NewsTradingSentimentEventsCommunityBriefing
Tech

Microsoft Ends SMS Login by 2027, Forcing Shift to Passkeys

By Tech Desk · · 2 min read
A physical hardware security key with a USB connector resting on a desk

Microsoft will disable its native SMS and voice authentication services in 2027, requiring users to adopt passkeys for secure access.

Key points

  • Microsoft will disable native SMS and voice MFA in Entra ID starting February 1, 2027.
  • Users relying solely on phone codes will be forced to register passkeys to access accounts.
  • Organizations can use third-party telecom providers to retain SMS authentication if required by compliance.

Microsoft is preparing to shut down its native SMS and voice-based multifactor authentication services within Microsoft Entra ID. The company argues that phone-based verification methods are increasingly vulnerable to phishing and SIM-swapping attacks, making them less secure than modern cryptographic alternatives. This move represents a significant shift in how identity verification is handled for enterprise users.

As reported by Petri IT Knowledgebase, the transition aims to make passkeys the default sign-in experience. Passkeys use cryptographic credentials stored on trusted devices rather than shared secrets like passwords or one-time codes. This approach provides stronger protection against account compromise while simplifying the user experience by reducing reliance on text messages.

Timeline for forced migration

Starting September 1, 2026, Microsoft will automatically enable passkey support for users relying on SMS or voice authentication. These users will begin receiving prompts to register a passkey after completing sign-ins. For most users, the legacy SMS and voice services will stop working entirely on February 1, 2027. Global Administrators and external users have a temporary extension until July 1, 2027, but internal guest users must comply with the earlier February deadline.

After the retirement date, users whose only MFA option is SMS or voice will face a mandatory passkey registration process. This enforcement cannot be bypassed, meaning affected users must register a passkey before they can continue accessing their accounts. Organizations are advised to identify these users early using tools like PowerShell scripts to plan their migration strategy.

Trade-offs for legacy requirements

Microsoft is not eliminating phone-based authentication globally but is ending its own telecom delivery service. Organizations with regulatory or compliance needs that still depend on SMS can select a customer-managed telecom provider through the Microsoft Security Store. This option is expected to become available later this year, allowing those with specific operational constraints to maintain legacy methods through third-party providers.

The primary trade-off for IT administrators is the operational burden of migrating large user bases. While passkeys offer stronger security, the mandatory nature of the switch means that any delay could result in help desk backlogs and potential user lockouts. Early adoption is recommended to reduce these risks and ensure a smooth transition before the hard deadlines arrive.

Based on reporting by Petri IT Knowledgebase, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories