Is Your Organization Ready for Microsoft’s MFA Changes?

by | Aug 31, 2026 | Blogs, Security

Microsoft Is Retiring SMS and Voice Authentication: What This Means for Your Organization

If your organization uses text messages or phone calls as part of your Microsoft multifactor authentication (MFA) strategy, there is an important change on the horizon that should be on your radar now.

Microsoft recently announced that it is retiring Microsoft-provided SMS and voice authentication for Microsoft Entra ID and making passkeys the default authentication experience moving forward. Beginning September 1, 2026, users who currently rely on SMS or voice authentication will begin being prompted to register passkeys. By February 1, 2027, Microsoft-provided SMS and voice authentication services will be retired. [learn.microsoft.com][mc.merill.net]

While 2027 may seem a long way off, this is one of those changes that organizations should start planning for sooner rather than later.

Why Microsoft Is Making This Change

The reality is that the threat landscape has changed significantly over the last few years.

Cybercriminals have become increasingly effective at bypassing traditional authentication methods through phishing attacks, social engineering, MFA fatigue attacks, and SIM-swapping techniques. While SMS-based MFA has historically been viewed as a strong security control, it is no longer considered the gold standard for protecting modern identities. [learn.microsoft.com][microsoft.com]

Microsoft’s response is to accelerate adoption of phishing-resistant authentication methods, with passkeys becoming the preferred approach for securing user identities.

From a security perspective, this is a positive move.

The Bigger Question: Are You Ready?

When we talk with clients about authentication, one of the most common assumptions is:

“We’re using MFA, so we’re good.”

The challenge is that many organizations don’t actually know:

  • How many users are still authenticating with SMS
  • Whether voice authentication is still enabled
  • Which users have already adopted stronger authentication methods
  • Whether their Entra policies align with Microsoft’s current security recommendations
  • How a change like this could impact user adoption and help desk workloads

For many organizations, authentication settings were configured years ago and haven’t been revisited since.

This retirement announcement is creating an opportunity to take a fresh look at identity security and determine whether your environment is prepared for the next generation of authentication.

What Are Passkeys?

Simply put, passkeys are designed to replace passwords and SMS verification codes with a more secure, phishing-resistant login experience.

Passkeys leverage trusted devices and modern authentication methods such as:

  • Windows Hello for Business
  • Microsoft Authenticator
  • FIDO2 security keys
  • Device biometrics, including facial recognition and fingerprints

The result is a login experience that is often faster for users while significantly reducing the risk of credential theft and phishing attacks.

In many cases, users find passkeys easier to use than waiting for a text message or entering a one-time code.

What We Recommend Clients Do Now

Even though the retirement date is still months away, now is the right time to start planning.

At Covenant, we’re encouraging clients to take four proactive steps:

1. Identify Who Is Using SMS or Voice Authentication

Before making any changes, understand your current state.

Determine:

  • How many users rely on SMS for MFA
  • Whether voice authentication is still enabled
  • Which departments may be most impacted by a transition

This baseline assessment helps avoid surprises later.

2. Review Your Authentication Policies

Many organizations have accumulated authentication settings over time.

A review of your Microsoft Entra authentication methods, Conditional Access policies, and passwordless readiness can help identify areas for improvement and ensure alignment with Microsoft’s future direction.

3. Create a User Adoption Strategy

Technology changes are only successful when users are prepared.

Organizations should begin thinking about:

  • User communications
  • Training requirements
  • Pilot groups
  • Executive sponsorship
  • Help desk preparedness

The earlier these conversations start, the smoother the transition will be.

4. Move Toward Phishing-Resistant Authentication

Microsoft’s message is clear: the future of identity security is phishing-resistant authentication.

Whether that means passkeys, Windows Hello for Business, FIDO2 security keys, or a combination of approaches, organizations should begin evaluating what makes the most sense for their workforce and security requirements. [learn.microsoft.com][microsoft.com]

How Covenant Can Help

As a Microsoft Security partner, we’re already helping organizations evaluate their identity security posture and prepare for changes like this.

Our team can help you:

  • Assess current authentication methods across your environment
  • Identify users relying on SMS or voice authentication
  • Review Microsoft Entra configurations and security policies
  • Develop a transition roadmap
  • Implement passkeys and passwordless authentication strategies
  • Educate end users and stakeholders on upcoming changes

More importantly, we can help ensure that your organization doesn’t wait until Microsoft deadlines create unnecessary disruption.

Final Thoughts

Authentication remains one of the most important security controls in your organization. Microsoft’s decision to retire SMS and voice authentication is another step toward a more secure, passwordless future.

Organizations that begin preparing now will be in a much stronger position than those waiting until the retirement deadline approaches.

If you’re unsure whether your users are still relying on SMS-based MFA, that’s the perfect place to start.

The Covenant Security team would be happy to help you assess your current environment, understand your exposure, and build a practical path forward.

Interested in understanding your organization’s readiness? Reach out to our Security team to schedule an Identity Security Assessment and Passkey Readiness Review.