International Edition
Latest News
Technology

Microsoft to End SMS and Voice MFA for Entra ID to Combat AI Phishing

Microsoft plans to phase out native SMS and voice authentication for Entra ID, shifting toward passkeys as its default security experience to combat sophisticated AI-driven phishing attacks. According to official Microsoft documentation, the company will automatically enable passkeys…

<>

Microsoft plans to phase out native SMS and voice authentication for Entra ID, shifting toward passkeys as its default security experience to combat sophisticated AI-driven phishing attacks. According to official Microsoft documentation, the company will automatically enable passkeys for users currently reliant on SMS or voice starting September 1, 2026, before blocking native telecommunications methods entirely for unconfigured tenants on February 1, 2027.

The Timeline for Microsoft Entra ID Authentication Changes

The deprecation of built-in text message and voice call multi-factor authentication rolls out across strict deadlines detailed by Microsoft. Beginning September 1, 2026, Microsoft will auto-enable passkeys in the Entra Authentication Methods Policy for any users currently utilizing SMS or voice. At the same time, registration campaign settings automatically switch to a Microsoft-managed state, which prompts users to register a passkey the next time they sign in and complete multi-factor authentication.

Enforcement hits on February 1, 2027. According to Microsoft, tenants that have not configured a customer-managed telecom provider through the Microsoft Security Store will completely lose the ability to use SMS or voice for multi-factor authentication. Users whose only authentication method relies on those legacy channels must register a passkey during their sign-in flow to maintain account access. Azure AD B2C environments remain completely out of scope for this announcement, while Microsoft Entra External ID tenants will face a separate transition timeline announced next year.

Why Microsoft Is Eliminating SMS and Voice Verification

Security drives the decision to deprecate text-based and voice verification methods. According to Microsoft, SMS and voice rank among the most vulnerable authentication vectors available, offering weak defenses against modern account compromise and phishing campaigns. Artificial intelligence tools have drastically lowered the barrier for attackers to intercept codes or execute adversary-in-the-middle phishing attacks.

To replace these legacy channels, Microsoft is pushing passkeys as the default standard because they use cryptographic security bound to a specific device or hardware key. Passkeys cannot be phished through fake login portals or intercepted via SIM-swapping attacks, making them a robust defense against automated identity theft.

Options for Regulated Organizations and Tenant Administrators

Organizations facing strict regulatory, business, or technical requirements that mandate traditional telecom channels still have a path forward. According to Microsoft, administrators can contract directly with approved telecommunications providers through the Microsoft Security Store to maintain custom SMS or voice workflows.

Microsoft Learn
Photo: learn.microsoft.com

Options and terms for these customer-managed providers become available in the Microsoft Security Store starting September 18, 2026. Pricing varies by region and provider volume, typically structured on a per-message basis. Conversely, migrating native Microsoft-provided SMS and voice users directly to passkeys incurs no additional cost. Administrators wanting to check their exposure before the deadline can run a specific PowerShell script provided in Microsoft’s technical documentation to identify any users still relying exclusively on text or voice verification.

31. Add Multi-factor Authentication Methods in Microsoft Entra ID
About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”