Microsoft has issued a clear notice to enterprise IT administrators, urging them to accelerate the transition away from legacy two-factor authentication methods and adopt phishing-resistant passkeys. As part of a major security overhaul across its identity infrastructure, the tech giant announced plans to phase out native short message service (SMS) and voice-based multi-factor authentication (MFA) within Microsoft Entra ID.

The strategic shift aims to protect corporate networks against increasingly sophisticated identity-based cyber threats, including AI-driven social engineering campaigns, man-in-the-middle attacks, and SIM-swapping fraud. By replacing telecommunications-based verification codes with modern cryptographic credentials, Microsoft is positioning passkeys as the foundation of modern identity architecture.

Microsoft Urges IT Admins to Abandon SMS and Voice 2FA

For over a decade, SMS text messages and automated phone calls served as the primary second factor for millions of enterprise users. While phone-based verification provided a necessary upgrade over simple static passwords, security experts have long warned that telecommunications channels were never designed for secure data transmission.

In official communication sent to Microsoft Entra ID administrators, the company highlighted the severe vulnerabilities inherent in phone-based verification. Standard SMS relies on shared secrets sent over unencrypted cellular protocols, leaving one-time passcodes susceptible to interception. Threat actors frequently manipulate mobile carriers through SIM-swapping techniques or use automated phishing kits to capture text codes in real time.

To eliminate these systemic risks, Microsoft is formally moving passkeys to the forefront. Built on the Fast Identity Online (FIDO2) and World Wide Web Consortium (W3C) standards, passkeys utilize public-key cryptography to authenticate users. Because authentication is tied directly to the website or application domain, passkeys cannot be phished or intercepted through standard social engineering methods.

Rising Threat of AI-Driven Phishing and SIM Swapping

The urgency behind Microsoft's decision stems largely from the rapid evolution of artificial intelligence in the cyber threat landscape. Threat actors are leveraging generative AI tools to execute highly convincing, automated phishing campaigns at unprecedented scales. Microsoft Threat Intelligence reports indicate that AI-enhanced lure messages achieve significantly higher interaction rates compared to traditional spam campaigns.

Furthermore, social engineering tactics targeting customer support representatives at mobile network operators have simplified SIM swapping. Once an attacker successfully transfers a target's phone number to a rogue SIM card, all incoming SMS authentication codes are immediately diverted to the adversary. This structural weakness makes traditional phone-based MFA increasingly ineffective against motivated state-sponsored and cybercrime entities.

Timeline for Blocking SMS Authentication in Entra ID

To give enterprise customers adequate time to adapt their identity policies, Microsoft has outlined a structured rollout timeline leading up to the final native SMS authentication block in Entra ID.

Beginning September 1, 2026, passkeys will automatically become the default authentication experience across Microsoft Entra ID tenants. Users currently configured for SMS or voice verification will be automatically enabled for passkey functionality. During subsequent sign-in attempts, these users will receive registration prompts encouraging them to set up a passkey on their device.

The critical enforcement date arrives on February 1, 2027, when Microsoft fully retires native SMS and voice delivery. After this deadline, Entra ID will no longer send text messages or place phone calls for authentication. Users who have not migrated to an approved alternative will encounter a mandatory registration wall requiring them to enroll a passkey or another phishing-resistant credential before gaining access to corporate resources.

Transitioning Users to Phishing-Resistant Passkeys

For organizations with unique compliance mandates or legacy operational requirements that necessitate ongoing telephony support, Microsoft will offer an alternative route. Starting in late 2026, administrators can integrate third-party telecom providers through the Microsoft Security Store. However, organizations choosing this path must contract directly with external carriers and assume all associated operational and financial expenses, as native support within Microsoft Entra ID will cease entirely.

Beyond security enhancements, Microsoft emphasizes that transitioning to passkeys offers substantial operational benefits. Internal benchmark metrics show that signing in with a passkey takes a fraction of the time required for traditional password and SMS workflows, drastically improving user productivity while eliminating costs related to telecom message delivery.

Security Recommendations for Enterprise Administrators

Cybersecurity experts recommend that IT administrators begin preparing their environments immediately rather than waiting for automated prompts. Transitioning an enterprise user base involves identity policy reviews, device readiness audits, and internal user education.

Key recommendations for system administrators include:

  • Audit Current MFA Usage: Run Microsoft Entra ID sign-in reports to identify all active users and groups relying on SMS or voice verification.
  • Configure Passkey Policies: Update authentication method policies in the Entra admin center to enable passkeys (FIDO2) for target user groups.
  • Determine Hardware Requirements: Decide whether your security posture requires hardware-bound FIDO2 security keys or allows device-synced platform passkeys.
  • Update Identity Recovery Workflows: Review self-service password reset (SSPR) procedures to ensure account recovery mechanisms do not rely on deprecated phone channels.
  • Launch User Training Campaigns: Provide employees with clear guidance on how to register and sign in using biometrics, Windows Hello for Business, or security keys.

The impending retirement of native phone authentication marks a major milestone in the multi-year industry movement toward a passwordless web. By systematically blocking SMS authentication in Microsoft Entra ID and establishing passkeys as the default identity standard, Microsoft aims to significantly reduce account takeover attacks across the global enterprise ecosystem. Administrators are urged to initiate their migration roadmaps now to avoid sign-in disruptions as enforcement deadlines approach.