, Sarpy County, and the greater Omaha area manage Microsoft 365, cybersecurity, authentication, managed IT services, and the technology their employees depend on every day.

February 1, 2027 may sound like it’s a long way away. When it comes to making an organization-wide security change, it isn’t.

Take a few minutes now to review your Microsoft security information—and avoid making it a problem later.

Frequently Asked Questions

Phishing:  Users can be tricked into sharing MFA codes.

SIM Swapping: Attackers may gain control of a phone number and receive text codes.

Social Engineering: Fraudsters often impersonate support staff or trusted organizations.

Identity Attacks: Modern cyberattacks increasingly focus on user identities rather than devices.

Recommended:

Microsoft Authenticator
Passkeys
Windows Hello for Business
FIDO2 Security Keys

Being Retired:

SMS Text Messages
Phone Call Verification

Microsoft retires Microsoft-provided SMS and Voice MFA on February 1, 2027.

Microsoft is making this change to reduce successful phishing and identity-based attacks. Moving users to Microsoft Authenticator and other modern authentication methods improves security and helps avoid sign-in disruptions before the 2027 deadline.

Stay Ahead of Cyber Threats

Sign up to get expert security tips and practical advice that help protect your business from today’s cyber risks.

We respect your privacy and never spam or sell your info.