Microsoft Sets Entra SMS and Voice Retirement

Microsoft will make passkeys the default Microsoft Entra ID authentication experience starting September 1, 2026, then retire its native SMS and voice delivery on February 1, 2027. Microsoft's security blog attributes the change to phishing, credential-theft, and social-engineering risks, including threats amplified by AI. Organizations needing phone-based methods after retirement can use customer-managed telecom providers through the Microsoft Security Store.
Microsoft will begin making passkeys the default authentication experience in Microsoft Entra ID on September 1, 2026, and will retire Microsoft-provided SMS and voice authentication delivery on February 1, 2027. The change affects enterprise tenants using Entra ID for multifactor authentication, not merely consumer Microsoft accounts.
According to Microsoft's July 13 security blog, users enabled for SMS or voice will be automatically enabled for passkeys as the rollout reaches their organization. At their next MFA sign-in, eligible users will be prompted to register a passkey. Microsoft's Entra documentation states that, after February 1, 2027, users whose only available MFA method is SMS or voice will face a blocking passkey-registration prompt before they can continue accessing their accounts.
What is retiring
The scheduled retirement applies to Microsoft-provided telecom delivery for SMS and voice in Entra ID. It does not mean that every organization must eliminate phone-based authentication on that date. Microsoft's documentation states that customers that still require SMS or voice can configure customer-managed telecom providers through the Microsoft Security Store. Microsoft has scheduled additional information about customer-managed telecoms for September 18, 2026.
Microsoft's announcement frames the transition as a move away from phishable authentication methods. The company writes that SMS and voice rely on shared secrets or communications channels that attackers can intercept, phish, or manipulate, while passkeys use public-key cryptography. Windows Latest, which reported on a Microsoft email to IT administrators, quoted the company as describing SMS and voice as more vulnerable to phishing, SIM-swap, and replay attacks than passkeys.
Microsoft's AI-era discussion focuses on attacker capability. AI-assisted content can make impersonation and phishing campaigns easier to produce and tailor, but SMS one-time codes remain susceptible to established risks including SIM swapping, message interception, number reassignment, and real-time phishing proxies.
Timeline and operational impact
Microsoft documents three key stages:
- •September 1, 2026: Entra users enabled for SMS or voice are auto-enabled for passkeys and prompted to register one during MFA.
- •February 1, 2027: Microsoft-provided SMS and voice delivery is fully retired from Entra ID.
- •After February 1, 2027: Users with SMS or voice as their only MFA option must register a passkey during sign-in; the registration prompt blocks account access until completed.
Microsoft recommends moving users to passkeys or another phishing-resistant method as soon as possible. Its documentation identifies Windows Hello for Business and FIDO2 methods alongside passkeys as options that existing users can continue to use.
For tenant administrators, the practical distinction is between enrollment and policy coverage. Microsoft provides a public PowerShell repository, entra-sms-voice-usage-analyzer, that checks SMS and voice authentication-method policy scope, reports registration-campaign status, exports targeted users and groups, and summarizes timeline exposure. The script requires Microsoft Graph permissions including Policy.Read.All and Group.Read.All.
Microsoft's registration-campaign documentation also describes controls for targeting users or groups, setting postponement periods, and requiring registration after up to three deferrals. Conditional Access rules governing security-information registration apply before a user receives the enrollment prompt.
Companies undertaking comparable MFA transitions commonly need to inventory users with legacy factors, test passkey enrollment across managed and unmanaged devices, and identify service or recovery workflows that still depend on phone delivery. The February 2027 blocking condition makes that inventory especially material for Entra administrators: a user population left with SMS or voice as its sole configured MFA method can encounter an access interruption rather than a passive deprecation notice.
Key Points
- 1Microsoft will default eligible Entra ID SMS and voice users into passkey registration beginning September 1, 2026.
- 2Native Entra SMS and voice delivery ends February 1, 2027, while customer-managed telecom providers remain an option.
- 3Comparable MFA migrations require policy inventories because users relying solely on retired factors can face blocking enrollment prompts.
Scoring Rationale
The retirement timeline affects enterprise identity operations across Microsoft Entra ID tenants and creates a concrete access-risk deadline for users relying solely on SMS or voice MFA. It is especially relevant to security and platform teams managing phishing-resistant authentication, Conditional Access, device readiness, and recovery workflows.
Sources
Primary source and supporting public references used for this report.
View 4 more sources
- Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra IDmicrosoft.com
- microsoft/entra-sms-voice-usage-analyzer: PowerShell script to check Entra ID SMS/Voice authentication method policy usage.github.com
- Microsoft warns you to stop using SMS-based passwords because of AI phishing, and it’ll block you starting with Entra IDwindowslatest.com
- No More SMS One-time Codes and Voice Calls from Entra IDoffice365itpros.com
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

