Microsoft is phasing out text-message and phone-call verification in Microsoft 365. Here is the timeline, why it is happening, and the steps your organization should take now.
If anyone on your team signs in to Microsoft 365 by entering a code from a text message or answering an automated phone call, an important change is coming. Microsoft has announced it is retiring its built-in SMS one-time codes and voice calls as multifactor authentication (MFA) methods in Microsoft Entra ID, the identity system behind Microsoft 365.
The timeline
Microsoft laid out a phased rollout rather than a single cutoff date. Starting September 1, 2026, passkeys become the default sign-in experience for organizations, and new users will no longer be able to register SMS or voice as authentication methods. Existing SMS and voice users continue working through a transition period, with full retirement of Microsoft-provided SMS and voice authentication completing by February 1, 2027. Organizations that still need telephony-based authentication after that date must configure their own telecom provider through Entra custom authentication extensions.
Why Microsoft is making this change
Text messages and phone calls were never designed to be security tools. Attackers can intercept SMS codes through SIM-swapping, trick users into reading codes aloud during vishing calls, or simply phish the code in real time. Phishing-resistant methods such as passkeys and the Microsoft Authenticator app are tied to the device and the real sign-in page, which removes most of those attack paths. Microsoft is moving every organization toward these stronger methods by default.
What this means for your organization
If your users already approve sign-ins with the Microsoft Authenticator app, you are largely unaffected. But any user still relying on a text message or phone call will eventually be unable to sign in unless a new method is registered before the enforcement date. For small businesses, municipalities, and clinics without dedicated IT staff, the risk is simple: someone gets locked out of email at the worst possible time.
Steps to take now
First, review which MFA methods your users have registered in the Entra admin center so you know who still depends on SMS or voice. Second, move those users to the Microsoft Authenticator app, which is free and takes only a few minutes per person. Third, consider passkeys or FIDO2 security keys for your highest-risk accounts such as administrators, finance staff, and anyone who handles payments. Finally, update your onboarding process so new employees are set up with app-based authentication from day one.
How we can help
Blue Guys IT helps organizations across Arkansas plan and roll out MFA changes without disrupting daily work. We can audit your current sign-in methods, migrate users to the Authenticator app or passkeys, and document the process for your records. If you are unsure how many of your users still rely on text-message verification, schedule a consultation and we will walk through it together.
