Blog · Cybersecurity · August 4, 2026 · By Mike Parker

Microsoft Is Retiring Text-Message Logins. Here Is Your Deadline.

On February 1, 2027, the six-digit code Microsoft texts your team stops working — and the prompt that replaces it blocks the sign-in until they act. The first change lands September 1, 2026. Here is what happens, who it hits, and the order to do things in.

If your business runs on Microsoft 365, there is a good chance some of your team still logs in by typing a password and then a six-digit code from a text message. That method is going away, on a schedule Microsoft has already published.

This is not a vendor nudge or a best-practice suggestion. It is a dated change to how sign-in works, with an enforcement date attached — and most small businesses have not heard about it yet, because the announcement lives in an identity-administration document nobody outside IT reads.

The two dates that matter

September 1, 2026 — passkeys become the default. Anyone currently set up for text or phone-call codes is automatically enabled for passkeys, and the next time they complete a sign-in they get prompted to register one. It is a nudge, not a wall: people can skip it, and by default they can keep skipping it. Nothing breaks. But every one of your employees starts seeing an unfamiliar security prompt, and if nobody has told them it is coming, your phone rings.

February 1, 2027 — Microsoft-provided text and voice codes are retired. After this date, anyone whose only second factor is a text message or phone call is required to register a passkey during sign-in before they can continue into their account. Microsoft describes this prompt as blocking, and states there is no opt-out from it for any tenant.

Nobody is permanently locked out of anything. But “my login is demanding something I have never seen and I have a client on the phone” is a bad morning for the employee and a worse one for whoever supports them — multiplied by however many people were still on text codes.

Why Microsoft is doing it

Because text-message codes were never actually strong, and attackers have gotten very good at collecting them. A convincing fake login page asks for the password and the code in the same breath, and relays both to the real site while the victim is still reading. SIM-swap fraud moves the phone number itself. Neither attack requires sophistication anymore — the toolkits are rented.

A passkey removes the thing being stolen. Instead of a secret you type, your device proves who you are with a key it never hands over, unlocked by your fingerprint, face, or PIN. There is nothing to phish, because there is nothing to type. That is the whole reason insurers and auditors started asking specifically about phishing-resistant authentication instead of just asking whether you have MFA.

The schedule, in numbers

What is coming, and when

Two dates, one enforcement moment. The middle window is the whole opportunity to do this calmly.

1 Sep

Passkeys become the default — text-code users are auto-enabled and prompted to register. Skippable.

Microsoft Entra ID, 2026

1 Feb

Text and voice codes retired. The registration prompt becomes blocking — and there is no opt-out.

Microsoft Entra ID, 2027

$0

Extra license cost to move to passkeys. Available in every Entra ID edition, including the free one.

Microsoft Entra ID documentation

Who this actually hits

Not everyone. If your people already sign in with Windows Hello, the Microsoft Authenticator app, or a security key, they are on a phishing-resistant method and nothing changes for them.

The exposure is anyone still receiving codes by text or phone call. In most small businesses that is a specific, predictable group:

  • The people who set up their account years ago and were never migrated when the Authenticator app arrived.
  • Staff without company phones — floor, field, and shift workers who registered a personal mobile number because it was the only option offered.
  • Executives and owners who opted out of installing a work app on a personal device and chose text codes instead. This group tends to be both the most exposed and the least patient about a surprise prompt.
  • Shared and kiosk accounts pointed at one office phone line — the ones nobody remembers until they stop working.
  • Anyone whose password reset depends on a text, since the retirement covers self-service password reset too.

You do not have to guess who is on the list. Microsoft publishes a script that reports exactly which accounts in your tenant are still enabled for text or voice, and running it is the honest first step — the answer is usually higher than people expect and occasionally zero, which is a good morning either way.

The part most businesses will get wrong

The temptation is to wait until January 2027 and handle it then. That converts a manageable project into a support emergency, for three reasons.

First, the September nudge is already noisy. From that date your whole team starts seeing prompts, and confused people call somebody. If that somebody has no answer prepared, you spend the autumn improvising.

Second, the hard cases take time to solve. The employee with no smartphone, the shared workstation, the executive who will not install anything — each has a good answer (a hardware security key, Windows Hello on the machine itself), but each answer needs to be chosen, bought, tested and taught. That is a calendar problem, not a technical one.

Third, doing it early is free and doing it late is not. Migrating to passkeys carries no extra license cost. The fallback for businesses that truly must keep text messages — contracting a telecom provider through the Microsoft Security Store — is a per-message expense you would be signing up for permanently, to preserve the weakest method available.

What to do, in order

  1. Find out who is still on text or voice codes. Microsoft’s reporting script names them. Until you have that list, everything else is guesswork.
  2. Sort that list into easy and hard. Most people have a company phone or a work laptop and can register a passkey in about two minutes. The rest — no smartphone, shared device, personal-device holdouts — are the real project.
  3. Decide the method for each group before you announce anything: passkey in the Authenticator app, Windows Hello on the workstation, or a hardware security key for the people the first two do not fit.
  4. Turn on passkeys and pilot with a friendly group. A handful of people, one week, real feedback. This is where you find the device that will not cooperate.
  5. Tell everyone before the prompts start — what is changing, why, what they will see, and who to ask. One short email beats a hundred help-desk calls.
  6. Run the registration campaign so people are prompted deliberately, on your schedule, with your explanation already in their inbox.
  7. Check the leftovers before the deadline and personally handle anyone still on text codes as February approaches. There are always a few.
  8. Then tighten the policy. Once your people are on passkeys, requiring phishing-resistant sign-in for sensitive access is the step that turns a migration into a genuine security upgrade — and it is what an insurer or auditor is really asking about.

Handled this way it is a few weeks of unremarkable work. Handled in January it is a fire drill with your executives in it.

Free checklist

Microsoft MFA Retirement Readiness Checklist

The eight steps above as a printable one-pager, with the two dates and space to record who is still on text codes. No form, no email required.

Open the checklist →

If you genuinely cannot move some users

There are legitimate cases — a regulator that demands an out-of-band text, a workflow with no other option. Microsoft’s answer is to contract your own telecom provider through its Security Store; details were slated for publication in September 2026, with configuration opening later in the autumn. It costs money per message, it applies only to the users who truly need it, and it should be a documented exception rather than a way to postpone the work. For everyone else, passkeys are the path Microsoft has chosen, and the one your insurance questionnaire is drifting toward anyway.

Quick answers

The MFA retirement, answered plainly

Is Microsoft really turning off SMS and voice MFA?

Yes, on a published schedule. Microsoft has announced that from February 1, 2027 it will stop providing SMS and voice delivery for multi-factor authentication in Microsoft Entra ID (the identity system behind Microsoft 365). Before that, on September 1, 2026, passkeys become the default sign-in experience and users still set up for text or phone-call codes are automatically enabled for passkeys and prompted to register one. Organizations that genuinely need a telephone channel after the retirement will be able to contract their own telecom provider through the Microsoft Security Store, at their own cost.

What happens if we do nothing before February 1, 2027?

Anyone whose only second factor is a text message or phone call will hit a blocking prompt at sign-in: they must register a passkey before they can get into their account. It is not a warning they can dismiss, and Microsoft has stated plainly that there is no opt-out from that behavior for any tenant. Nobody is permanently locked out — but people will be stopped mid-morning and asked to set up a new sign-in method, without warning, unless you have prepared them.

What exactly is a passkey?

A passkey replaces the password and the code with the unlock you already use on your device — a fingerprint, a face scan, or a PIN. The secret never leaves your phone or laptop, and nothing is typed, so there is nothing for a fake login page to capture or for an attacker to intercept in a text message. Microsoft supports passkeys stored in the Microsoft Authenticator app, in a security key, in Windows Hello, and in platform password managers such as iCloud Keychain or Google Password Manager.

Do we need to buy new licenses for passkeys?

No. Microsoft states that passkeys are available in every Microsoft Entra ID edition, including the free one, and that no extra licenses are required. Moving users from Microsoft-provided SMS and voice to passkeys carries no additional cost. Enforcing passkeys for sensitive access — a Conditional Access authentication strength policy — does require Entra ID P1, which is already included in Microsoft 365 Business Premium, E3 and E5. Keeping text messages through a third-party telecom provider is the option that costs money, typically per message.

Our staff share devices or work without phones. What then?

That is exactly the case to plan for early rather than discover on February 1. Passkeys do not require a personal phone: they can live in a hardware security key that hangs on a lanyard, or in Windows Hello on the workstation itself. Shift workers on shared machines, floor staff without company phones, and anyone who refuses to install a work app on a personal device all have a workable path — it just needs to be chosen and tested, not improvised at a sign-in prompt.

Does this affect password resets too?

Yes. The retirement of Microsoft-provided SMS and voice applies across Entra ID, including self-service password reset, so a text message will no longer be a way to verify yourself while resetting a password unless you have contracted your own telecom provider. If your password-reset process depends on texting a code, that process needs revisiting on the same timeline.

Not sure who in your business is still on text codes?

A free 30-minute assessment with the owner — we will walk your Microsoft 365 setup, tell you honestly how exposed you are to this deadline, and what the work involves.

Book a Free 30-Minute IT Assessment