Microsoft reportedly plans to phase out SMS and voice authentication for Microsoft Entra ID users, pushing organizations toward passkeys and other phishing-resistant sign-in methods.
According to an administrator notice first reported by Windows Latest, affected users will have to register a passkey before Microsoft disables the phone-based authentication methods.
“We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication,” the reported notice states.
Microsoft said SMS and voice authentication provide weaker protection against cyber threats such as phishing, SIM-swapping, and replay attacks. AI-assisted social engineering adds to that risk by helping attackers create more convincing campaigns designed to steal credentials and one-time codes.

More Microsoft news
- Inside Microsoft’s Real-Time War Against Cybersecurity Threats
- Project Ire: Microsoft Tests AI That Autonomously Detects Malware
- Microsoft Targets ‘Critical AI Talent’ from Meta to Dominate Next AI Breakthroughs
- Windows 10 Support Ends Soon, Though Extended Security Updates Offers Are Available
Deadlines for enterprise and consumers
Microsoft has laid out a strict, mandatory timetable for its corporate Entra ID platform:
- Sept. 1: Users logging in with voice or SMS credentials will be required to register a passkey during sign-in.
- Feb. 1, 2027: Microsoft will permanently terminate SMS and voice verification across all Entra ID accounts.
“There is no opt out from this enforcement; it applies to all tenants,” the reported notice states.
Everyday consumers will eventually face the same reality. Microsoft confirmed in support documentation spotted by Windows Latest that it is phasing out text verification and account recovery across personal Microsoft accounts, which power Windows 11, Xbox, and Outlook. While Microsoft has not set a formal cut-off date for home users, the company declared that “the future of authentication is passwordless, secure, and user-friendly,” Windows Latest reported.
The passwordless transition friction
Forcing an entire corporate ecosystem off SMS solves a glaring security loophole, but it introduces immediate operational friction. The universal appeal of the text message was its absolute convenience: virtually every mobile device, regardless of age or operating system, can receive an SMS without user configuration.
Passkeys rely on device-level biometric hardware and modern authenticator apps. Organizations must now navigate the logistics of onboarding non-technical staff and supporting workers on older hardware or restrictive bring-your-own-device policies.
Moreover, because text codes have long functioned as the default safety net for forgotten credentials, locking out SMS account recovery creates a higher risk of permanent account lockouts if a user loses access to their primary authentication device. Companies and individual users alike should audit their recovery options and establish passkeys before Microsoft pulls the safety cord entirely.
Read more: Bitwarden’s passkey support for Windows 11 gives Microsoft Entra ID users a phishing-resistant alternative to traditional login credentials.