What is happening, and when

Microsoft is retiring its built-in SMS and voice verification methods in Entra ID, the sign-in for Microsoft 365. According to Microsoft's own documentation it happens in two steps:

  • 1 September 2026: passkeys are enabled by default, and users are prompted to register one.
  • 1 February 2027: SMS and voice calls stop working as a verification method.

Do not conflate them. The first is a reminder. The second is a closed door. And it applies to everyone, there is no opt-out.

Why Microsoft is doing it

Because SMS was never particularly secure. Codes can be fished out in real time by a fake sign-in page, and phone numbers can be hijacked. What made SMS popular was that everyone already has a phone, not that it did the job.

Passkeys, meaning sign-in with fingerprint, face or a PIN tied to a device, cannot be talked out of someone the same way. This is not Microsoft being difficult: Google and Apple are moving in exactly the same direction. SMS as a security factor is running out everywhere.

What actually gets awkward

The switch itself is simple for most people. A modern phone or computer handles passkeys directly, and it takes a minute per person.

The problem is the last five percent, and they look the same in almost every company we meet: the person in production or the shop who shares an account and has no device of their own. The owner who is the only administrator and therefore has nobody to unlock for them. The contractor or seasonal worker without a work phone. The person who consistently declines anything involving an app.

None of them is a technical problem. All of them become an urgent problem at eight o'clock on a Monday in February if you have not looked for them in advance.

What we recommend

  • Do the inventory now, not in January. Pull the list of who still uses SMS or voice calls. You have five months, not five days.
  • Start with the admin accounts. They should never be on SMS anyway, whatever Microsoft does.
  • Handle the special cases separately. Shared accounts, people without a device and emergency access each need their own plan, not a mass email.
  • Use the opportunity to clean up. While you are going through who signs in how, close the accounts that are not in use.

This is exactly the kind of everyday work we take care of under Managed IT: we do the inventory, fix the special cases and make sure nobody ends up locked out. Want to know how many at your company are affected? Book a free consultation and we will look together.