Microsoft 365 · Sign-in security

Microsoft is ending SMS codes: what it means for your sign-in

Since 1 September 2026, Microsoft has been enabling passkeys by default in Entra ID and prompting users to set one up when they sign in. On 1 February 2027, delivery of SMS and phone call codes will stop. Anyone who has not registered another method by then will not get any further – at that point the prompt can no longer be dismissed.

By Dipl.-Ing. Mohamed Khater · · 9 min read

What changes – and what explicitly does not

Two methods are affected: the code by text message and the automated voice call. Microsoft has delivered both itself up to now, without a company having to set anything up for it. It is exactly this delivery that is ending.

The Microsoft Authenticator app is not affected. This is the point that raises the most questions: if you use the app with approval or number matching, you do not need to do anything. Other methods such as FIDO2 security keys or Windows Hello for Business also remain unchanged. This is solely about phone calls and SMS.

If you still need SMS or voice calls – for example because a regulator requires it, or because staff do not have a suitable device – you can continue them via your own telecommunications provider. You book one through the Microsoft Security Store, and it costs money. Previously, delivery was included in the subscription.

Four dates

The timeline at a glance

There are ten months between the first and the last date. The decisive one is the third.

1 Sept 2026Passkeys become the default. Users with SMS or voice call are prompted to set up a passkey when they sign in.The prompt can be dismissed. It can be switched off temporarily – but that only postpones the time pressure.
18 Sept 2026Microsoft publishes in the Security Store which telecommunications providers are available and what they cost.Only relevant if you need SMS beyond February 2027.
30 Oct 2026Your own provider can be set up and tested.Microsoft recommends completing this at least four weeks before the cut-off date.
1 Feb 2027Microsoft stops its own delivery of SMS and voice calls.Anyone who has only SMS or voice call registered must set up a passkey when signing in. This prompt blocks – it can no longer be dismissed.

An exception that is easily overlooked

For <b>global administrators and external users</b>, delivery does not end in February but only on <b>1 July 2027</b>. That sounds like a relief, but it is a trap: if the administrator accounts of all things keep working with SMS for months, testing will not reveal that it stopped long ago for everyone else. Internal guest accounts, incidentally, fall under the February date, not the July date.

Context

SMS, Authenticator, passkey – where the difference lies

All three are a second factor. They differ in what an attacker has to do to get around them.

SMS and voice call

The code is read out or sent as a message. An attacker who lures the victim to a fake sign-in page gets the code typed in there and uses it straight away. On top of that there is SIM swapping at the mobile provider.

  • Ends on 1 February 2027
  • No protection against fake pages

Microsoft Authenticator

Approval in the app, often with number matching. Considerably better than SMS, because no code travels over the mobile network. It can still be circumvented, though: anyone who lands on a fake page approves the attacker's request in good faith.

  • Remains in place, no action needed
  • Switch on number matching if it is not active

Passkey

The key is stored on the device and is only released to the genuine address. A fake page simply does not get it – not because the user is paying attention, but because the address does not match. It is unlocked with a fingerprint, face or PIN.

  • New default at Microsoft
  • No password, cannot be phished

Clarify before the switch

Six points where things get stuck in practice

The technology is the easy part. It gets laborious with the people who do not fit the standard picture – and every business has them.

  • Where is the passkey stored? On the phone, on the computer or in a password manager such as Bitwarden or 1Password. This decision belongs before the rollout, not after it: a passkey that exists on only one device is gone if that device is lost.
  • Who has no suitable device at all? Staff in production, warehousing or care often have no work phone, and you cannot assume they will use a private one. For them, FIDO2 security keys on a key ring are usually the more practical solution.
  • What happens if a device is lost? Everyone needs at least two methods. Anyone with only one passkey on one phone who loses the phone faces the same lockout as before with SMS.
  • Shared accounts. A passkey belongs to one person and one device. Accounts shared by several people – reception, shift supervisors, shared mailboxes – do not work cleanly with it. The right answer is personal accounts with permission to access the shared mailbox.
  • Password reset. In many businesses it runs via the same phone number. If SMS goes away, this route has to be rearranged as well – otherwise the problem just moves elsewhere.
  • Older programs and devices. Multifunction printers with scan-to-email, time recording, inventory management: anything that signs in with a user account should be listed beforehand. Such sign-ins usually use other methods, but you should know about them.

Four months left

What to do now

In this order. The first step takes ten minutes and determines how much effort the rest will be.

  1. Count who is affected at all

    In the Entra admin centre you can report on which users have SMS or voice call registered as a method. In many businesses the number is smaller than feared – anyone who already works with the Authenticator app is not affected. Only this list tells you whether it will be an afternoon's work or a project.

  2. Decide: passkeys or your own provider

    For the vast majority of small and medium-sized businesses, passkeys are the right route – they are more secure and cost nothing extra. Your own telecommunications provider is only worth it if an external requirement explicitly demands SMS, or if some of your staff cannot provide a device.

  3. Decide where passkeys are stored and choose a fallback method

    Before the first user sets anything up, it must be clear where the passkey is stored and what the second route is if the device is not available. Without these two answers you end up with a muddle that is tedious to clear up later.

  4. Start with a small group

    Five to ten people from different departments, deliberately including someone who is not particularly technically minded. The questions that come up there will later come from everyone – only then all on the same day.

  5. Prepare your staff before the prompt appears

    The message appears in the middle of signing in. Anyone who does not know what it is will dismiss it or call for help. A short message in advance – what is coming, why, what to do – saves most of the questions.

  6. Count again in January

    One month before the cut-off date, run the same report as in step one. Anyone still on the list is approached individually. Otherwise, it is these last few per cent who will all call at the same time on 1 February.

Tool

Checklist for the switch

To tick off and print. The points are ordered so that the decisions come before the technology – in reverse order it gets expensive.

Your entries stay in this browser window. Nothing is stored and nothing is transmitted.

Take stock

Without these figures, the effort cannot be estimated.

Make decisions

These four questions need to be answered before the first passkey is set up.

Roll out

First in a small group, then across the board.

Follow up

The part you plan to do and then forget.

Nothing ticked yet.

Frequently asked questions

What we are often asked about this

We use the Authenticator app. Do we have to switch now?

No. The Authenticator app is not affected by the shutdown; it continues to work as before. Only the code by text message and the automated voice call are affected.

Your staff may still see the prompt to set up a passkey – it appears for everyone who is still enabled for SMS or voice call, even if they no longer use that method. In that case it is enough to remove the old registration.

Can we postpone the switch?

Until 1 February 2027, yes. For the period from September 2026 to February 2027, Microsoft offers a temporary opt-out from the automatic enablement – an administrator has to set this up explicitly.

Beyond February it does not help. From then on the shutdown applies to everyone, and the prompt at sign-in can no longer be dismissed. Postponing moves the effort from September to January; it does not save it.

What does it cost to keep using SMS?

That depends on the provider you book through the Microsoft Security Store. The prices have been listed there since 18 September 2026. What is new above all is that it costs anything at all – until now, delivery was included in the subscription.

For most small and medium-sized businesses it is not worth it. It makes sense if an external requirement explicitly demands SMS, or if a larger part of your staff has no suitable device.

An employee loses their phone. Can they still get in?

Only if a second method is registered. This is exactly where switchovers fail: anyone with a single passkey on a single device faces the same lockout when it is lost as someone without phone reception did before.

That is why we always set up two routes – for example a passkey on the phone plus a security key or a passkey in the password manager. That includes a named person in the company who is authorised to reset access.

Are passkeys really more secure, or is that marketing?

The difference is technical, not a matter of degree. A passkey is only released to the address it was created for. A fake sign-in page at a similar address does not get it – regardless of how convincing it looks and how inattentive the user happens to be.

With SMS, and also with approval in the app, protection depends on the person recognising the fake. That assumption no longer holds now that sign-in pages can be copied in minutes.

What about accounts that several people use?

They are the most awkward part. A passkey belongs to one person and one device; an account shared by reception and shift supervisors does not fit that picture.

The clean solution is a different one anyway: personal accounts that are given permission to access the shared mailbox. That is more work than a shared account, but it solves several problems at once – including the question of who actually sent what.

Dipl.-Ing. Mohamed Khater

Dipl.-Ing. Mohamed Khater founded INFONET Computer GmbH in Cologne in 1992. The experience from switchovers like this is always the same: the technology is done in an afternoon; the people without a work phone need three weeks' lead time.

Further reading

Free analysis

How many of your accounts still depend on SMS?

We analyse your Microsoft environment and tell you how many users are affected, who has no suitable device and what the switch means for you. You get the result in writing – even if you do nothing further with us afterwards.

+49 221 984300-0Switchboard and support hotline

[email protected]Reply within 4 hours on working days

Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen

Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement