Cyber Security ChecklistsChecklist and Guide

Microsoft SMS and Voice MFA Retirement Checklist

8 minutes to completeEvergreen guide — kept up to date

Microsoft-provided SMS and voice authentication in Microsoft Entra ID retires on 1 February 2027. From 1 September 2026, affected users will begin receiving passkey registration prompts. This checklist covers the discovery, policy, pilot, communication, monitoring and closure steps a business should complete before the deadline.

What is retiring and when?

  • 1 September 2026 — Microsoft begins making passkeys the default for users enabled for SMS or voice. Affected users will be prompted to register a passkey after completing MFA.
  • 1 February 2027 — Microsoft-provided SMS and voice authentication retires. Users with no alternative method may face a blocking sign-in prompt.
  • After 1 February 2027 — Users relying only on SMS or voice must register a passkey before continuing. There is no general opt-out.

This is no longer a recommendation to move away from SMS and voice. Microsoft has now set a retirement date.

Step 1: Discovery — who is affected?

  • Users enabled for SMS authentication in the Authentication Methods Policy
  • Users enabled for voice-call authentication
  • Users confirmed to actively use SMS or voice in sign-in logs
  • Users with SMS or voice as their only registered MFA method
  • SSPR configuration — review for SMS and voice dependencies
  • Legacy per-user MFA settings — check for phone-method registrations
  • Guest users, contractors and shared accounts
  • Emergency and break-glass accounts

A user may appear to have several methods registered while still depending on SMS every time they sign in. Identify enabled, registered and used separately.

Step 2: Choose the target methods

MethodBest suited toKey consideration
Passkey (device or synced)Staff with compatible smartphones or managed devicesRequires compatible device, screen lock, supported OS
Windows Hello for BusinessStaff on managed Windows computersTied to device; less suited to shared or hot-desk workstations
FIDO2 security keyAdmins, frontline workers, users without smartphonesPhysical cost; must be issued, tracked and revoked
Microsoft Authenticator passkeyStaff with managed smartphones and Authenticator installedConfirm current passkey support in Authenticator

MFA is not one level of security. The method used matters. Not all MFA methods are equally resistant to phishing.

Step 3: Policy and configuration

  • Enable the chosen method in the Authentication Methods Policy
  • Confirm Conditional Access does not block passkey registration
  • Update SSPR authentication methods
  • Move administrators and privileged accounts first
  • Review emergency account authentication — it must not depend on SMS or voice

Step 4: Pilot

  • Include administrators, office staff, remote workers, frontline workers and users with accessibility needs
  • Test registration on all major device types
  • Test lost-device recovery and Temporary Access Pass issuance
  • Test SSPR with the new methods
  • Confirm the support process works before mass rollout

Step 5: Communicate

Tell users before Microsoft's prompts appear. A pre-announcement prevents genuine registration prompts being mistaken for phishing. Include the reason for the change, what users must do, which devices are supported, the deadline, the support route and what happens if they ignore the prompt.

Step 6: Monitor and close

  • Track registration completion — who registered, who failed, who postponed
  • Identify continued SMS and voice usage after the campaign
  • Document any exceptions with a named owner, a business reason and a review date
  • Once alternative methods are proven, remove SMS and voice from the Authentication Methods Policy
  • Test full recovery chain for all user types
  • Schedule Operational Heartbeat review of authentication methods

The migration is not complete when a passkey is registered. It is complete when users can sign in, recover access and receive support without falling back to SMS.

Self-service password reset

Microsoft's retirement also affects SMS and voice dependencies in SSPR. Review the SSPR authentication methods, combined registration flow, recovery options and administrator reset procedures alongside the MFA migration. Replacing MFA without redesigning account recovery can leave the business with a more secure sign-in and a broken support process.

Customer-managed telecom — exception path only

Organisations with a genuine documented operational need may use a supported customer-managed telecom provider through the Microsoft Security Store. This introduces separate contracts, billing and management. Verify current provider availability, UK support, SMS limitations and SSPR support before committing to this path. Continuing with SMS should be a documented exception with a business reason — not the easiest way to avoid changing user behaviour.

Warning signs — stop or escalate where any apply

  • Nobody knows which users currently use SMS or voice
  • Administrators still rely on SMS for their own accounts
  • Break-glass accounts have not been reviewed
  • Passkeys have not been tested with representative users
  • No security-key option exists for users without smartphones
  • SSPR has not been reviewed for phone-method dependencies
  • Conditional Access blocks passkey registration
  • The plan is to wait for Microsoft's blocking prompt

Plain-English Takeaway

Microsoft-provided SMS and voice authentication in Microsoft Entra ID retires on 1 February 2027. Identify affected users, choose phishing-resistant target methods, move administrators first, pilot and communicate before Microsoft's prompts arrive, and test every recovery route before removing the retiring methods.

Downloadable guide

Download the Microsoft SMS and Voice MFA Retirement Checklist

A printable A4 checklist covering discovery, target method, policy, pilot, communication, monitoring and closure — with the confirmed timeline and warning signs.

Download PDF

Free download. No email address required.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.