The way organisations authenticate users is undergoing one of its most significant shifts in years. As AI‑driven cyber threats grow more sophisticated, traditional methods like SMS and voice authentication simply can’t keep pace. Microsoft has now confirmed that passkeys will become the default authentication experience in Microsoft Entra ID, and that Microsoft‑provided SMS and voice authentication will retire on 1st February 2027.
For many organisations, this marks a turning point. At Zephi IT Solutions, we’re helping businesses understand what this change means, why it’s happening, and how to prepare well ahead of the deadline.
Why Microsoft Is Moving Away from SMS and Voice
SMS and voice authentication have long been popular because they’re easy to use and familiar to end‑users. But familiarity doesn’t equal security. These methods are among the most vulnerable to modern attacks, from phishing and SIM‑swaps to replay attacks that exploit intercepted codes.
Passkeys, by contrast, offer a fundamentally stronger approach. They rely on cryptographic authentication rather than shared secrets, making them resistant to phishing and dramatically reducing the risk of credential theft. Microsoft’s decision reflects a broader industry trend: stronger, phishing‑resistant authentication must become the default, not an optional upgrade.
What’s Changing and When
Starting on 1st September 2026, any user currently enabled for SMS or voice authentication will automatically be enabled for passkeys. When they next complete MFA, they’ll be prompted to register a passkey. Organisations that do not want this automatic enablement must adjust their Authentication Methods Policy before that date.
The more significant milestone arrives on 1st February 2027, when Microsoft‑provided SMS and voice authentication will be fully retired. After this point, any user whose only MFA method is SMS or voice will be blocked from signing in until they register a passkey. This enforcement applies to all tenants, with no opt‑out available.
It’s important to note that customer‑managed telecom providers, configured through the Microsoft Security Store, are not affected by this retirement. Organisations with regulatory or operational requirements to continue using SMS or voice can adopt one of these providers, with options and pricing available from 18th September 2026 and configuration opening on 30th October 2026.
What This Means for Your Organisation
If your tenant has already moved away from SMS and voice, you can consider yourself ahead of the curve. But if even a small number of users still rely on these methods, action is required. Waiting until 2027 risks user lockouts, support bottlenecks, and unnecessary disruption.
The recommended path is clear: transition users to passkeys, Microsoft’s default phishing‑resistant credential. Doing so not only aligns with Microsoft’s long‑term identity strategy but also strengthens your organisation’s security posture in an increasingly hostile threat landscape.
How to Prepare: A Practical Approach
The first step is understanding who in your organisation is still using SMS or voice for MFA. Once you’ve identified these users, enable passkeys and begin a registration campaign that encourages early adoption. Organisations that act before September 2026 retain full control over the pace of their rollout, avoiding the pressure of automatic enablement.
Communication is equally important. Users need to know what’s changing, why it matters, and what they’re expected to do. Clear, timely messaging can prevent confusion and reduce the burden on IT support teams.
Only organisations with strict regulatory or operational requirements should consider retaining SMS or voice through a customer‑managed telecom provider. For most businesses, passkeys offer a simpler, more secure, and future‑proof solution.
The Bottom Line
Every user who currently relies on SMS or voice authentication must transition to a phishing‑resistant method, ideally passkeys, before 1 February 2027. Acting early ensures a smooth experience, avoids blocking prompts, and gives your organisation the breathing room to manage the change on your own terms.
At Zephi IT Solutions, we’re ready to support you through every stage of this transition, from auditing your current authentication methods to planning your rollout and communicating with your users.
If you’d like help preparing your organisation for the move to passkeys, just let us know.





