ADAM PULSE Knowledge Base
Identity Security · Microsoft Entra ID · MFA

Microsoft is retiring SMS and voice MFA. What should you do before February 1, 2027?

Microsoft has confirmed that Microsoft-provided SMS and voice authentication will be fully retired in Microsoft Entra ID on February 1, 2027. Most coverage stops there, which is a mistake, because the date that will actually change what your users see is earlier and closer.

On September 1, 2026, every user still enabled for SMS or voice is automatically enabled for passkeys and is nudged to register one the next time they complete multifactor authentication. Your registration campaign settings are moved to a Microsoft-managed state and those users are pulled into scope automatically. Nobody is locked out that day — the nudge can be snoozed, and by default it can be snoozed an unlimited number of times — but your help desk will start getting calls about a prompt nobody warned users about.

This article covers what is changing, what is in scope and what is not, the temporary opt-out that most summaries omit, and ten concrete actions worth taking now.

Key takeaways
  • Two dates, not one. September 1, 2026 — automatic passkey enablement and nudges. February 1, 2027 — Microsoft-provided SMS and voice retired.
  • After February 1, 2027 the prompt is blocking. Users whose only available MFA method is SMS or voice must register a passkey before they can continue signing in. There is no opt out from that enforcement, and it applies to all tenants.
  • There is a temporary opt-out for the interim. Setting passkeyDynamicMigration to true via Microsoft Graph delays the September 1 auto-enablement and registration campaign through February 1, 2027 — and only that far.
  • Passkeys are recommended, not mandatory. Microsoft's stated bar for February 1, 2027 is a phishing-resistant method: passkeys, Windows Hello, or FIDO2.
  • SSPR is in scope. The retirement of native SMS and voice applies across Entra, self-service password reset included.
  • Keeping SMS costs money. Customer-managed telecom providers in the Microsoft Security Store are priced per message and vary by region. Moving users to passkeys costs nothing extra.

Why Microsoft is moving away from SMS and voice

For a decade the security advice has been that any MFA beats no MFA. That is still true. What has changed is that the gap between the weakest and strongest second factors has widened enough to matter.

Microsoft's own framing is blunt: SMS and voice are among the most vulnerable authentication methods available today and provide significantly weaker protection against phishing and account compromise than passkeys. The specific weaknesses are well understood:

Passkeys break most of that chain by design. They are cryptographic key pairs bound to a device or a synced credential store rather than a shared secret, and they are bound to the origin they were registered against — so a lookalike domain cannot elicit a valid assertion no matter how convincing the page is. Microsoft Entra ID supports both synced passkeys, saved in a platform credential manager such as iCloud Keychain or Google Password Manager, and device-bound passkeys such as Passkey in Microsoft Authenticator, Entra Passkey on Windows, and FIDO2 hardware security keys.

The retirement timeline

Microsoft's published milestones for the SMS and voice retirement.
DateWhat happensWhat you should do
September 1, 2026 Users enabled for SMS or voice are auto-enabled for passkeys in the Authentication Methods Policy and nudged to register on their next MFA sign-in. Registration campaign settings move to Microsoft-managed state. Nudges are snoozable, unlimited by default. Notify users before this date. Move users out of SMS or voice in the policy, or apply the temporary opt-out, if you are not ready.
September 18, 2026 Telecom provider options and terms published in the Microsoft Security Store. Only relevant if you have a documented regulatory or operational need to keep a telecom channel.
October 30, 2026 Customers can select and configure a telecom provider from the Microsoft Security Store. Stand up the contract and pilot it well before the February deadline.
February 1, 2027 Microsoft-provided SMS and voice fully retired in Microsoft Entra ID. Every user should already be on a phishing-resistant method — passkeys, Windows Hello, or FIDO2.
After February 1, 2027 Users whose only available MFA method is SMS or voice get a blocking prompt to register a passkey before they can continue signing in. No opt out. All tenants. Confirm nobody is left dependent on Microsoft-provided SMS or voice.

Microsoft is explicit that this is not a lockout event: users are not locked out on February 1, they are stopped at a registration prompt they can no longer skip. In practice, for a large tenant with no preparation, that distinction will feel academic on the morning of February 1.

What is in scope — and what is not

Scope is where most internal summaries of this change go wrong. Microsoft's FAQ answers several questions that materially affect planning:

The opt-out most write-ups miss

Microsoft documents a temporary opt-out for the September 1, 2026 through February 1, 2027 window. Update the authentication methods policy through Microsoft Graph and set passkeyDynamicMigration to true under optOutSettings. This requires the Policy.ReadWrite.AuthenticationMethod permission and excludes the tenant from automatic passkey enablement and the registration campaign for that period.

It is a scheduling tool, not an escape hatch. Beginning February 1, 2027 the standard migration and enforcement timelines apply regardless of the setting. Use it to control when your users are prompted, not whether you migrate.

Ten actions to take now

1. Identify every user still enabled for SMS or voice

You cannot plan a migration against a population you have not counted. Microsoft publishes a PowerShell script for exactly this — the entra-sms-voice-usage-analyzer — and running it requires one of the Global Reader, Authentication Policy Administrator, or Security Reader roles. Any non-zero result means your tenant is in scope. A zero result means you can stop reading and file this for reference.

Do not stop at everyday employees. Look specifically at administrators, executives, remote workers, contractors, temporary staff, service accounts, shared accounts, vendor accounts, legacy accounts, and privileged users. The accounts that cause incidents are usually the ones nobody has reviewed in two years.

Action item. Produce an authentication inventory listing every active account, its registered MFA methods, privilege level, last sign-in activity, and an accountable owner.

2. Start moving users to passkeys before September 1, 2026

Microsoft's own recommendation is a registration campaign, which prompts users to set up a passkey the next time they sign in and complete MFA. You can enable one yourself before Microsoft enables it for you. Doing it on your schedule means you choose the pilot group, the comms, and the support window.

Before configuring the campaign, confirm Passkey (FIDO2) is enabled as an authentication method and that your SMS and voice users are inside a passkey-enabled authentication methods policy. Then, as an Authentication Policy Administrator, go to Entra ID → Authentication methods → Registration campaign, set State to Microsoft Managed, and target the security group of SMS and voice users you built in step 1.

Action item. Run a passkey pilot with IT staff and technically comfortable users first, then publish a phased schedule for everyone else.

3. Protect privileged accounts first

Not every account carries the same blast radius. A compromised administrator can reach mail, identity configuration, cloud applications, security settings, and financial systems. Migrate privileged accounts to phishing-resistant methods ahead of the general population, and take the opportunity to ask whether every account holding administrative rights still needs them.

Separating administrative identities from everyday working identities is worth the friction. An administrator should not browse the web and read mail with the same credential that can rewrite your Conditional Access policies.

Action item. Migrate privileged and administrative accounts to phishing-resistant authentication before the broad rollout, and re-justify each administrative assignment while you are in there.

4. Review Conditional Access policies

Strong credentials matter more when the policy engine knows what to do with them. Microsoft Entra Conditional Access can evaluate user identity, device compliance, application sensitivity, location, risk signals, authentication strength, and administrative privilege before granting access.

Authentication strength is the control worth revisiting specifically. It lets you require a phishing-resistant method for a defined set of applications or roles rather than accepting any MFA. That is the mechanism that turns "we have passkeys available" into "the finance application will not accept anything weaker."

Action item. Confirm your sensitive applications and privileged roles require an appropriate authentication strength, not merely "multifactor authentication."

5. Eliminate dormant and unnecessary accounts

The easiest account to compromise is one nobody remembers exists. Former employees, expired contractors, unused test accounts, and forgotten service principals accumulate quietly, and an authentication migration is the cheapest moment you will ever get to clean them up — because you are already enumerating every account and its methods.

Action item. Review inactive accounts and disable or remove anything without a current business justification.

6. Strengthen help desk identity verification

This is the failure mode that undoes everything else. Stronger authentication increases the value of the recovery path, and the recovery path usually runs through a human being under time pressure.

"I lost my phone." "I have a new device." "My authentication is not working." "I need my MFA reset." If your help desk can reset a method on the strength of a name, a birthday, and an employee number, then your effective authentication strength is whatever that conversation costs an attacker.

Action item. Document a verification procedure for password resets, passkey resets, MFA changes, and account recovery — and make sure it does not rely on facts a stranger can find on LinkedIn.

7. Retrain employees on modern phishing

Attackers impersonate Microsoft, IT support, executives, vendors, banks, customers, shipping companies, and HR. Generative AI has lowered the cost of doing that convincingly, at volume, in the target's own idiom. The obvious tells that awareness training was built around in 2019 — broken grammar, generic salutations, implausible urgency — are no longer reliable.

Worth adding to the syllabus specifically: users are about to start seeing a legitimate, unexpected Microsoft prompt asking them to register a passkey. That is precisely the shape of a message an attacker would fake. Tell people it is coming, and tell them how to tell the real one from a copy.

Action item. Run recurring training covering phishing simulations, credential theft, social engineering, fraudulent MFA requests, and AI-assisted impersonation.

8. Review third-party and vendor access

Your employees are not the only identities in your tenant. Consultants, software vendors, managed service providers, and partners hold access that expands your attack surface and is rarely reviewed on a schedule. Note also that guest and B2B users are in scope for this retirement while passkey support for them is planned for the end of calendar year 2026 — so external identities need their own plan rather than being folded into the employee rollout.

For each external identity: who has access, why, to what, when it was last reviewed, what method they authenticate with, and when it should expire.

Action item. Establish a quarterly vendor access review and remove permissions that are no longer required.

9. Monitor authentication activity

Authentication is a continuous signal, not a one-time gate. Repeated failures, unexpected method changes, unusual geography, new device registrations, privilege changes, and suspicious recovery activity are all worth an alert and an owner.

During a migration this matters more than usual, because "user registered a new authentication method" is about to become extremely common — which is exactly the noise an attacker would like to hide in.

Action item. Review Entra ID sign-in and authentication methods reporting, and define an escalation path for anomalous identity activity before the September rollout starts generating volume.

10. Write the roadmap down and give it an owner

A workable sequence, given the published dates:

Action item. Assign a named owner and track the plan somewhere your leadership already looks.

If you genuinely need to keep SMS or voice

Some organizations have a real regulatory or operational requirement for an out-of-band telecom channel. Microsoft's answer is a customer-managed telecom provider contracted through the Microsoft Security Store, which gives you regional control and the ability to pick a carrier that meets local compliance requirements.

Three things to plan around. First, this costs money: pricing varies by provider and region, is typically per message, and depends on volume and geographic distribution. Migrating users to passkeys instead incurs no additional cost. Second, the timing is tight — options and terms publish September 18, 2026 and configuration opens October 30, 2026, leaving roughly three months to evaluate, contract, configure, and pilot before February 1. Third, this should be a scoped exception, not a tenant-wide decision: identify the specific user segments with a genuine requirement, document which regulation or scenario drives it, and default everyone else to passkeys.

The broader point: identity is the control plane now

Cybersecurity strategy used to be organised around a network perimeter. Firewalls guarded the edge, employees worked inside offices, applications ran in corporate data centres. That geometry is mostly gone. People work from homes, hotels, airports, and personal devices, against applications the organization does not host, over networks it does not control.

What replaced the perimeter is identity. An attacker holding valid credentials and a satisfied MFA challenge does not look like an attack to most network controls — the traffic is legitimate, the session is authenticated, the user agent is ordinary. Detection has to move to behaviour, and prevention has to move to credentials that cannot be handed over by a person who has been convinced to hand them over.

That is the real content of Microsoft's announcement. The specific mechanism — retiring one delivery channel for one-time codes — is small. The direction it encodes is not: the industry is moving from "prove you know a secret" to "prove you hold a key that cannot leave the device it lives on." Organizations that treat February 1, 2027 as a configuration deadline will meet it. Organizations that treat it as a prompt to review who has access, how they authenticate, what they can reach, and whether that is still justified will get considerably more out of the same work.

USA Telecom Consulting LLC is a Service-Disabled Veteran-Owned Small Business. We work with Microsoft Entra ID, Zoom, and carrier environments for regulated and defense-supply-chain organizations.

Frequently asked questions

When exactly do SMS and voice MFA stop working in Microsoft Entra ID?

Microsoft-provided SMS and voice are fully retired on February 1, 2027. The earlier change is September 1, 2026, when users enabled for SMS or voice are automatically enabled for passkeys and nudged to register one on their next MFA sign-in. After February 1, 2027, users whose only available MFA method is SMS or voice receive a blocking prompt to register a passkey before they can continue signing in.

Can we opt out of the September 1, 2026 automatic passkey enablement?

Temporarily, yes. Microsoft documents a temporary opt-out covering September 1, 2026 through February 1, 2027: set passkeyDynamicMigration to true in the authentication methods policy through Microsoft Graph, which requires the Policy.ReadWrite.AuthenticationMethod permission. It excludes the tenant from automatic passkey enablement and the registration campaign for that window only. There is no opt out from the February 1, 2027 enforcement, and it applies to all tenants.

Do we have to use passkeys, or do FIDO2 keys and Windows Hello count?

Microsoft recommends passkeys as the default phishing-resistant credential, but its guidance for February 1, 2027 is that every user should be on a phishing-resistant method — passkeys, Windows Hello, or FIDO2. Entra ID supports synced passkeys held in a platform credential manager as well as device-bound passkeys including Passkey in Microsoft Authenticator, Entra Passkey on Windows, and FIDO2 hardware security keys.

Does this affect self-service password reset?

Yes. Microsoft states the retirement of native SMS and voice applies across Entra, including SSPR. Organizations that configure a customer-managed telecom provider through the Security Store can continue using SMS and voice for it.

How do we find out whether our tenant is affected?

Run Microsoft's entra-sms-voice-usage-analyzer PowerShell script with one of the Global Reader, Authentication Policy Administrator, or Security Reader roles. Any non-zero result means you are in scope. If no users are enabled for SMS or voice, no action is required.

What does keeping SMS or voice cost?

Microsoft confirms there is a cost that varies by telecom provider and region, typically per message and dependent on volume and geographic distribution. Provider options and terms publish beginning September 18, 2026, and configuration becomes available beginning October 30, 2026. Migrating users to passkeys instead incurs no additional cost.

Are Azure AD B2C and Microsoft Entra External ID included?

No. Microsoft states that Azure AD B2C is out of scope and unaffected, and that Microsoft Entra External ID is covered by a separate announcement next year. The published timeline also applies to public cloud environments only; other cloud environments follow later with advance communication.

Will users be locked out on February 1, 2027?

Microsoft's answer is no — users are not locked out, they are stopped at a passkey registration prompt they can no longer skip. The practical consequence for an unprepared tenant is the same volume of help desk calls either way, which is the argument for migrating on your own schedule instead.

Your ten-point checklist

  1. Identified every user still enabled for SMS or voice, using Microsoft's usage analyzer.
  2. Started migrating users to passkeys or another phishing-resistant method.
  3. Migrated privileged and administrative accounts first.
  4. Reviewed Conditional Access policies, specifically authentication strength.
  5. Removed dormant, unnecessary, and outdated accounts.
  6. Documented and hardened help desk identity verification and account recovery.
  7. Updated security awareness training, including the legitimate passkey prompt users are about to see.
  8. Reviewed vendor, guest, and B2B access, accounting for the end-of-2026 passkey support timing for guests.
  9. Established authentication monitoring and an escalation path.
  10. Written a dated migration roadmap with a named owner.

Sources

← More from the ADAM Pulse Knowledge Base