Pro User
Timespan
explore our new search
Entra Ends SMS & Voice MFA: What Now
Microsoft Entra
Aug 27, 2026 10:49 PM

Entra Ends SMS & Voice MFA: What Now

by HubSite 365 about Nick Ross [MVP] (T-Minus365)

Entra ends SMS and voice MFA; Microsoft Authenticator, passkeys and SSPR tips for MSPs and IT teams to migrate smoothly

Key insights

  • Passkeys by default
    Microsoft will automatically enable passkeys for users currently on SMS/voice starting September 1, 2026, and will retire Microsoft‑provided SMS/voice delivery on February 1, 2027.
    After retirement, tenants must use a customer‑managed telecom provider if they need phone‑based MFA.
  • Phishing‑resistant methods
    Entra shifts the default to stronger options: passkeys, Windows Hello for Business, and FIDO2 security keys, with Microsoft Authenticator where allowed.
    These methods reduce risks like SIM swap and interception compared with SMS or voice codes.
  • Authentication Methods Policy
    Manage authentication centrally via the Authentication Methods Policy rather than legacy MFA settings to control passkey rollout and method availability.
    Note: SSPR or legacy settings can still allow SMS in some cases, so verify configurations to avoid surprises.
  • Inventory and migration plan
    Identify users still registered for or relying on SMS/voice, then run controlled registration campaigns to move them to phishing‑resistant methods.
    Create staged communication and verification steps to limit disruption and document the process as a repeatable migration project.
  • Blocking passkey prompt
    Users whose only MFA method is SMS or voice will face a blocking prompt to register a passkey before signing in after the change; Microsoft provides no opt‑out for that flow post‑retirement.
    Prioritize these users in your migration to prevent access interruptions.
  • Customer‑managed telecom option
    If your tenant must keep phone delivery after February 1, 2027, integrate a supported telecom provider from the Microsoft Security Store to continue phone‑based MFA.
    Otherwise, plan to complete migration to passkeys or other phishing‑resistant factors before the retirement date.

Overview of the change

Overview of the change

In a recent webinar, Nick Ross [MVP] (T-Minus365) explained how Microsoft is shifting authentication in Entra away from SMS and voice and toward stronger, phishing-resistant options such as passkeys. Consequently, administrators and managed service providers should treat this as a planned, enforced change rather than an optional recommendation. Ross laid out clear timelines and practical implications so IT teams can prepare without surprises.

First, Microsoft will automatically enable passkeys for users relying on phone-based methods starting on September 1, 2026, and then fully retire its built-in SMS and voice delivery on February 1, 2027. After the retirement date, tenants that must keep phone-based delivery will need a customer-managed telecom provider from the Microsoft store to continue using phone factors. Therefore, organizations that do not act will see native phone factors stop working and should expect enforced registration flows for stronger methods.

Technical and administrative details

Ross emphasized that this change affects both MFA and SSPR flows in Entra, and that some legacy settings can make migration trickier than administrators expect. Notably, certain SSPR configurations can still allow SMS even when legacy MFA options appear disabled, which raises the risk of surprise exceptions during rollout. As a result, teams must audit both modern and legacy configurations to find users who remain reachable only by phone.

Moreover, the forced behavior includes a blocking prompt for users whose only recovery or authentication method is SMS or voice, requiring them to register a passkey to continue signing in. To manage this more gracefully, Microsoft offers the Authentication Methods Policy and registration campaign controls that can stage adoption. Administrators should also evaluate alternatives such as the Microsoft Authenticator, device-bound or synced passkeys, and FIDO2 security keys depending on user devices and security needs.

Tradeoffs and practical challenges

On one hand, moving to passkeys and other phishing-resistant methods significantly improves protection against interception and SIM swap attacks, and thus reduces account compromise. On the other hand, this shift introduces user friction during the transition and may increase short-term support volume, especially for users with older phones, limited device capabilities, or poor connectivity. Therefore, IT teams must balance the immediate operational cost of migration against the long-term security gains.

In addition, relying on a third-party telecom integration after retirement brings new operational and cost tradeoffs, because a customer-managed telecom provider requires procurement, regional compatibility checks, and ongoing management. Likewise, regulatory or accessibility requirements in certain regions might limit how quickly an organization can remove phone-based fallbacks. Consequently, decision makers should consider phased approaches and exceptions for high-risk or constrained user populations.

Recommended migration steps

Ross recommends that administrators begin with a thorough inventory to identify accounts still registered for or relying on SMS and voice, and to check for unexpected re-enabling of phone factors via SSPR settings. Next, organizations should centralize control in the Authentication Methods Policy rather than continue to rely on legacy MFA settings, because the modern policy enables clearer rollout controls. In practice, this inventory-driven approach helps prioritize pilots and preserves access for users who need time to transition.

Then, pilot deployments and registration campaigns help reduce disruption by prompting users to adopt passkeys or alternative phishing-resistant methods in a measured fashion. Ross explains how administrators can delay or temporarily opt out of the automatic passkey enablement for controlled groups, while preparing broader adoption for the September 2026 milestone. Finally, teams should document an exception process and determine whether any group needs a telecom integration after the February 2027 retirement.

What IT teams should expect

Expect a phased program that combines technical changes with a communication plan, because the most successful migrations balance security, usability, and timing. In particular, help desks should prepare for an initial surge of support requests, and communication templates can reduce confusion by offering clear steps for end users; the original webinar included template examples and resources to support that work. Over time, however, the shift to phishing-resistant factors should lower incident rates and credential-based risk.

In short, Nick Ross’s guidance frames this as a manageable project rather than a sudden emergency: start with discovery, pilot carefully, and use registration campaigns to limit disruption while meeting Microsoft’s timeline. Ultimately, organizations that plan now will gain stronger protection and avoid last-minute scramble when native phone delivery ends. Therefore, IT teams should inventory their tenants, run targeted pilots, and prepare communications so the transition is secure and user-friendly.

Microsoft Entra - Entra Ends SMS & Voice MFA: What Now

Keywords

Microsoft Entra MFA migration, Entra SMS and voice deprecation, Alternatives to SMS MFA, Entra passwordless authentication, Configure FIDO2 Entra, Entra conditional access MFA settings, How to replace SMS MFA, Secure accounts without SMS MFA