Identity has become one of the primary targets for cybercriminals. As AI makes phishing attacks faster, more convincing and increasingly difficult to detect, traditional authentication methods are no longer enough.
Microsoft's latest announcement reflects that reality. The company will retire its built-in SMS and voice authentication services for Microsoft Entra on February 1, 2027, while passkeys become the default authentication experience for users.
This announcement comes to no surprise. In our previous article, Is 2025 Going to Be the Year of Passwordless?, we already explored why the industry was steadily moving away from passwords towards phishing-resistant authentication.
And, although this may seem like a technical update, it signals something much bigger: phishing-resistant authentication is becoming the new security standard.
In this article |
1. Why Microsoft Is Moving Away from SMS and Voice
SMS and voice authentication have long been considered practical second factors, but they were never designed to withstand today's threat landscape.
SIM-swapping, phishing proxies, social engineering and the interception of one-time passcodes continue to expose their limitations. And as AI makes social engineering increasingly convincing and scalable, protecting digital identities becomes even more important.
Passkeys, on the other hand, are designed to resist phishing by default. They offer a simpler sign-in experience for users while significantly reducing the risk of credential theft and phishing.
It's a natural next step in Microsoft's broader passwordless strategy.
2. What This Means for Organisations
The key date may be February 2027, but organisations shouldn't wait until then.
From September 1, 2026, Microsoft will automatically enable passkeys for users who still rely on SMS or voice authentication and start prompting them to register one.
This doesn't mean SMS and voice suddenly stop working on September 1. During the transition period, users can still postpone registration and continue using their existing authentication method.
The hard deadline comes on February 1, 2027, when Microsoft-provided SMS and voice authentication are retired. Users whose only available MFA method is still SMS or voice will then face a blocking prompt requiring them to register a passkey before they can continue signing in.
Organisations with specific regulatory or operational requirements may have alternatives through customer-managed telecom providers, but these scenarios should be assessed carefully rather than treated as a default migration path.
For most organisations, however, the bigger question isn't simply how to replace SMS and voice, it should be:
"How does this transition fit into my broader identity strategy?"
3. Three Strategic Recommendations
Rather than treating this as another Microsoft deadline, organisations should use the coming months to determine what phishing-resistant authentication should look like in their environment.
Microsoft is clearly steering organisations towards passkeys, but that doesn't mean every user, device or organisation should follow exactly the same migration path. The right approach depends on your current authentication methods, device landscape, security requirements and operational reality.
-
Know where SMS and voice are still being used .
Many IT teams underestimate how many users, administrators or legacy scenarios still rely on these authentication methods. Visibility is the first step towards a successful migration.
-
Think beyond enabling passkeys.
The technology you choose is only one part of the equation. Your authentication policies, Conditional Access strategy, recovery scenarios and operational processes need to evolve with it.
Take FIDO2 security keys, for example. How will you manage physical keys across your users? What happens when someone loses their key and needs immediate access? How will keys be issued and replaced? And does your existing Conditional Access strategy still fit the authentication model you're moving towards?
-
Prepare your users early.
Moving away from familiar authentication methods changes the user experience. A phased rollout, clear communication and the right registration strategy can significantly reduce friction while giving IT teams time to learn and adjust before enforcement begins.
There isn't one answer that works for every organisation. That's why the transition should be treated as an Identity & Access decision rather than simply another Microsoft configuration change.
Easi's Identity & Access Specialists can help organisations assess these scenarios and determine a practical path towards phishing-resistant authentication that fits their users, devices and security requirements.
The New Authentication Baseline
Microsoft's announcement is about much more than retiring SMS and voice authentication. It reflects a broader shift towards stronger, phishing-resistant identity protection as a foundation of modern cybersecurity.
And AI is accelerating that shift. While organisations are discovering new ways to use AI to increase productivity and innovation, cybercriminals are using the same technology to make phishing and social engineering faster, more convincing and harder to detect.
Organisations that start preparing today won't just avoid disruption in February 2027. They'll take an important step towards a more secure, resilient and future-ready identity environment.
Wondering how prepared your Microsoft Entra environment is for the transition? Easi's Identity & Access Specialists can help you assess your current authentication strategy and define a practical roadmap towards phishing-resistant authentication.
> Contact us for more information
![]() |
![]() |
![]() |
|
Dylan Pylyser |
Patrick De Waele |
Loïc Op De Beek |


