Back to BlogCybersecurity

Microsoft SMS MFA Retirement: What Small Businesses Need to Do Before February 2027

August 30, 20265 min read
A businesswoman using a smartphone beside her laptop in an office.

The Microsoft SMS MFA retirement is now on a real clock, and the first change arrives before most businesses have planned for it. Starting September 1, 2026, Microsoft Entra ID begins automatically enabling passkeys for users who are enabled for Short Message Service (SMS) texts or voice authentication. On February 1, 2027, Microsoft will retire the SMS and voice delivery it currently provides inside Entra ID.

This timeline applies to public-cloud Entra ID tenants. Azure AD B2C and Entra External ID are not included in this announcement, and other Microsoft cloud environments will follow later.

That sounds like an IT housekeeping item. It is not. An estimator in Fountain who cannot reach email before a bid deadline, or a front-desk employee in Pueblo who gets stopped on the way into a scheduling system, does not care which authentication policy changed. They care that work stopped.

This is manageable, but the plan must cover more than installing an app.

The Microsoft SMS MFA retirement has two important dates

Microsoft's retirement announcement separates the change into two stages.

Starting September 1, 2026, users enabled for SMS or voice in the Entra Authentication Methods Policy or legacy MFA settings will be automatically enabled for passkeys as Microsoft rolls out the change. Microsoft also moves the registration campaign into a Microsoft-managed state for those users. After completing their usual sign-in verification, they can be prompted to create a passkey.

Automatic enablement is not the same as a completed migration. Before the retirement date, the Microsoft-managed prompt allows unlimited snoozes. A tenant can therefore look ready in the policy screen while employees keep postponing registration.

On February 1, 2027, Microsoft-provided SMS and voice delivery ends. A user whose only available multifactor authentication (MFA) method is SMS or voice must register a passkey before continuing to sign in. The prompt becomes blocking, and Microsoft says there is no opt-out from that enforcement.

Dates to know: Passkey enablement and registration nudges begin September 1, 2026. Microsoft-provided SMS and voice delivery ends February 1, 2027.

Microsoft is not banning every possible phone-based option. Organizations with a documented operational or regulatory reason can contract with a customer-managed telecom provider through the Microsoft Security Store. That exception will require a separate provider relationship, with pricing set by the provider and costs typically based on message volume.

Why SMS and voice are losing their place

A texted code feels separate from a password, but both can be captured by the same fake sign-in page. An attacker can collect the password, ask for the one-time code, and relay both to the real Microsoft login while the code is still valid. SIM swaps, phone-number porting, and unreliable delivery add another layer of risk.

NIST's current digital identity guidance treats authentication through the public telephone network as restricted. It also says manually entered one-time codes are not phishing-resistant because an impostor can relay them.

A passkey works differently. It uses a cryptographic key tied to the legitimate service where it was created. The private part stays on the user's device or inside an approved passkey provider, and a fingerprint, face scan, or device PIN unlocks it locally. There is no reusable password or six-digit code for an employee to type into a convincing fake Microsoft page.

That makes this change more than a Microsoft deadline. It is a useful forcing function for any Colorado Springs or Pueblo business that has treated all forms of MFA as equally strong. Our managed cybersecurity work increasingly starts with identity because email, cloud files, accounting tools, and password resets all depend on who the system believes is signing in.

Microsoft Authenticator and an Authenticator passkey are not the same thing

This detail will trip people up. Microsoft Authenticator can handle push approvals, rotating verification codes, passwordless phone sign-in, and device-bound passkeys. Those are different authentication methods even though they live in the same app.

A normal push approval is not automatically phishing-resistant. Neither is a rotating code. A passkey created inside Microsoft Authenticator uses FIDO2, an open authentication standard, and is phishing-resistant. Microsoft's own authentication-strength table draws that distinction.

So the useful rollout question is not, "Does everyone have Authenticator?" It is, "Which method has each person actually registered, and does it work on the devices that person uses?" A green check next to an app installation does not answer that.

Having Microsoft Authenticator installed does not mean an employee has registered a phishing-resistant passkey.

A practical Microsoft SMS MFA retirement plan for a small team

For a ten-person office, the technical clicks are not the hard part. The work is matching authentication to real people, real devices, and the awkward situations that happen after rollout.

  1. Inventory the people in scope. Use Microsoft's authentication-method reports or its SMS and voice usage analyzer. Check registered methods and actual usage instead of assuming everyone is covered.
  2. Choose the credential by role. An office employee may use Windows Hello plus a portable passkey. An administrator or someone handling regulated data may warrant a hardware FIDO2 security key. A field employee needs a flow tested on the phone that person actually carries.
  3. Pilot before enforcing. Test a small group across Windows, iPhone, Android, browsers, Microsoft mobile apps, shared workstations, and any older devices still in service.
  4. Give every user a backup and a recovery path. Microsoft recommends at least two registered methods. Administrators should also know how to issue a Temporary Access Pass when a phone is lost or a passkey becomes unavailable.
  5. Explain the prompt before it appears. An unexplained security-registration screen looks suspicious, especially after years of telling employees not to trust unexpected login prompts.
  6. Track completion, then remove the weak method. Do not leave SMS available forever just because the stronger method was registered once.

Where GTZ's passkey manager fits

GTZ also provides a managed enterprise password and passkey manager in qualifying managed-service plans. It gives employees an encrypted business vault for their remaining passwords and supported passkeys, with access across authorized browsers and devices instead of a scattered mix of browser profiles, personal keychains, and notes nobody can recover during offboarding.

The management piece matters. We can provision users, apply business policies, help employees enroll, and remove company access when someone leaves. That is part of the wider managed IT service, not another app dropped on an employee's desktop with no training.

A passkey manager does not replace the Entra work. The tenant still needs the right passkey profiles, compatible devices, tested recovery, and policies that require the intended authentication strength. But it gives the business a managed home for supported passkeys and makes the human side of adoption much cleaner.

If someone truly needs SMS or voice after February

Some organizations have a legitimate workflow that still depends on a telecom channel. Microsoft says provider options and terms will appear in the Security Store beginning September 18, 2026, with configuration available beginning October 30, 2026. According to Microsoft's retirement FAQ, pricing will vary by provider and region, with costs typically charged per message and influenced by volume and geographic distribution.

As of August 30, 2026, Microsoft has not published those Security Store provider choices or prices. Any quote for the new Security Store options before then is speculative.

Our recommendation is to treat phone delivery as a documented exception. Do not keep every employee on a weaker method because one shared workstation, legacy device, or regulated process needs special handling. Identify that group, confirm the requirement, test the provider when details are available, and move everyone else to phishing-resistant credentials.

Do not let a blocking prompt choose your rollout date

The September prompt may help adoption, but unlimited snoozes make it a reminder rather than a migration plan. By February, the same conversation happens while an employee is trying to work.

Start with the inventory. Then choose where passkeys will live, test the devices your people actually use, set up recovery, and tell the team what they will see. For a small Southern Colorado business, that can be a controlled project. Left until the deadline, it becomes a help-desk scramble at exactly the wrong time.

Free Consultation

Questions About Your IT?

Book a free assessment with Efrain. No sales pitch, no obligation.

Get Your Free Assessment
Call (719) 203-7752