Person holding smartphone with authentication notification on screen
Guide

Microsoft Is Removing SMS MFA: What Australian Businesses Need to Do

CX
CX IT Services
·

Microsoft is retiring SMS and voice-based multi-factor authentication from Entra ID. Here is the official timeline, what it means for your business, and exactly how to move your team to stronger authentication before the deadline.

The short version: Microsoft is phasing out SMS and voice calls as built-in MFA methods in Entra ID (formerly Azure AD). Passkeys become the default sign-in experience from September 2026, and Microsoft will stop delivering SMS/voice codes entirely by February 2027. If your team still relies on text message codes to log in, you need to start migrating now.


What Is Happening

Microsoft has announced two major changes to how multi-factor authentication works in Microsoft 365 and Entra ID:

  1. Passkeys become the default MFA method. Starting 1 September 2026, passkeys will be automatically enabled as the default authentication experience for all users who currently use SMS or voice-based MFA.

  2. Microsoft stops providing SMS and voice delivery. From 1 February 2027, Microsoft will no longer operate the telecom infrastructure that sends those text message codes and voice calls. The built-in SMS/voice MFA you have been using simply will not work anymore unless you configure a third-party telecom provider through the Microsoft Security Store.

This is not a soft deprecation or a future consideration. These are hard deadlines with automatic changes.


The Official Timeline

DateWhat Happens
NowNew Entra ID tenants already default to passkeys. Existing tenants can begin migration.
1 September 2026Passkeys become the default sign-in experience. Users currently on SMS or voice will be automatically enrolled in passkeys.
18 September 2026Microsoft publishes details on customer-managed telecom provider options for organisations that still need SMS/voice.
1 February 2027Microsoft-provided SMS and voice delivery is fully retired. Organisations that have not migrated or configured a customer-managed telecom provider will lose SMS/voice MFA entirely.

Why Microsoft Is Doing This

SMS-based MFA has been considered insecure for years. Here is why:

SIM swapping and cloning. Attackers can convince a mobile carrier to port your phone number to a new SIM card. Once they have it, they receive your MFA codes. This is a well-documented attack that has been used against high-profile targets and everyday business accounts alike.

SMS interception. Text messages are transmitted unencrypted over the SS7 signalling network. Anyone with access to that network (and it is more accessible than you would think) can intercept SMS messages in transit.

Phishing. An attacker sends a convincing login page, the user enters their password and their SMS code, and the attacker uses both in real time to access the account. SMS does nothing to prevent this because the code works regardless of which site it was entered on.

Delivery failures. SMS messages can be delayed, never arrive, or be blocked by carriers. This creates both security gaps and frustrated users who cannot log in.

No device binding. An SMS code proves someone has access to a phone number, not that they are physically holding a specific trusted device. Passkeys and authenticator apps are bound to the actual device.

Microsoft’s own data shows that phishing-resistant methods like passkeys block virtually all automated account attacks, while SMS-based MFA can still be defeated by motivated attackers.


What This Means for Your Business

If your team uses the Microsoft Authenticator app

You are already in a good position. The Microsoft Authenticator app is not being retired. It supports push notifications, number matching, and passkeys. Your users can continue using it, though Microsoft recommends enabling passkeys within the app for the strongest protection.

If your team uses SMS codes (text messages) to log in

This is the group that needs to act. Your users will be automatically migrated to passkeys on 1 September 2026. If you do not prepare them for this change, they will be confused and locked out.

If you have users on basic phones without smartphones

This is the hardest scenario. SMS was the fallback for users who could not install an authenticator app. You will need to either provide them with a smartphone or a physical security key (like a YubiKey), or configure a customer-managed telecom provider to keep SMS working after February 2027.

If you use Conditional Access Policies

Review any policies that specifically reference SMS or voice as allowed authentication methods. These will need to be updated to include passkeys and/or the Microsoft Authenticator app.


What You Need to Do

Step 1: Find out who is still using SMS

In the Microsoft Entra admin centre, navigate to Protection > Authentication methods > Activity to see which users are registered for which MFA methods. Identify everyone still relying on SMS or voice.

Step 2: Communicate the change to your team

Do not let this catch people off guard. Tell your staff that the way they log in is changing, explain why (stronger security, industry standard), and give them clear instructions for setting up the new method.

Step 3: Roll out passkeys or the Authenticator app

For most businesses, the simplest path is:

  • Microsoft Authenticator app on smartphones (supports passkeys, push notifications, and number matching)
  • Physical security keys (YubiKey, Feitian, etc.) for users without smartphones or for high-security roles

Both are phishing-resistant and satisfy Microsoft’s new requirements.

Step 4: Enable passkeys in your Entra ID tenant

In the Entra admin centre:

  1. Go to Protection > Authentication methods > Policies
  2. Enable Passkey (FIDO2) or Microsoft Authenticator (with passkey support)
  3. Assign to all users or start with a pilot group

Step 5: Update Conditional Access Policies

If you have Conditional Access Policies that specify allowed authentication strengths, make sure they include passkeys. Microsoft provides a built-in “Phishing-resistant MFA” authentication strength you can reference.

Step 6: Remove SMS as a registered method

Once users have enrolled in a stronger method, remove SMS/voice from their registered authentication methods so there is no fallback to the weaker option.


What Are Passkeys, Exactly?

A passkey is a cryptographic credential stored on a device (your phone, your laptop, or a physical security key). When you sign in, the device proves it holds the passkey using public-key cryptography. No code is sent, no code can be intercepted, and the credential only works on the legitimate Microsoft sign-in page.

For the user, it looks like this: you go to sign in, your phone or laptop prompts you with a fingerprint scan, face scan, or PIN, and you are in. No waiting for a text message, no typing a six-digit code.

Passkeys are:

  • Phishing-resistant - they only work on the real sign-in page, not a lookalike
  • Device-bound - they cannot be copied or intercepted over a network
  • Faster - most users find them quicker than waiting for an SMS code
  • Supported everywhere - Windows, macOS, iOS, Android, and all modern browsers

Frequently Asked Questions

Will this affect my Microsoft 365 login?

Yes. If your organisation uses Microsoft 365 with Entra ID (which is the standard), this change applies to you.

Is the Microsoft Authenticator app going away?

No. The Authenticator app is not being retired. In fact, it is one of the recommended replacements for SMS. Microsoft is adding passkey support directly into the Authenticator app.

What if some of my staff do not have smartphones?

You can provide physical security keys (USB devices that plug into a computer). YubiKeys and similar devices cost around $40-80 AUD each and work as a passkey.

Can I keep using SMS if I set up my own telecom provider?

Yes, but only after Microsoft publishes the customer-managed telecom provider details (expected 18 September 2026). You would need to configure and pay for a third-party provider through the Microsoft Security Store. This is more complex and more expensive than simply migrating to passkeys.

What happens if I do nothing?

On 1 September 2026, your users on SMS/voice will be automatically enabled for passkeys. On 1 February 2027, SMS/voice codes from Microsoft will stop working entirely. Users who have not set up an alternative method will be locked out.

Does this affect MFA for non-Microsoft apps?

Only if those apps use Entra ID (Azure AD) for sign-in. If you use SMS MFA with other services (banking, accounting software, etc.), those are managed separately by each provider.

How long does it take to migrate a team?

For a typical small business (5-50 people), the technical setup takes under an hour. Each user needs about five minutes to register their new authentication method. The main time investment is communication and scheduling.


Need Help Migrating?

If you are a CX IT Services client, your named account manager can coordinate the migration for your entire team. We will audit your current MFA setup, identify who needs to transition, handle the technical configuration, and guide each user through the enrolment process.

If you are not yet a client but want expert help with this transition, book a clarity call and we will walk through what needs to happen for your specific setup.

#mfa #microsoft-365 #security #entra-id #passkeys #smb
Free Right Fit Call

Want a Professional Assessment?

Book a free 15-minute Right Fit Call. We'll review your current IT setup and tell you honestly where the gaps are.

  • No lock-in contracts - ever
  • Valued at $250 - completely free
  • 4.5-star Google rated
  • Answer in 60 seconds or less
CX IT Services team

See If You Qualify

Takes 2 minutes · Spots strictly limited

  • Free IT environment review
  • Straight answer - right fit or not
  • No sales pitch, no obligation
Apply Now