Microsoft SMS and Voice MFA Retirement Checklist
Microsoft-provided SMS and voice authentication in Microsoft Entra ID retires on 1 February 2027. From 1 September 2026, affected users will begin receiving passkey registration prompts. This checklist covers the discovery, policy, pilot, communication, monitoring and closure steps a business should complete before the deadline.
What is retiring and when?
- 1 September 2026 — Microsoft begins making passkeys the default for users enabled for SMS or voice. Affected users will be prompted to register a passkey after completing MFA.
- 1 February 2027 — Microsoft-provided SMS and voice authentication retires. Users with no alternative method may face a blocking sign-in prompt.
- After 1 February 2027 — Users relying only on SMS or voice must register a passkey before continuing. There is no general opt-out.
This is no longer a recommendation to move away from SMS and voice. Microsoft has now set a retirement date.
Step 1: Discovery — who is affected?
- Users enabled for SMS authentication in the Authentication Methods Policy
- Users enabled for voice-call authentication
- Users confirmed to actively use SMS or voice in sign-in logs
- Users with SMS or voice as their only registered MFA method
- SSPR configuration — review for SMS and voice dependencies
- Legacy per-user MFA settings — check for phone-method registrations
- Guest users, contractors and shared accounts
- Emergency and break-glass accounts
A user may appear to have several methods registered while still depending on SMS every time they sign in. Identify enabled, registered and used separately.
Step 2: Choose the target methods
| Method | Best suited to | Key consideration |
|---|---|---|
| Passkey (device or synced) | Staff with compatible smartphones or managed devices | Requires compatible device, screen lock, supported OS |
| Windows Hello for Business | Staff on managed Windows computers | Tied to device; less suited to shared or hot-desk workstations |
| FIDO2 security key | Admins, frontline workers, users without smartphones | Physical cost; must be issued, tracked and revoked |
| Microsoft Authenticator passkey | Staff with managed smartphones and Authenticator installed | Confirm current passkey support in Authenticator |
MFA is not one level of security. The method used matters. Not all MFA methods are equally resistant to phishing.
Step 3: Policy and configuration
- Enable the chosen method in the Authentication Methods Policy
- Confirm Conditional Access does not block passkey registration
- Update SSPR authentication methods
- Move administrators and privileged accounts first
- Review emergency account authentication — it must not depend on SMS or voice
Step 4: Pilot
- Include administrators, office staff, remote workers, frontline workers and users with accessibility needs
- Test registration on all major device types
- Test lost-device recovery and Temporary Access Pass issuance
- Test SSPR with the new methods
- Confirm the support process works before mass rollout
Step 5: Communicate
Tell users before Microsoft's prompts appear. A pre-announcement prevents genuine registration prompts being mistaken for phishing. Include the reason for the change, what users must do, which devices are supported, the deadline, the support route and what happens if they ignore the prompt.
Step 6: Monitor and close
- Track registration completion — who registered, who failed, who postponed
- Identify continued SMS and voice usage after the campaign
- Document any exceptions with a named owner, a business reason and a review date
- Once alternative methods are proven, remove SMS and voice from the Authentication Methods Policy
- Test full recovery chain for all user types
- Schedule Operational Heartbeat review of authentication methods
The migration is not complete when a passkey is registered. It is complete when users can sign in, recover access and receive support without falling back to SMS.
Self-service password reset
Microsoft's retirement also affects SMS and voice dependencies in SSPR. Review the SSPR authentication methods, combined registration flow, recovery options and administrator reset procedures alongside the MFA migration. Replacing MFA without redesigning account recovery can leave the business with a more secure sign-in and a broken support process.
Customer-managed telecom — exception path only
Organisations with a genuine documented operational need may use a supported customer-managed telecom provider through the Microsoft Security Store. This introduces separate contracts, billing and management. Verify current provider availability, UK support, SMS limitations and SSPR support before committing to this path. Continuing with SMS should be a documented exception with a business reason — not the easiest way to avoid changing user behaviour.
Warning signs — stop or escalate where any apply
- Nobody knows which users currently use SMS or voice
- Administrators still rely on SMS for their own accounts
- Break-glass accounts have not been reviewed
- Passkeys have not been tested with representative users
- No security-key option exists for users without smartphones
- SSPR has not been reviewed for phone-method dependencies
- Conditional Access blocks passkey registration
- The plan is to wait for Microsoft's blocking prompt
Plain-English Takeaway
Microsoft-provided SMS and voice authentication in Microsoft Entra ID retires on 1 February 2027. Identify affected users, choose phishing-resistant target methods, move administrators first, pilot and communicate before Microsoft's prompts arrive, and test every recovery route before removing the retiring methods.
Downloadable guide
Download the Microsoft SMS and Voice MFA Retirement Checklist
A printable A4 checklist covering discovery, target method, policy, pilot, communication, monitoring and closure — with the confirmed timeline and warning signs.
Download PDFFree download. No email address required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Microsoft Passkey Readiness Guide
Check which users, devices, authentication policies and recovery procedures your business should review before Microsoft retires its own SMS and voice authentication.
View guidePasskey Setup Guide for Microsoft and Google
Create a more phishing-resistant sign-in method on a trusted device and prepare a safe recovery route before relying on it.
View guideCyber Essentials Readiness Checklist
Work through the key controls to review before applying for Cyber Essentials.
View guide