If you’re used to signing into Microsoft 365 and waiting for a six-digit code to arrive by text, that experience is on its way out.
Microsoft is moving away from SMS and voice calls as preferred methods of verifying sign-ins and pushing users toward more secure options, including passkeys and the Microsoft Authenticator app.
For businesses, this is less about learning another Microsoft feature and more about making sure employees are ready before their familiar sign-in option changes.
Why Is Microsoft Moving Away From Text Messages?
Text-message verification was a big improvement over using a password alone. The problem is that attackers have gotten better at getting around it.
SMS codes can be intercepted or stolen through phishing and SIM-swapping attacks. They also depend on your mobile carrier actually delivering the message. Anyone who has stared at a login screen waiting for a code that never arrives knows that isn’t always a given.
Microsoft now recommends stronger authentication methods that don’t rely on a text message being sent to your phone.
That includes Microsoft Authenticator, Windows Hello for Business, security keys and, increasingly, passkeys.
Wait — What’s a Passkey?
A passkey is essentially a replacement for a traditional password that uses something you already have, such as your phone or computer, to verify that you’re really you.
Depending on the device, that might mean using your fingerprint, Face ID, Windows Hello or your device PIN.
The important part isn’t the terminology. It’s that passkeys are designed to be much harder for an attacker to steal through a fake login page.
Microsoft Authenticator can also be part of this experience. The app supports MFA approvals, verification codes, passwordless sign-in and passkeys.
What Is Actually Changing?
Microsoft has been moving users toward stronger authentication for some time, but there are now some important dates for businesses using Microsoft Entra ID.
Beginning September 1, 2026, Microsoft plans to start automatically enabling passkey registration prompts for users who are still enabled for SMS or voice authentication.
Then, beginning February 1, 2027, Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID.
That doesn’t mean everyone’s text-message MFA will suddenly disappear tomorrow. Organizations have time to prepare, and Microsoft provides administrators with options for managing the transition.
But it does mean businesses shouldn’t wait until employees are confronted with an unfamiliar sign-in screen to figure out what they’re supposed to do.
What Does This Mean for Your Employees?
For most users, the biggest change will simply be how they prove it’s really them when they sign in.
Instead of:
Password → Receive text → Enter six-digit code
they may use something like:
Password → Approve sign-in through Authenticator
or eventually:
Passkey → Face, fingerprint or device PIN
Depending on how your Microsoft environment is configured, the exact experience may look different.
And that’s important: businesses shouldn’t tell employees to blindly follow every unexpected authentication prompt they receive. Your IT provider or internal IT team should determine which authentication methods your organization is using and communicate that process to employees.
Why This Is a Good Thing
Any change to the login process can be annoying at first. From a security standpoint, though, moving away from SMS makes sense.
Passwords get stolen. Text-message codes can be phished. Attackers routinely create convincing Microsoft login pages designed specifically to capture credentials and verification codes.
Modern authentication methods make that considerably harder.
Microsoft is also increasingly using system-preferred authentication, which means that when someone has multiple authentication methods registered, Microsoft can prompt them to use the strongest available option instead of automatically falling back to something weaker.
The goal is pretty simple: make the easiest way to sign in also one of the safest.
What Should Businesses Do Now?
You don’t need to panic, and you don’t need to wait until 2027 either.
This is a good time to have your team review:
• Which employees are still using SMS or voice calls for MFA
• Whether passkeys are appropriate for your organization
• Which authentication methods are allowed in Microsoft Entra ID
• How employees will be notified and trained before their sign-in experience changes
• What your recovery process looks like when someone loses or replaces a phone
A little preparation now can prevent a lot of “I can’t get into my email” calls later.
MFA Isn’t Going Away — It’s Getting Better
The takeaway isn’t that Microsoft is getting rid of multi-factor authentication.
Quite the opposite.
Microsoft is moving away from some of the older ways of doing MFA and toward methods that are harder for attackers to steal, intercept or trick users into handing over.
If your business still relies heavily on text-message codes, now is a good time to review how your Microsoft 365 accounts are protected and start preparing employees for what’s coming.
Not sure which authentication methods your organization is currently using? InfiNet Solutions can review your Microsoft 365 security configuration, identify users still relying on older authentication methods and help you plan the transition without turning it into a company-wide login headache.