Microsoft is retiring SMS and voice as multifactor authentication methods in Entra ID. Here are the three dates that matter, the blind spots the announcement does not highlight, and a realistic transition plan.
What Microsoft actually announced on July 13
Message MC1426371, published July 13, 2026 and updated on the 16th, announces two things at once, and that is where the confusion starts. On one side, passkeys become the default authentication method in Microsoft Entra. On the other, Microsoft-provided SMS and voice are being retired as multifactor authentication methods.
Worth clarifying: passkeys are not new. Passkey profiles have been generally available since 2025, and Entra has been auto-enabling them in tenants since March 2026. What changes this time is their default status and, above all, the disappearance of Microsoft-provided telephony. In many organizations, SMS remains the most widely used fallback method. That is exactly the one going away.
Three dates for your calendar
On September 1, 2026, users enabled for SMS or voice, including through legacy per-user MFA settings, are automatically enabled for passkeys and nudged to register one at their next strong authentication. By default, that nudge can be snoozed an unlimited number of times.
On September 18, 2026, third-party telecom providers appear in the Microsoft Security Store, and configuration becomes possible starting October 30, 2026.
On February 1, 2027, Microsoft-provided SMS and voice stop working. No extension is planned for that date.
The blind spots that cost you
The first blind spot hits self-service password reset. The retirement is not limited to strong authentication, it applies across Entra, SSPR included. A user who forgets their password and had only their mobile number as a verification method no longer has a self-serve way out. They call the help desk.
The second involves your external collaborators. If your organization has partners, contractors or agents working inside your tenant, that segment deserves its own plan, because support arrives late.
The third is the most direct: after February 1, 2027, a user whose only registered method was SMS faces a blocking prompt. They do not sign in until they register a new method.
“Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.”
- Microsoft Learn, SMS and voice retirement FAQ
What you are not required to do
The announcement suggests you have to move everyone to passkeys before February. You do not, and that changes your planning. Only Microsoft-provided SMS and voice are being retired. Microsoft Authenticator, app-based one-time codes, OATH hardware tokens, FIDO2 security keys, Windows Hello for Business and certificate-based authentication are not in scope.
Two relief valves also exist. A temporary opt-out, available through Microsoft Graph until February 1, 2027, delays automatic passkey enablement and the registration campaign. It does not delay the deadline, it gives you control of the calendar. And where telephony remains required by a regulatory framework or an out-of-band need, you can configure your own telecom provider.
A four-step transition plan
- By the end of August, take inventory. Export your tenant's authentication methods report and isolate users whose only registered method is SMS or voice. Check break-glass accounts and guest accounts too, which are often overlooked.
- In September, segment. Office staff, frontline staff without a corporate phone, shared workstations, privileged accounts and external users do not share the same target method. For shared workstations, a physical FIDO2 security key solves the problem better than a passkey synced to a personal device.
- From October to December, pilot. Turn on the registration campaign for a volunteer group, measure the real registration rate, then expand. Staff communication is prepared before the nudge appears, not after.
- Before February, build the safety net. A Temporary Access Pass procedure for re-registrations, a documented help desk runbook, and at least two emergency accounts using a strong non-telephony method.
The real milestone is not February, it is September
The February 2027 deadline feels far away. The real milestone is September 1, 2026, the day your users start receiving a prompt they are not expecting. An organization that has communicated nothing by then spends the fall handling help desk calls instead of running a migration.
How io4 helps
We inventory your tenant's authentication methods, produce the named list of users and guest accounts at risk of being locked out, then build the transition plan segment by segment: target method for each one, FIDO2 hardware where it is required, activation sequence. We also take on the registration campaign, staff communication and the help desk runbook. For organizations covered by io4 360 or by our managed Defender XDR SOC, the work folds into the existing review cycle, with no separate project to scope. To frame the transition, talk to an io4 expert.
Want to talk it through?
Let's spend 30 minutes on your situation.
A free assessment with an io4 architect. No commitment, no pressure.
Book my assessment
