Microsoft Entra Retires SMS and Voice MFA: Act Now
If SMS or a phone call is still your MFA safety net, it now has an expiration date.
Microsoft will start making passkeys the default experience for SMS- and voice-enabled users on September 1, 2026. On February 1, 2027, Microsoft-provided SMS and voice delivery retires in Entra ID public cloud. Users who have no stronger method may face a blocking passkey registration during sign-in.

The Problem
The Microsoft Entra SMS and voice retirement is easy to underestimate because “enabled” is not the same as “actively used.” A tenant may have users in scope through the modern Authentication Methods Policy, legacy MFA settings, or self-service password reset. Guest and recovery scenarios add more edges.
The dangerous plan is to wait for February and hope users register when prompted. Microsoft says there is no opt-out from the February 1 enforcement. A blocking registration flow is a poor migration experience for an executive, a frontline worker, or a user changing phones under pressure.
The Nugget
Treat this as a five-part identity migration, not a settings toggle:
-
Find the real population. Use Microsoft’s reporting and PowerShell guidance to identify everyone enabled for SMS or voice, then separate regular MFA, SSPR, guest, and recovery dependencies.
-
Enable phishing-resistant choices first. Pilot passkeys, Windows Hello for Business, and FIDO2 security keys with representative users and devices.
-
Drive registration before enforcement. Configure the Entra registration campaign for the scoped group instead of waiting for the automatic September experience.
-
Design the exceptions. Document users who genuinely need a telecom channel. Microsoft plans customer-managed providers through the Security Store, with configuration beginning October 30, 2026.
-
Measure completion weekly. Track who is registered, who still authenticates with a weak method, and which support cases fail in the pilot.
The screenshot below shows the control point in Entra: Authentication methods brings passkeys, SMS, voice, registration campaigns, and activity reporting into one admin workflow.
Why This Matters
SMS and voice are vulnerable to phishing, SIM-swap attacks, and social engineering. Passkeys replace shared secrets with cryptographic credentials tied to a device or credential store.
The security gain is important, but the operational deadline is just as important. The retirement also applies to SSPR, and B2B users remain in scope even though broader passkey support for those scenarios is planned later in 2026. That makes inventory and exception testing essential.
What Admins Should Do
-
Export the SMS- and voice-enabled population now.
-
Confirm Passkey (FIDO2) policy scope and registration options.
-
Create a pilot group that covers Windows, iOS, Android, guests, and recovery.
-
Turn on a targeted registration campaign and publish simple user guidance.
-
Review weekly registration and authentication-method activity.
-
Decide whether any regulated or operational exception needs a customer-managed telecom provider.
-
Finish the migration well before February 1, 2027.
Pro Tip
Do not report only how many users can use passkeys. Report how many users would lose their usable MFA path if Microsoft-provided SMS and voice stopped today. That is the risk number leadership can act on.
For an independent view of your Microsoft 365 security posture, SecureLeaf can help turn authentication weaknesses into a prioritized audit finding and remediation plan.
Sources
Head of AI
Jannik brings deep expertise in AI integration, modern infrastructure, and enterprise transformation at scale.
Leading Expert
Florian specializes in Intune, endpoint management, and security with extensive real-world enterprise experience.