Blog Post

Microsoft Is Retiring SMS and Phone-Based MFA: What This Means for You

Microsoft has announced an important change to the way users verify their identity when signing in to Microsoft 365 and other Microsoft cloud services.

From 1 February 2027, Microsoft will retire its built-in use of SMS text messages and automated phone calls for multi-factor authentication in Microsoft Entra ID.

This means that users who currently receive a text message or phone call when signing in will need to move to a stronger and more secure sign-in method, such as a passkey.

JGC IT Services will support customers throughout this transition. We will take the necessary steps to enable suitable authentication methods, plan the migration and help ensure that user onboarding is straightforward and disruption is kept to a minimum.

What is changing?

Many users currently approve a Microsoft 365 sign-in by:

  • Entering a one-time code received by text message
  • Answering an automated phone call
  • Approving a notification in Microsoft Authenticator

Microsoft is retiring SMS and voice-based authentication because these methods are no longer considered sufficiently secure for modern business use.

The recommended replacement is a passkey or another phishing-resistant authentication method.

For most users, this will mean signing in using something familiar, such as:

  • Windows Hello facial recognition
  • A fingerprint
  • A device PIN
  • Microsoft Authenticator
  • A supported security key

What is a passkey?

A passkey is a more secure replacement for passwords and temporary verification codes.

Rather than receiving a code by text message, a passkey allows you to confirm your identity using a trusted device.

For example, you may sign in to your Microsoft account by using:

  • Face recognition on your computer or mobile device
  • Your fingerprint
  • Your Windows Hello PIN
  • Microsoft Authenticator
  • A company-provided security key

Behind the scenes, the passkey uses secure cryptographic technology to confirm that the sign-in request is genuine.

The private part of the passkey remains protected on your device and is not sent to Microsoft or entered into a website.

Is a passkey the same as a password?

No.

A password is something that you know and type into a website. Passwords can be guessed, reused, stolen or entered into a fraudulent sign-in page.

A passkey is something securely stored on a trusted device. You unlock it using a fingerprint, face recognition or device PIN.

In many cases, using a passkey will be quicker and easier than entering a password and waiting for a text message.

Why is Microsoft making this change?

SMS and phone calls are more secure than using a password alone, but they are still vulnerable to attack.

Phishing

A fraudulent website may ask a user to enter both their password and the code they have received by text message.

An attacker can then use those details to access the genuine account.

Passkeys are designed to work only with the legitimate Microsoft sign-in service, making them much more resistant to phishing.

SIM-swap attacks

Attackers may attempt to transfer a user’s mobile number to another SIM card.

If successful, they may be able to receive text message verification codes intended for the genuine user.

Passkeys do not rely on a mobile telephone number and are not affected by this type of attack.

Delayed or unavailable text messages

SMS authentication depends on mobile coverage and an external telecommunications network.

Messages may be delayed or unavailable when travelling, working in poor signal areas or experiencing a mobile network issue.

Passkeys remove the need to wait for a verification message.

Social engineering

Attackers may impersonate IT support teams, Microsoft or mobile providers to persuade users to disclose codes or change their authentication details.

A passkey cannot simply be read out, forwarded or copied into a fraudulent website.

What are the benefits of passkeys?

Stronger account security

Passkeys provide significantly better protection against phishing, stolen credentials and account compromise.

Faster sign-ins

Users will not need to wait for a text message, enter a temporary code or answer an automated call.

A simpler experience

Most users will be able to sign in using the same fingerprint, face recognition or PIN they already use to unlock their device.

Less reliance on mobile numbers

Changing mobile provider, losing phone signal or travelling abroad should no longer prevent access to Microsoft 365.

Reduced risk from stolen passwords

The private passkey remains protected on the user’s device and is not shared with Microsoft or typed into a website.

Key dates

Before 1 September 2026

JGC IT Services will review affected customer environments and identify users who currently rely on SMS messages or phone calls.

We will also assess which passkey and authentication methods are most appropriate for each customer.

1 September 2026

Microsoft will begin automatically enabling passkeys in the Authentication Methods Policy for users who are currently enabled for SMS or voice authentication.

This does not mean that SMS and phone calls will stop working immediately.

It is an important preparation stage ahead of the final retirement date.

September 2026 to January 2027

During this period, JGC IT Services will work with supported customers to:

  • Enable the required passkey settings
  • Test the sign-in process
  • Plan a staged user rollout
  • Provide user instructions
  • Support users with registration
  • Review backup authentication and account recovery options
  • Monitor migration progress
  • Resolve any device or compatibility issues

The aim will be to complete migrations in advance of the deadline and avoid unnecessary sign-in disruption.

1 February 2027

Microsoft-provided SMS and phone call authentication will be retired.

Users who still rely solely on one of these methods may be required to register a passkey before they can continue signing in.

JGC IT Services will work to ensure supported users are migrated before this date.

What will users need to do?

The exact process will depend on the devices and authentication methods used by your organisation.

You may be asked to:

  • Install or update Microsoft Authenticator
  • Register a passkey
  • Configure Windows Hello
  • Use a fingerprint, face recognition or device PIN
  • Register a company-provided security key
  • Confirm a backup authentication method

JGC IT Services will provide clear instructions when action is required.