Microsoft Abandons SMS and Voice Authentication in Favor of Phishing-Resistant Passkeys
Microsoft has announced significant changes to its authentication methods in Entra ID. As of September 7, 2026, users can no longer rely on unregistered directory contact data for self-service password reset (SSPR). This means mobile numbers, business phones, and secondary emails not explicitly registered as authentication methods will no longer function for verification.
The shift towards passkeys continues with the default authentication experience in Entra ID being passkeys since September 1, 2026. While users can currently opt out of this transition, the deadline is nearing. By February 1, 2027, Microsoft-provided SMS and voice authentication will be fully retired.
The retirement of SMS and voice authentication comes as a response to the high threat landscape faced by Microsoft environments, which experience over 600 million daily identity attacks. AI-enabled phishing campaigns have seen a significant increase in click-through rates, reaching 54%, compared to 12% for traditional campaigns.