Key takeaway: Microsoft is retiring Microsoft-provided SMS and voice one-time passcodes from Entra ID on February 1, 2027. Starting September 1, 2026, every user still relying on SMS is being nudged to register a passkey at sign-in. Admins have until February 2027 to complete migration before enrollment becomes mandatory at login. The right path for most organizations is passkeys in the Microsoft Authenticator app or FIDO2 hardware keys — both are available today.
In This Article
The Retirement Timeline
Microsoft announced the retirement of Microsoft-provided SMS and voice authentication via Message Center notification MC1426371. The rollout is structured in two phases, with passkeys replacing both channels:
- Sep 1, 2026 Passkeys become the default. Every user with SMS or voice enabled is automatically enabled for passkeys. On their next MFA sign-in they see a prompt to register a passkey. Users can dismiss the prompt, but it returns on subsequent sign-ins. The Registration Campaign begins running automatically.
- Sep–Jan 2027 Opt-out window. Admins can use a temporary opt-out setting to pause the automatic Registration Campaign nudge for users, allowing a phased, admin-controlled migration. This opt-out must be applied via the Authentication Methods API. It expires on February 1, 2027.
- Feb 1, 2027 Microsoft-provided SMS and voice retire. Users whose only registered MFA method is SMS or voice will be required to register a passkey before completing sign-in. The opt-out no longer applies. Existing MFA registrations that include a passkey or other modern method are unaffected.
What "Microsoft-provided" means: This retirement affects SMS and voice codes sent by Microsoft's own authentication infrastructure. It does not affect third-party telephony-based MFA if you have purchased a telecom provider through the Microsoft Security Store. However, the recommended migration path is passkeys, not a third-party SMS replacement.
The practical implication for admins: you are in the execution window right now. Users are already seeing passkey prompts as of September 1. Running an admin-controlled migration before the February deadline avoids a last-minute rush and a poor user experience for the cohort that waits until forced enrollment.
Why SMS MFA Is Going Away
SMS one-time passcodes have been a widely deployed second factor for years, but the security community has recognized three structural problems with them that cannot be patched at the application level.
SIM Swapping
A SIM swap attack occurs when an attacker convinces a mobile carrier to transfer a victim's phone number to a SIM card they control. Once they have the number, all SMS messages — including MFA codes — are delivered to the attacker. SIM swap attacks have been used to compromise corporate Microsoft 365 accounts, cryptocurrency wallets, and bank accounts. Carriers have improved fraud controls, but social engineering remains effective against customer service teams. SMS OTP offers no defense against a successful SIM swap.
SS7 Protocol Vulnerabilities
The Signaling System 7 (SS7) protocol that routes SMS messages across telecom networks was designed in 1975 with no authentication mechanisms. Known vulnerabilities allow actors with access to the SS7 network — telecom insiders, foreign state actors, or operators of rogue carrier equipment — to intercept SMS messages in transit. These attacks do not require the attacker to interact with the victim's carrier at all. Researchers and national security agencies have documented SS7 interception of MFA codes as a real-world attack vector against high-value targets.
Phishing and Real-Time Relay
SMS OTP is vulnerable to real-time phishing because the code itself is a short-lived secret that a user can be tricked into entering into a fake login page. Attacker-in-the-middle toolkits (Evilginx, Modlishka) proxy the real Microsoft sign-in page and can capture both the session cookie and the SMS code before the victim realizes anything is wrong. This attack requires no compromise of the phone itself — just a convincing phishing link and a brief interaction window before the OTP expires.
Passkeys are designed to eliminate all three attack surfaces. They are bound to the specific origin (domain) of the site requesting authentication, so they cannot be replayed on a phishing page. They do not travel over SMS. And the private key never leaves the device, so there is nothing to intercept at the transport layer.
Your Two Main Passkey Options
Microsoft Entra ID supports two categories of passkeys, and the distinction matters for deployment planning: device-bound passkeys on hardware security keys, and synced passkeys in the Microsoft Authenticator app.
| Factor | Synced Passkey (Authenticator App) | Device-Bound Passkey (Hardware Key) |
|---|---|---|
| Where credential lives | Microsoft Authenticator app; syncs across user's devices via the app's cloud sync | On the hardware key; never exported, never leaves the device |
| Device requirement | iOS 6.8.37+ or Android 6.2507.4749+ of Microsoft Authenticator | FIDO2-certified key (YubiKey, Feitian, etc.); USB-A, USB-C, NFC, or Lightning |
| User experience | Biometric or PIN on phone; works even without cell signal once registered | Physical tap or pin entry; requires carrying the key |
| Lost device recovery | Passkey syncs across user's devices; register a backup method in Security info | Spare key or backup auth method required; key cannot be duplicated |
| Best fit | General workforce; most users already have Microsoft Authenticator installed | Admins, privileged accounts, shared workstation environments, high-assurance roles |
| Attestation enforcement | Microsoft can attest that it is the Authenticator app | Manufacturer attestation available; enforce for high-security profiles |
| Cost | No additional hardware cost | ~$25–$70 per key depending on model and connector |
For most organizations migrating off SMS, the Authenticator app passkey is the practical default — users already have the app for push notifications, the upgrade is in-place, and there is no hardware to procure or distribute. Hardware keys are the right choice for privileged accounts, roles that require hardware-bound credentials, and shared workstation scenarios where a personal phone is not an appropriate authentication device.
Microsoft Authenticator push notifications are not passkeys. Number-matching push notifications (the prompt where a user taps a number shown on screen) are stronger than SMS but are still susceptible to push fatigue attacks and are not phishing-resistant by design. They are an acceptable interim method while you complete the passkey migration, but the retirement announcement is specifically about SMS and voice codes, not Authenticator push — registering a passkey is the correct end state.
How to Enable Passkeys in the Entra Admin Center
Passkeys (FIDO2) must be enabled as an authentication method before users can register them. If your tenant has previously configured FIDO2 settings, those settings are automatically migrated into a Default passkey profile — you do not need to reconfigure them from scratch.
Step 1: Enable the Passkey (FIDO2) authentication method
- Sign in to the Microsoft Entra admin center at entra.microsoft.com.
- Navigate to Protection > Authentication methods > Policies.
- Select Passkey (FIDO2) from the method list.
- Set Enable to Yes. Target All users or a specific group to start with a pilot cohort.
- Set Allow self-service setup to Yes so users can register from their Security info page without an admin-generated TAP.
- Click Save.
Step 2: Configure the Default passkey profile
The Default passkey profile controls which types of passkeys are accepted and whether attestation is enforced. In most organizations the default settings are appropriate for general users:
- Allow synced passkeys: Yes — required for Authenticator app passkeys.
- Allow device-bound passkeys: Yes — required for hardware security keys.
- Enforce attestation: No for the default profile (general users); create a separate custom profile for privileged accounts and set Enforce attestation to Yes.
Step 3: Create a custom profile for admin accounts (recommended)
For Global Administrators, Privileged Role Administrators, and other high-privilege roles, create a separate passkey profile with Enforce attestation: Yes and restrict allowed passkey types to device-bound hardware keys only. Target this profile to your privileged admin group. This ensures that the highest-risk accounts cannot register a passkey from an unverified platform.
Conditional Access enforcement requires P1 or P2. Enabling passkeys as an authentication method is available on the Entra ID Free tier. Enforcing a passkey-only sign-in requirement through a Conditional Access policy using authentication strengths requires Microsoft Entra ID P1 or P2. If your tenant is on Free or basic Microsoft 365 licenses, you can still deploy passkeys and use the Registration Campaign to drive adoption, but you cannot enforce passkey-only access via Conditional Access until you have P1/P2 assigned.
Running the Registration Campaign
The Registration Campaign is Microsoft's built-in mechanism for nudging users to register a stronger authentication method. As of September 1, 2026, it is running automatically for tenants with SMS or voice users. In most cases you want to take control of it rather than let it run unmanaged.
What the Registration Campaign does
After a successful MFA sign-in, eligible users see a prompt that says Microsoft recommends setting up a passkey. They can skip it a limited number of times (configurable) before it becomes mandatory to proceed. The campaign tracks completion and will stop showing for users who have already registered a passkey.
Managing the campaign from the admin center
- In the Entra admin center, go to Protection > Authentication methods > Registration campaign.
- Set the State to Enabled to run it for targeted users, or Microsoft managed to let Microsoft control the rollout timing.
- Under Users, add a scoped group to pilot the campaign before enabling it for everyone.
- Set Days allowed to snooze — Microsoft recommends 3. Setting it to 0 makes the prompt mandatory on first appearance.
- Save. The campaign begins showing for users in scope on their next sign-in.
Using the temporary opt-out
If you have a structured internal rollout plan and want to control the pace rather than have Microsoft nudge all SMS users immediately, you can apply the temporary opt-out using the Authentication Methods API or Microsoft Graph. The opt-out setting is scoped per-tenant and prevents the automatic passkey registration nudge from running. You can then enable the Registration Campaign manually for specific groups on your own schedule. This opt-out expires February 1, 2027 — after that date all users still on SMS or voice alone will be forced to register a passkey at next sign-in regardless of the setting.
How Users Register a Passkey
Once passkeys are enabled and the Registration Campaign is running, users can register in two ways: through the prompted sign-in flow, or by going to Security info directly. For admin-managed deployments, directing users to Security info ahead of the campaign gives you more control over timing and reduces sign-in disruption.
Option A: Microsoft Authenticator app passkey (recommended for most users)
- Update the Microsoft Authenticator app. Users on iOS need version 6.8.37 or later; Android users need version 6.2507.4749 or later. Check both the App Store and Google Play for updates before starting the rollout.
- On a desktop or separate device, navigate to mysignins.microsoft.com and sign in.
- Select Security info > Add sign-in method > Passkey in Microsoft Authenticator.
- Complete MFA to authorize the registration session. Microsoft requires MFA completion within the last five minutes before a passkey can be registered.
- Scan the QR code shown on screen with the updated Authenticator app, or follow the cross-device registration flow. The app creates and stores the passkey credential on the device.
- Name the passkey (e.g., "Work iPhone") and save. The passkey now appears in Security info and can be used immediately.
Option B: FIDO2 hardware security key
- Ensure the key is FIDO2-certified. Most current YubiKey models (YubiKey 5 series), Feitian keys, and other vendor keys from the FIDO Alliance certified products list qualify.
- Navigate to mysignins.microsoft.com, sign in, and complete MFA.
- Select Security info > Add sign-in method > Security key.
- Insert or tap the key when prompted. The browser will ask you to set or enter the key's PIN (if it's the first time using it) and then touch the key to confirm the credential registration.
- Name the key and save. Test the sign-in from the same browser session before distributing the key to the user.
Always register a backup method. Whether a user registers an Authenticator app passkey or a hardware key, they should also register a second passkey or a backup modern authentication method in Security info. A lost phone or damaged hardware key with no backup method means an admin-assisted account recovery — multiply that by a large user base and the helpdesk load becomes significant.
Blocking SMS After Migration
Once your users have registered passkeys, the remaining step is to remove SMS and voice as available methods — both to enforce the migration and to close the window where a user or attacker could add SMS back as a fallback.
Disable SMS and voice in Authentication Methods Policy
In Authentication methods > Policies, select SMS and set it to Disabled. Do the same for Voice call. This prevents any user from registering or using these methods going forward. Before disabling, verify that your reporting shows all targeted users have at least one passkey or other non-SMS method registered — disabling SMS before a user has an alternative method will lock them out.
Require phishing-resistant MFA via Conditional Access (P1/P2)
If your tenant has Entra ID P1 or P2, create a Conditional Access policy that enforces an Authentication strength of Phishing-resistant MFA for your targeted users or all users. This strength includes passkeys (FIDO2) and certificate-based authentication, and explicitly excludes SMS OTP, voice, and push notification MFA. With this policy in place, even if a user somehow has SMS enabled, it will not satisfy the MFA requirement at sign-in.
# Check registered auth methods for users still showing SMS
Connect-MgGraph -Scopes "UserAuthenticationMethod.Read.All"
Get-MgUser -All | ForEach-Object {
$methods = Get-MgUserAuthenticationMethod -UserId $_.Id
[PSCustomObject]@{
UPN = $_.UserPrincipalName
Methods = ($methods.AdditionalProperties.Values | Sort-Object) -join ", "
}
} | Where-Object { $_.Methods -like "*phone*" } | Select UPN, Methods
This script reports every user who still has a phone-based authentication method registered (which covers both SMS OTP and voice call). Run it before you disable SMS in the Authentication Methods policy to validate there are no stragglers, and again after to confirm clean state.
Frequently Asked Questions
When is Microsoft retiring SMS and voice MFA?
Microsoft-provided SMS and voice one-time passcodes retire on February 1, 2027. Starting September 1, 2026, users are nudged to register a passkey at each sign-in. From February 1, 2027, users whose only MFA method is SMS or voice will be required to register a passkey before they can sign in.
What replaces SMS MFA in Microsoft 365?
The primary replacements are passkeys in the Microsoft Authenticator app (synced passkeys, available on iOS and Android) and FIDO2 hardware security keys such as YubiKey (device-bound passkeys). Both are phishing-resistant and work without a phone signal once registered. The Microsoft Authenticator app also supports number matching push notifications as a near-term stopgap, but passkeys are the recommended long-term path.
Do passkeys require a paid Entra ID license?
Enabling passkeys (FIDO2) as an authentication method is available on the Entra ID Free tier. Enforcing a passkey-only policy through Conditional Access authentication strengths requires Microsoft Entra ID P1 or P2.
What happens to users who only have SMS MFA registered after February 2027?
Users whose only registered MFA method is SMS or voice will be prompted to register a passkey during their sign-in flow before they can proceed. They will not be permanently locked out, but they cannot bypass the registration step. This makes pre-migration critical — users forced to self-register at sign-in without prior training will have a poor experience, and the helpdesk load during a forced rollout is significant.
Can we delay the passkey Registration Campaign?
Yes. A temporary opt-out is available from September 1, 2026 through February 1, 2027. It lets you postpone the automatic passkey enrollment nudge and Registration Campaign while you run a controlled migration. The opt-out is applied via the Microsoft Graph Authentication Methods API. After February 1, 2027, the opt-out is no longer honored and standard enforcement applies.
Are push notifications from the Microsoft Authenticator app being retired too?
No. This retirement is specifically about Microsoft-provided SMS and voice codes. Authenticator push notifications, number matching, and the TOTP (time-based one-time password) codes in the Authenticator app are not being retired in this announcement. However, none of those methods are phishing-resistant, and passkeys are the security posture Microsoft is pushing organizations toward long-term.
Can users who travel internationally use a passkey?
Yes — this is one of the advantages of passkeys over SMS. The Authenticator app passkey works entirely on-device using biometrics or a PIN. It does not require cell service, an active SIM, or international roaming. Users who previously failed MFA abroad because their SMS code never arrived will have a significantly better experience with a passkey.
Sources
This article was published September 30, 2026 against current Microsoft documentation, including the Entra authentication methods documentation and Message Center notification MC1426371 covering SMS and voice retirement.