01/09/2026
Microsoft is retiring its own SMS and voice MFA service from 1 February 2027, and the first changes taking effect from today.
If your employees currently receive a text message or phone call to authenticate into Microsoft 365, your business needs to start planning what they will use instead.
Microsoft is moving organisations towards phishing-resistant authentication, with passkeys becoming the default experience.
But there is no single answer for every employee.
In our latest guide, we explain:
- What Microsoft is changing and when
- What passkeys and phishing-resistant authentication actually mean
- When Microsoft Authenticator may be appropriate
- Alternatives for employees who cannot or do not want to use a mobile phone
- FIDO2 security keys and hardware OTP tokens
- How to plan the migration without leaving employees unable to sign in
The key advice is simple: do not wait until SMS and voice disappear before working out what each employee will use instead.
Read the full guide here:
Microsoft is retiring SMS and voice MFA in 2027. Learn how to transition to secure authentication methods for your business before the change takes effect.