Bay Geeks logoTampa Bay IT Support ยท Since 2004

Security & Compliance

Client Advisories

Bay Geeks tracks the security and compliance changes that affect our clients' systems: vendor enforcement deadlines, patch requirements, and anything else worth knowing before it becomes a problem. This page is the central record; check back or subscribe to our newsletter for new bulletins.

Same-day appointments usually available

Security
Bulletin · Posted

Action Required: Microsoft is retiring SMS and voice-call multi-factor authentication for Microsoft 365 / Entra ID accounts on a fixed schedule, in favor of passkeys. Organizations should start migrating now: the enforcement dates below are already public and confirmed.

Microsoft Entra Passkey Enforcement: What's Actually Changing

If your business signs into Microsoft 365 using a text message or phone call for two-factor login, that method is being phased out by Microsoft on a specific timeline. This is not a rumor or a vague "someday" change: Microsoft has published exact dates. Here's what's confirmed, straight from Microsoft's own documentation.

What's Happening

Microsoft Entra ID (the sign-in service behind Microsoft 365) is retiring its built-in SMS and voice-call authentication methods. In their place, Microsoft is pushing passkeys, a phishing-resistant sign-in method tied to a device, biometric, or security key instead of a code sent by text or phone call.

This is a targeted change to one weak multi-factor authentication method, not a removal of passwords generally. If your organization already uses the Microsoft Authenticator app, a hardware key, or another MFA method, this change affects you less directly, but it's still worth reviewing who on your team still relies on SMS or voice codes.

The Confirmed Dates

Now to Aug 2026

Good time to audit which employees still sign in with SMS or voice codes, and start enrolling them in passkeys or the Authenticator app ahead of the deadline.

Sept 1, 2026

Microsoft auto-enables passkeys for any user currently set up for SMS or voice MFA. Those users are prompted to register a passkey the next time they sign in. A temporary opt-out is available from this date through Feb 1, 2027.

Feb 1, 2027

Microsoft retires SMS/voice MFA entirely: no opt-out. Anyone whose only MFA method is a text or phone code is blocked at sign-in until they register a passkey or another supported method.

After February 1, 2027, organizations that still want phone-based MFA can only get it by bringing their own service through a third-party telecom provider; Microsoft will no longer provide SMS/voice codes directly.

How Passkeys Work

A passkey is a cryptographic credential stored on a device (a phone, computer, or security key) instead of a password or a code sent over text. To sign in, a user confirms their identity with a fingerprint, face scan, or device PIN, and the device handles the cryptographic proof behind the scenes. Nothing that can be phished or intercepted ever gets typed or transmitted.

What You Need to Do

For Individual Users

  • Set up a passkey on your Microsoft account or work account before Sept 2026 if you can
  • Register it on at least one trusted device (phone, computer, or security key)
  • Test signing into Microsoft 365 with the passkey before you need it under pressure
  • Keep backup recovery options on file in case you lose the device

For Organizations

  • Audit which employees still authenticate via SMS or voice code
  • Roll out passkey enrollment in waves ahead of the Sept 1, 2026 auto-enable
  • Decide whether to use the temporary opt-out window, and for how long
  • Update internal IT policy and helpdesk documentation before the Feb 1, 2027 cutover

Common Questions

Does this mean passwords are going away entirely?

Not as part of this specific change. This is Microsoft retiring one MFA method (SMS and voice codes) in favor of passkeys. Passwords and other MFA methods (like the Authenticator app) aren't affected by this particular announcement.

What happens if we do nothing before February 1, 2027?

Anyone whose only registered MFA method is SMS or voice will be blocked at sign-in and forced to register a passkey on the spot, with no opt-out and no grace period. Migrating ahead of time avoids that scramble.

Can we keep using text-message codes after the deadline?

Only if you source SMS/voice MFA yourself through a third-party telecom provider. Microsoft will no longer provide it directly after February 1, 2027.

Where can I read Microsoft's official documentation?

Microsoft's own retirement notice and FAQ are published on Microsoft Learn, linked in the Resources section below.

Ready to Get Ahead of This?

Bay Geeks can help your organization prepare for the Microsoft passkey transition:

  • Audit of who's currently on SMS/voice MFA
  • Passkey rollout planning and staged enrollment
  • User training and hands-on setup support
  • Updated IT policy documentation

Contact us: 727-579-4335 or support@baygeeks.com

Resources

Disclaimer: Rollout details can vary by tenant configuration and Microsoft may adjust dates. This bulletin reflects Microsoft's published documentation as of August 2026; verify current details at the Microsoft Learn links above, or contact Bay Geeks for guidance specific to your environment.

Archive

Past Advisories

New bulletins are added here as they're published. Right now there's one active advisory; check back for future updates.

SecurityAugust 2026

Microsoft Entra Passkey Enforcement (SMS/Voice MFA Retirement)

Microsoft is retiring SMS and voice-call MFA for Microsoft 365 accounts in two phases: Sept 1, 2026 and Feb 1, 2027. See what your organization needs to do.

Read Full Advisory →

Questions About This Advisory?

We're Here to Help

Call, open a ticket, or schedule a technician: we'll walk you through what this means for your systems.

Call Now Schedule