Checklist · Microsoft 365
Microsoft MFA Retirement Checklist
Microsoft is retiring text-message and phone-call login codes on February 1, 2027, and passkeys become the default sign-in experience on September 1, 2026. After the retirement, anyone whose only second factor is a text hits a prompt they cannot skip. These are the eight steps to get there calmly.
The order is the strategy
The eight steps are sequenced on purpose: the early ones — finding who still signs in with texted codes, picking each group's method — decide whether the deadline months are calm or chaotic. Skip ahead and the hard cases surface at the worst time.
Forward this page to whoever runs your Microsoft 365 today. It's their to-do list now.
Read the full explainer →The checklist
Work top to bottom. The order matters more than the speed — every step below exists because skipping it turns up later as a support call.
Who this applies to. Any business running Microsoft 365 where some people still receive a six-digit code by text message or phone call. If everyone already signs in with Windows Hello, the Microsoft Authenticator app or a security key, you are already on a phishing-resistant method and nothing changes for you.
Why not just wait. From September 1, 2026 your whole team starts seeing unfamiliar prompts, so the support calls begin months before the deadline does. The hard cases — no smartphone, shared machines, personal-device holdouts — each need a method chosen, bought and tested, which is a calendar problem rather than a technical one. And moving to passkeys costs nothing in licensing, while keeping text messages afterward means contracting a paid telecom provider to preserve the weakest method available.
Before you touch anything
- Run Microsoft's reporting script to list every account still enabled for text or voice codes. Any result above zero means you are in scope.
- Note the two dates on your calendar now: September 1, 2026 (passkey prompts begin) and February 1, 2027 (text and voice codes retired).
- Confirm which Microsoft plan you hold. Passkeys need no extra license; enforcing them later needs Entra ID P1, which Business Premium, E3 and E5 already include.
Sort the list
- Separate the easy majority — anyone with a company phone or a work laptop can register a passkey in about two minutes.
- Flag staff with no smartphone: floor, field and shift workers who registered a personal number because it was the only option offered.
- Flag shared, kiosk and front-desk accounts pointed at one office phone line.
- Flag the personal-device holdouts, usually executives and owners. Decide their method before you ask them anything.
- Check whether your password-reset process depends on a text message — the retirement covers self-service password reset too.
Choose the method for each group
- Passkey in the Microsoft Authenticator app — the default for anyone with a work or personal smartphone they will use.
- Windows Hello on the workstation — fingerprint or face on the machine itself, ideal for desk-bound staff and shared computers.
- A hardware security key — for people with no usable phone, or who will not install a work app on a personal device.
- Document the exception list: anyone with a genuine regulatory need for a text message, and the reason, in writing.
Pilot before you announce
- Turn passkeys on for the tenant and enroll a small, friendly group first.
- Test each chosen method on the real devices your people actually use, including the awkward ones.
- Time the enrollment so you can tell everyone honestly how long it takes.
- Write down what broke in the pilot — that list is your help-desk script later.
Communicate, then migrate
- Send one plain-English email before any prompts appear: what is changing, when, what they will see, and who to ask.
- Run a registration campaign so people are prompted on your schedule rather than by surprise.
- Give the hard cases a scheduled fifteen minutes with a human instead of a prompt.
- Send a reminder to anyone who has not registered, well before February.
Finish and lock it in
- Re-run the reporting script and personally handle whoever is still on text codes as the deadline approaches.
- Require phishing-resistant sign-in for sensitive access once your people are migrated — this is the step that turns a migration into a security upgrade.
- Record what you did and when. It is the evidence your insurer and auditor will ask for.
- Remove text and voice as available methods so nobody drifts back.
Not sure how many of your people are still on text codes, or which method fits the awkward cases? That is a good use of thirty free minutes. Book the assessment →