Microsoft has announced an important change to the way users verify their identity when signing in to Microsoft 365 and other Microsoft cloud services.
From 1 February 2027, Microsoft will retire its built-in use of SMS text messages and automated phone calls for multi-factor authentication in Microsoft Entra ID.
This means that users who currently receive a text message or phone call when signing in will need to move to a stronger and more secure sign-in method, such as a passkey.
JGC IT Services will support customers throughout this transition. We will take the necessary steps to enable suitable authentication methods, plan the migration and help ensure that user onboarding is straightforward and disruption is kept to a minimum.
Many users currently approve a Microsoft 365 sign-in by:
Microsoft is retiring SMS and voice-based authentication because these methods are no longer considered sufficiently secure for modern business use.
The recommended replacement is a passkey or another phishing-resistant authentication method.
For most users, this will mean signing in using something familiar, such as:
A passkey is a more secure replacement for passwords and temporary verification codes.
Rather than receiving a code by text message, a passkey allows you to confirm your identity using a trusted device.
For example, you may sign in to your Microsoft account by using:
Behind the scenes, the passkey uses secure cryptographic technology to confirm that the sign-in request is genuine.
The private part of the passkey remains protected on your device and is not sent to Microsoft or entered into a website.
No.
A password is something that you know and type into a website. Passwords can be guessed, reused, stolen or entered into a fraudulent sign-in page.
A passkey is something securely stored on a trusted device. You unlock it using a fingerprint, face recognition or device PIN.
In many cases, using a passkey will be quicker and easier than entering a password and waiting for a text message.
SMS and phone calls are more secure than using a password alone, but they are still vulnerable to attack.
Phishing
A fraudulent website may ask a user to enter both their password and the code they have received by text message.
An attacker can then use those details to access the genuine account.
Passkeys are designed to work only with the legitimate Microsoft sign-in service, making them much more resistant to phishing.
SIM-swap attacks
Attackers may attempt to transfer a user’s mobile number to another SIM card.
If successful, they may be able to receive text message verification codes intended for the genuine user.
Passkeys do not rely on a mobile telephone number and are not affected by this type of attack.
Delayed or unavailable text messages
SMS authentication depends on mobile coverage and an external telecommunications network.
Messages may be delayed or unavailable when travelling, working in poor signal areas or experiencing a mobile network issue.
Passkeys remove the need to wait for a verification message.
Social engineering
Attackers may impersonate IT support teams, Microsoft or mobile providers to persuade users to disclose codes or change their authentication details.
A passkey cannot simply be read out, forwarded or copied into a fraudulent website.
Stronger account security
Passkeys provide significantly better protection against phishing, stolen credentials and account compromise.
Faster sign-ins
Users will not need to wait for a text message, enter a temporary code or answer an automated call.
A simpler experience
Most users will be able to sign in using the same fingerprint, face recognition or PIN they already use to unlock their device.
Less reliance on mobile numbers
Changing mobile provider, losing phone signal or travelling abroad should no longer prevent access to Microsoft 365.
Reduced risk from stolen passwords
The private passkey remains protected on the user’s device and is not shared with Microsoft or typed into a website.
Before 1 September 2026
JGC IT Services will review affected customer environments and identify users who currently rely on SMS messages or phone calls.
We will also assess which passkey and authentication methods are most appropriate for each customer.
1 September 2026
Microsoft will begin automatically enabling passkeys in the Authentication Methods Policy for users who are currently enabled for SMS or voice authentication.
This does not mean that SMS and phone calls will stop working immediately.
It is an important preparation stage ahead of the final retirement date.
September 2026 to January 2027
During this period, JGC IT Services will work with supported customers to:
The aim will be to complete migrations in advance of the deadline and avoid unnecessary sign-in disruption.
1 February 2027
Microsoft-provided SMS and phone call authentication will be retired.
Users who still rely solely on one of these methods may be required to register a passkey before they can continue signing in.
JGC IT Services will work to ensure supported users are migrated before this date.
The exact process will depend on the devices and authentication methods used by your organisation.
You may be asked to:
JGC IT Services will provide clear instructions when action is required.