Accucom Blog
Microsoft is Scrapping SMS MFA (for Good Reason)
Microsoft is officially ending support for SMS and voice multi-factor authentication (MFA) in Entra ID. To combat modern cyber threats, Microsoft is replacing legacy phone verification with secure, cryptographic passkeys. Organizations must begin preparing their IT environments immediately to ensure uninterrupted network access for their workforce.
The Vulnerability of Legacy Verification
Relying on text messages and automated phone calls for account security is no longer sufficient. These verification methods are highly susceptible to interception, SIM swapping, and automated phishing proxies. Passkeys eliminate these specific vulnerabilities by tying credentials directly to a physical device and the verified corporate domain. This cryptographic binding prevents unauthorized access and protects accounts from credential theft.
The Retirement Schedule
The transition timeline is underway, with the first major shift happening just a few weeks ago:
- September 1, 2026 - Users who relied on SMS or voice authentication were automatically enabled for passkeys. If they tried to sign in, they should have been prompted to register a passkey to their account.
- February 1, 2027 - Microsoft will permanently shut down its SMS and voice MFA delivery service across all Entra ID tenants.
- After February 1, 2027 - Any user without a registered passkey will be entirely blocked from logging in until they complete the passkey registration process.
Required Action Leaders Need to Take
Administrators must take proactive steps to prevent unexpected downtime and operational friction:
- Audit tenant accounts - Review your Entra ID environment to pinpoint every user currently utilizing SMS or voice verification as their secondary factor.
- Deploy passkeys early - Update your organization's authentication policies to support passkeys and encourage staff to register.
- Inform staff - Distribute clear communications to employees detailing the changes and providing step-by-step registration instructions.
- Configure telecom fallbacks - If specific regulatory mandates require your business to maintain SMS or voice authentication, you must set up a customer-managed telecom provider through the Microsoft Security Store prior to the final February deadline.
Handling these authentication updates ahead of the enforcement dates will keep your daily operations running smoothly while strengthening your digital security. For assistance auditing your Microsoft Entra ID policies or deploying a seamless passkey rollout across your organization, call us today at (02) 8825-5555.



Comments