Back to BlogEmail Security Guides

Is Microsoft Ending Text-Message MFA? Passkeys Will Be the Entra ID Default

StopSpoofingMe TeamPublished 6 min read

Yes, for the text and voice codes Microsoft sends itself. Microsoft announced on July 13, 2026 that it will start rolling out passkeys as the default sign-in method in Entra ID on September 1, 2026, and that its own SMS and voice MFA will end on February 1, 2027. Small businesses should move their SMS users to passkeys now.

Key takeaways

  • From September 1, 2026, as the rollout reaches each organization, users enabled for SMS or voice will be automatically enabled for passkeys and prompted to register one at their next MFA sign-in.
  • On February 1, 2027, Microsoft-provided SMS and voice authentication will end. After that, users who use SMS or voice for MFA will be required to register a passkey before they can sign in, and Microsoft says there will be no opt-out.
  • Organizations that still need SMS or voice will have to contract a telecom provider through the Microsoft Security Store and pay the telecom-related costs.
  • Passkeys use cryptography instead of codes a person can be tricked into sharing, which helps prevent the mailbox takeovers behind many business email compromise (BEC) scams.
  • Passkeys don't stop every trick. Block sign-in flows you don't use, such as device code flow, and keep verifying payment changes by phone.

What did Microsoft announce?

On July 13, 2026, Nadim Abdo, Microsoft's Corporate Vice President of Identity and Network Access Engineering, announced that Microsoft Entra ID will make passkeys the default authentication experience and will stop providing SMS and voice codes itself. Entra ID is the sign-in system behind Microsoft 365, so this affects small business tenants too.

Here is Microsoft's timeline:

Date What Microsoft says will happen What to do by then
September 1, 2026 Rollout begins. Users enabled for SMS or voice are auto-enabled for passkeys and nudged to register at their next MFA sign-in. Tell users what's coming and make sure everyone has a phishing-resistant method.
September 18, 2026 Microsoft shares pricing, commercial terms and a list of supported telecom providers. Decide whether anyone truly needs SMS or voice.
October 30, 2026 Admins can select and configure a telecom provider through the Microsoft Security Store. Contract a provider only if you must keep SMS or voice.
February 1, 2027 Microsoft-provided SMS and voice authentication ends. Have every user on a passkey or another phishing-resistant method, and configure a telecom provider for anyone who must keep SMS or voice.
After February 1, 2027 Users who use SMS or voice for MFA are required to register a passkey before they can sign in. Registration prompts are enforced for all users in all tenants, with no opt-out. —

Microsoft says these dates apply to Entra ID in the public cloud only. For most organizations, Microsoft's recommended path is to move users to passkeys "at no additional cost."

Entra ID supports two kinds of passkeys, according to Microsoft: synced passkeys, stored in credential managers such as iCloud Keychain and Google Password Manager, and device-bound passkeys, such as passkeys in Microsoft Authenticator, Entra passkey on Windows, and FIDO2 security keys.

Why does this matter for business email compromise?

Many BEC scams depend on getting into a real mailbox. Microsoft notes that attackers often use a compromised user's mailbox to send to recipients inside and outside the organization, and that BEC is a prolific type of attack.

A hijacked mailbox is dangerous because its mail is genuine. It goes out through your real mail servers under your real domain, so SPF, DKIM and DMARC, which exist to catch forged senders, have nothing to catch. The fraudulent invoice or "new bank details" email looks exactly like your colleague's normal messages because it is sent from their account.

That's why the sign-in method matters. Microsoft's announcement says SMS and voice "rely on shared secrets or channels that attackers increasingly intercept, phish, or manipulate," and that tactics such as SIM swapping and MFA bypass have become more accessible. Passkeys use public-key cryptography instead of a shared secret, which Microsoft describes as "phishing-resistant by design."

Microsoft also cites its own threat intelligence: AI-enabled phishing campaigns have reached click-through rates as high as 54%, compared with roughly 12% for more traditional campaigns.

What passkeys don't fix

  • Device-code phishing. In this technique, which Microsoft documented in February 2025 in a campaign by a group it tracks as Storm-2372, the attacker tricks the victim into entering a code on a legitimate Microsoft sign-in page, which hands the attacker access tokens. Because the victim signs in on the real page, a phishing-resistant method on its own doesn't block it. Microsoft recommends blocking device code flow wherever possible.
  • Lookalike domains and fake display names. A criminal emailing from a domain you don't own never touches your sign-in system, and your DMARC policy can't stop it either, because DMARC only protects your exact domain. That's a job for inbound impersonation filtering, staff awareness and payment checks.
  • Payment fraud by process. No sign-in method stops an employee from paying a convincing fake invoice. A call-back to a number on file is the check designed to catch it.

What should a small business admin do now?

Microsoft's announcement lists four preparation steps. Here's how they look for a small business, plus two extra checks:

  1. Find who still uses SMS or voice. Review your authentication methods policy and list the users or groups enabled for SMS or voice.
  2. Turn on passkeys and pick the types. Passkeys in Microsoft Authenticator suit most phone users. Consider FIDO2 security keys for admin accounts and anyone who approves payments.
  3. Start a registration campaign now. Entra ID can prompt users to register a passkey during their MFA sign-in. Starting before September 1 means your staff move on your schedule, not Microsoft's.
  4. Tell users what's coming. Explain what's changing, when they'll see the passkey registration prompt and how to complete it on their device, so nobody mistakes it for phishing.
  5. Close the gaps passkeys leave. If you have Microsoft 365 Business Premium, which includes Entra ID P1 and Conditional Access, block device code flow unless you need it. Business Basic and Standard include Entra ID Free, which uses security defaults rather than Conditional Access.
  6. Protect your domain and your payments. Check your SPF, DKIM and DMARC with our free domain scanner, and confirm every bank-detail or payroll change by calling a number you already have on file. Our INTERPOL Operation First Light explainer covers what to do if money has already moved.

If you're on E3, the Defender for Office 365 Plan 1 features added on July 1 add impersonation protection on the email side.

Frequently asked questions

Will my users be locked out on February 1, 2027?

Microsoft hasn't described a lockout. It says that after February 1, 2027, users who use SMS or voice for MFA will be required to register a passkey before they can sign in, and there will be no opt-out. Registering passkeys early avoids a forced setup at sign-in.

Does switching to passkeys cost anything?

Microsoft says that for most organizations the recommended path is to move users to passkeys at no additional cost. Passkeys can live in Microsoft Authenticator, on Windows, or in iCloud Keychain and Google Password Manager. FIDO2 security keys are hardware from third-party vendors, so they're a separate purchase. Keeping SMS or voice through a telecom provider will carry telecom-related costs.

Can we keep using text-message codes?

After February 1, 2027, only through a third-party telecom provider. Microsoft says organizations with a regulatory, technical or business need can select and configure a provider through the Microsoft Security Store starting October 30, 2026, with pricing and a provider list due September 18, 2026. Microsoft strongly recommends moving to passkeys instead.

Do passkeys stop business email compromise?

They reduce one major route: stolen logins used to take over real mailboxes, which then send fraud that can pass SPF, DKIM and DMARC. They don't stop lookalike domains, device-code tricks or a convincing fake invoice. Pair passkeys with DMARC enforcement against forgery of your exact domain, and call-back verification for payments.

Need help planning a passkey rollout or tightening your email authentication? Call (818) 574-8240.

Sources

  1. Microsoft Security Blog — Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID (July 13, 2026)
  2. Microsoft Security Blog — Storm-2372 conducts device code phishing campaign (February 13, 2025)
  3. Microsoft Learn — Respond to a compromised cloud email account (reference documentation, undated)
  4. Microsoft Learn — Email authentication in cloud organizations (reference documentation, undated)
  5. Microsoft Learn — Microsoft 365 for business security overview (reference documentation, undated)
  6. Microsoft Learn — Microsoft Entra ID attestation for passkey (FIDO2) vendors (reference documentation, undated)

Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.

Related Topics

microsoft entra passkeys defaultmicrosoft sms mfa retiremententra id sms voice retirement february 2027phishing-resistant mfa small businessmicrosoft 365 passkeyspasskey registration campaignbusiness email compromise account takeover

Ready to Secure Your Email?

Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.