Move to Phishing-Resistant Authentication Before 2027

iStock 2277184474

Move to phishing-resistant authentication before SMS and voice retire

Microsoft is changing how businesses protect employee sign-ins in Microsoft Entra ID. Passkeys are becoming the default authentication experience, as Microsoft-provided SMS and voice authentication will retire on February 1, 2027. Microsoft provides a full breakdown of theSMS and voice authentication retirement and transition to passkeys here.

For business owners, the change means more than adopting a different way to log in. Any employees currently using SMS or phone calls for multifactor authentication (MFA) will need to switch to a more secure verification method. This could mean updating internal policies, communicating the change to your team, and ensuring everyone has access to an approved authentication app. Planning ahead gives your business time to make the transition smoothly, without disrupting everyday work.

What is changing with Microsoft Entra authentication?

Microsoft is moving users away from SMS and voice authentication and toward passkeys, which provide stronger protection against common account takeover attempts.

A passkey is a unique digital credential that is saved on a trusted device or hardware security key. Instead of typing a password and then entering a code received by text, the user confirms their identity through the device itself, often with a fingerprint, face scan, or PIN. Microsoft explains in more detailhow passkeys work in Microsoft Entra ID, including how they use cryptographic keys instead of shareable verification codes.

There are two significant updates to watch out for:

  • For users currently using SMS or voice authentication, passkeys will become the new default sign-in method.
  • Microsoft will discontinue its SMS and voice delivery services on February 1, 2027.

What dates should your business know?

Microsoft’s transition happens in stages.

September 1, 2026: Users who currently rely on SMS or voice authentication will be able to use passkeys. Microsoft will prompt these users to set up a passkey the next time they verify their identity using MFA.

February 1, 2027: Microsoft will discontinue support for SMS and voice-based authentication methods.

After February 1, 2027: Employees who rely solely on SMS or voice for MFA will be prompted to set up a passkey before they can proceed. This will be a mandatory requirement with no opt-out option provided by Microsoft.

If nobody in your Microsoft Entra environment uses SMS or voice authentication, you do not need to take action.

Make the move before it becomes mandatory

Moving to passkeys ahead of the deadline lets your business control the schedule instead of waiting for employees to encounter blocking prompts.

Ready to prepare your Microsoft environment for the change? Contact PCM to discuss your authentication and cybersecurity needs.

Archives