Microsoft is making important changes to how users protect their Microsoft 365 accounts with multi-factor authentication (MFA). If you currently use a text message or phone call to verify your identity, now is the time to switch to a more secure method.
From 1st September 2026, passkeys will become the default sign-in experience for Microsoft 365 users. Those currently using SMS or voice-call MFA will be prompted to register a passkey when signing in, although these early prompts can initially be skipped.
The bigger change comes on 1st February 2027, when Microsoft retires its own SMS and voice-call MFA service. Anyone relying solely on these methods will then have to register a passkey before they can continue signing in.
Who needs to act?
The changes specifically affect users who currently rely on SMS or voice calls for Microsoft 365 MFA. If you already use Microsoft Authenticator, another authenticator app, a passkey or a hardware security key, no action is required.
Microsoft is making the change because SMS and voice authentication are more vulnerable to interception, redirection and social-engineering scams. Passkeys provide stronger, phishing-resistant protection and can also make signing in quicker and easier.
What should you do?
Check your current sign-in methods at mysignins.microsoft.com/security-info. If you’re still using text messages or calls, set up Microsoft Authenticator or a passkey before the February 2027 deadline.
For most organisations, the transition is straightforward and comes at no additional cost. Getting users set up early also gives businesses time to deal with forgotten passwords, lost devices and employees who may need support.
Contact us for more information.