SMS and voice are going as MFA in Microsoft 365

Someone holding an iPhone next to a MacBook

⏱ Reading time: ± 6 minutes

On 1 February 2027, Microsoft will stop sending SMS and phone codes for signing in to Microsoft 365 and Entra. Passkeys are becoming the norm. After that date, the old method will no longer work.

Don't panic: you have plenty of time. But it pays to understand what's happening now, so that nobody on your team ends up locked out later on.

Key takeaways

  • What: Microsoft is dropping SMS and phone calls as a way to sign in to Microsoft 365 and Entra.
  • When: from 1 September 2026, passkeys become the default; on 1 February 2027, SMS and voice codes stop for good.
  • Why: SMS is too easy to intercept; passkeys are resistant to phishing.
  • For you: anyone who uses only SMS or phone will have to set up a passkey after 1 February 2027. There are no exceptions.
  • To do now: find out who still uses SMS or phone, and get those people to switch in good time.

What exactly is changing?

Many businesses today protect their Microsoft 365 with an extra step after the password. Often that's a code sent by text message or a phone call. This is known as multi-factor authentication, or MFA for short.

Microsoft is ending both of those methods. In practice:

  • From 1 September 2026, passkeys become the default way to sign in. Users who currently rely on SMS or phone will automatically be asked to set up a passkey.
  • From 1 February 2027, Microsoft itself will no longer send SMS or voice codes. Anyone who has only that method by then will see a mandatory screen at sign-in asking them to set up a passkey first. Only then can they carry on.

Important: there is no exception and no way to opt out of that requirement on 1 February 2027. It applies to every organisation.

Already using something other than SMS or phone today, such as the Microsoft Authenticator app, Windows Hello or a physical security key? Then you can simply keep using it. Very little changes for you.

Why is Microsoft doing this?

The reason is security. For years, a code by text message seemed safe, but attackers have since found ways around it. They intercept messages, hijack phone numbers through what's known as SIM swapping, or lure people to a fake page that passes the code straight on.

That last one, phishing, has become far more dangerous in recent years. Attackers now use artificial intelligence to create convincing fake emails and fake screens. According to figures cited by Microsoft, up to 54% of people click through on an AI-generated phishing email, compared with around 12% for traditional phishing. (Source: Microsoft Security Blog, 2026) An SMS code won't stop a targeted attack like that.

An attacker can steal a password and trick you into handing over an SMS code, but a passkey only works on the real website. It simply doesn't recognise a fake.

What is a passkey?

A passkey is a way of signing in without a password and without a code. Instead, you confirm who you are with something you already have: your fingerprint, your face or your device PIN. Think of how you unlock your banking app or your phone today.

Behind the scenes, it uses a digital key that is tied to Microsoft's real website. If an attacker tries a fake site, the passkey simply refuses to work, because the key doesn't recognise the fake page. So there's nothing to intercept or hand over, as there's no code for you to type in anywhere.

For the user, it's often quicker and easier than waiting for a text message, too. Unlock your device and you're done.

Passkeys can be stored in different places:

  • In a password manager: a separate app that stores your passkeys and passwords securely and syncs them across all your devices.
  • In an app or on your device: for example in the Microsoft Authenticator app, in Windows Hello, or in Apple's or Google's built-in storage.
  • On a separate key: a small physical stick (a FIDO2 key) that you plug into your computer or hold against your phone.

Where should you keep your passkeys? Choose a good password manager.

This is the question that makes the biggest difference in the long run. A passkey is only as convenient as the place where it's stored.

Does everyone in your business use Apple devices? Then Apple's built-in storage (Keychain) is perfectly fine. It works smoothly and syncs neatly between iPhone, iPad and Mac.

Once you're running a business, though, that model soon hits its limits:

  • You don't work with Apple alone. Most SMEs have a mix of Windows computers, Android phones and sometimes Apple. Apple's Keychain stops at the edge of the Apple ecosystem.
  • You want to be able to share passkeys. Think of a shared login for your accounting software or a social media account. With a proper password manager, you can share these securely within a team, without sending passwords by email or chat.

For a business, a separate password manager is therefore almost always the better choice. It works on every device, lets you share securely and gives you an overview of who has access to what.

How we handle it at nxtbit. We include that password manager as standard in three of our NXT managed services plans. That way the basics are right from the start, and nobody has to go hunting for separate tools.

And it doesn't stop there. On top of the business licence, every employee also gets a family licence for five people. So it's not just the company accounts that are protected, but also the personal logins of your people and their families. Safe habits at home make your employees more resilient at work, too.

What does this mean for your business?

That depends on how you sign in today. This timeline will help you get your bearings:

  1. 1

    1 September 2026

    Passkeys become the default. SMS and phone users are asked to set one up.

  2. 2

    18 September 2026

    Microsoft announces which external telecoms providers may continue to deliver SMS, for those who genuinely need it.

  3. 3

    30 October 2026

    Businesses that insist on keeping SMS can set up a provider. This comes at a cost.

  4. 4

    1 February 2027 Deadline

    Microsoft's SMS and phone codes stop. Anyone who has only that method must set up a passkey.

For most SMEs, the message is simple: move your people over to passkeys, and this change is nothing to worry about. Setting up passkeys for your employees costs nothing extra with Microsoft. Only those who want to use an external SMS provider pay for it.

What should you do now?

You have until early 2027, but leaving it to the last minute isn't wise. A phased approach means nobody finds themselves locked out one morning.

01

Find out who still uses SMS or phone.

Often it's only a handful of people, and sometimes they're the busiest or most important ones.

02

Choose where to store the passkeys.

For a business with a mix of devices, a separate password manager is the best choice: passkeys then work everywhere and can be shared securely.

03

Get your people to switch in good time.

A short explanation and some guidance work better than a mandatory screen that suddenly pops up.

04

Communicate clearly.

Explain what's changing, when, and what each employee needs to do. Good communication is a reliable predictor of a smooth transition.

Does your business have a genuine reason to keep SMS, for example strict regulations in your sector? Then you have the option of working through an external provider. For most SMEs that isn't necessary, and passkeys are the better and cheaper choice.

Frequently asked questions

Do I need to switch everything over right now?
No. You have until early 2027. But start in good time, so the switch can be phased and calm and nobody gets stuck at the last minute.
What if an employee doesn't have a smartphone?
Then a physical security key (a FIDO2 stick) or a passkey in a password manager on their computer can be the answer. There's a suitable method for every situation.
Is a passkey really more secure than an SMS code?
Yes. An SMS code can be intercepted, or tricked out of someone through phishing or a hijacked phone number. A passkey only works on the real website and can't be handed over to an attacker.
Do we have to pay for this switch?
Setting up passkeys with Microsoft costs nothing extra. Only those who insist on keeping SMS through an external provider pay for it. At nxtbit, the password manager comes as standard with the three top NXT managed services plans.
What changes for users who already use the Authenticator app?
Very little. Anyone who already signs in with a phishing-resistant method such as the Microsoft Authenticator app, Windows Hello or a security key can simply keep using it.

Secure your sign-in now

nxtbit is the Apple-first IT partner for SMEs in Flanders. One dedicated point of contact, proactive management, no surprises. For us, passkeys and a password manager are a standard part of a well-managed workplace.

Sources