Microsoft Is Retiring Text and Phone MFA

Microsoft Is Retiring Text and Phone MFA: What It Means for Your Business

If your team signs into Microsoft 365 using a text message or phone call as your second security step, that’s about to change.

Microsoft has confirmed it is retiring SMS and voice call multi-factor authentication (MFA) across Microsoft Entra ID. The changeover starts sooner than most businesses realise, and there’s no opt-out once it’s complete.

What's actually changing?

From September 2026, Microsoft will begin rolling out passkeys as the default authentication method. Anyone currently using text or phone call MFA will automatically be enabled for passkeys and prompted to register one the next time they sign in.

From February 2027, Microsoft will stop providing SMS and voice authentication itself. Businesses that still need it will have to arrange it separately through a third-party telecom partner, at their own cost. After that point, everyone will be required to register a passkey, with no fallback option.

Full details and the official timeline are available on the Microsoft Security Blog.

Why this matters more than it first appears.

On the surface, this looks like a simple swap: passkeys instead of text codes. In practice, it creates a real problem for a lot of small businesses.

Several parts of Microsoft 365 already require two separate MFA methods to be set up, not just one. Passkeys are typically tied to the device they’re created on. If your team works across a laptop, a phone, and sometimes a tablet, a passkey registered on one device won’t automatically be available on the others.

Without a way to store and sync passkeys properly, staff can end up locked out simply because they’re not sat at the device where their passkey lives. For businesses without a password manager in place, this is likely to cause real disruption once the changes land.

Where a Password Manager fits in.

This is exactly the gap that a password manager is built to close. Tools like 1Password store your passkeys securely and sync them across every device your team uses, so signing in works the same way whether someone’s on their laptop at the office or their phone on the road.

Beyond passkeys, a password manager also removes the everyday habits that cause security problems in the first place, weak passwords, reused logins, and passwords shared over email or messaging apps.

Our advice: don't wait until 2027.

The rollout begins in September 2026, which doesn’t leave much time to get things in order. If your business relies on Microsoft 365 and doesn’t currently use a password manager, now is the time to plan ahead rather than dealing with locked-out staff further down the line.

At Atmosphere IT, we can review your current authentication setup, help you choose and roll out a password manager, and make sure your team is ready well before Microsoft’s deadlines hit.

Get in touch to talk it through.

Share

Recent Posts

Security

The Phishing Trip

A Story For National “Gummy Bear Day” (and “National “Tell a Story Day”)! Benny was a golden gummy bear, and he worked in accounts. Not

Read More »
Outsourced IT in Reading Team members smiling discussing outsourced IT in Reading
Past Vacancies

Second Line Support Technician

About Atmosphere IT We are a leading Microsoft-focused Managed Services Provider (MSP) delivering exceptional IT support and solutions to a wide range of clients. As

Read More »