Skip to content

Field note

Entra SMS and Voice MFA Retirement: Passkeys

The SMS and voice retirement is not a switch you can leave for later. From 1 September 2026 your SMS and voice users are already being nudged to register passkeys, and from 1 February 2027 the nudge becomes a block.

Published27 Sept 2026

Updatedtoday

Read time5 min. 1,065 words.

Microsoft is retiring Microsoft-provided SMS and voice authentication in Microsoft Entra ID and making passkeys the default sign-in experience. The first stage has already happened. Starting 1 September 2026, passkeys are automatically enabled for users who are enabled for SMS or voice.

The date that matters most for a small business is 1 February 2027. From then, Microsoft-provided SMS and voice delivery is retired for all users except Global Administrators and external users, who follow on 1 July 2027. Users whose only MFA method is SMS or voice will have to register a passkey during sign-in before they can continue.

This is not a lockout, but it is a blocking prompt. If your staff are not ready, the first working day after the deadline will be a help desk day.

Quick answer

  1. Run Microsoft's SMS and voice usage analyser script to find who is still enabled for SMS or voice.
  2. Check that Passkey (FIDO2) is enabled and that your SMS and voice users sit in a passkey-enabled policy.
  3. Let the registration campaign nudge users now, or target it at a specific security group yourself.
  4. Tell staff what is changing, when, and which method they will use.
  5. Only consider a Microsoft Security Store telephony provider if you have a documented regulatory or operational need.
  6. Get Global Administrators onto a phishing-resistant method well before 1 July 2027.

What changed on 1 September 2026

According to Microsoft Learn, on 1 September 2026 users enabled for SMS or voice in the Entra Authentication Methods Policy, or in legacy MFA settings, were auto-enabled for passkeys. Those users are placed into a passkey profile allowing all types of passkeys, and the Registration Campaign is set to a Microsoft managed state targeting passkeys.

In practice, the next time one of those users completes MFA, they are nudged to register a passkey. By default they can snooze that prompt an unlimited number of times. That is why many SMEs will see little movement unless they drive it: people snooze prompts they do not understand.

Microsoft offers a temporary opt-out covering the period from 1 September 2026 to 1 February 2027, set through Microsoft Graph with the passkeyDynamicMigration property. It only delays automatic enablement. There is no opt-out for enforcement, so for most SMEs opting out simply wastes preparation time.

The dates that apply to which users

Microsoft Learn sets out three populations:

  • Most users and internal guest users: Microsoft-provided SMS and voice retires on 1 February 2027.
  • Global Administrators and external users: retirement is on 1 July 2027.
  • Tenants with a telephony provider configured: SMS and voice can continue through that provider, according to your own policies.

After the applicable date, a user whose only available MFA method is SMS or voice must register a passkey during sign-in. Microsoft is explicit that this prompt is blocking. The change also applies to self-service password reset, so check whether any of your users rely on text messages to reset their passwords.

Microsoft says this timeline applies to public cloud environments only, and that Azure AD B2C is out of scope.

Find who is in scope

Microsoft points admins to its entra-sms-voice-usage-analyzer PowerShell script. You need Global Reader, Authentication Policy Administrator or Security Reader to run it. Microsoft's FAQ says any non-zero result means your tenant is in scope.

From that output, build a security group of SMS and voice users. You will use it for the registration campaign and for targeted communications. While you are there, look for shared mailboxes with sign-in enabled, service accounts, and staff who only ever used a landline for voice calls. Those are the accounts that tend to break.

If you are still tidying up how MFA is enforced in the first place, our guide to security defaults, Conditional Access and per-user MFA is a sensible companion read.

Move people to passkeys, not to another weak method

Microsoft supports synced passkeys, stored in a platform credential manager such as iCloud Keychain or Google Password Manager, and device-bound passkeys, such as a passkey in Microsoft Authenticator, a FIDO2 security key or a passkey on Windows.

For most UK SMEs the practical order is:

  1. Staff with a company or personal smartphone: passkey in Microsoft Authenticator.
  2. Staff on managed Windows devices: Windows Hello for Business alongside a phone-based passkey for other devices.
  3. Staff who cannot or will not use a phone: a FIDO2 security key issued by the business.

To push adoption rather than wait, sign in to the Entra admin center as an Authentication Policy Administrator, go to Entra ID, Authentication methods, Registration campaign, set the state to Microsoft Managed and target your SMS and voice group. Our practical passkey rollout guide covers pilot groups, recovery and help desk scripts in more detail.

When a telephony provider makes sense

Microsoft recommends passkeys as the primary migration path. A telephony provider through Microsoft Security Store is intended for organisations with a legitimate business, regulatory or technical need for SMS or voice. Soprano and Telesign are the initial providers in private preview, and Microsoft says the configuration experience becomes available beginning 30 October 2026.

This route has a cost. Microsoft states that pricing varies by provider and region, while migrating users to passkeys incurs no additional cost. For a typical SME, a telephony provider should be an exception for a named group with a written reason, not a way to avoid change.

Communicate before the block, not after

Microsoft recommends a three-stage plan: awareness, action and reminder. Use it. A short email explaining why SMS is going, a one-page guide per device type, and a reminder a few weeks before 1 February 2027 will prevent most of the calls you would otherwise take on the day.

Put Global Administrators on your list separately. They have until 1 July 2027, but admin accounts are the last place you want SMS as the only second factor.

Source basis

Related notes

Need help mapping this to your own tenant, controls, or assessment timeline?