Microsoft Ditches SMS and Voice MFA for Passkeys
Microsoft is retiring its native SMS and voice multifactor authentication (MFA) services in Microsoft Entra ID, citing security vulnerabilities. The company will begin disabling its own telecom delivery service starting on February 1, 2027, for most users.
The change aims to promote the adoption of passkeys as the default sign-in experience. Passkeys rely on cryptographic credentials stored on trusted devices or credential managers rather than shared secrets like passwords or one-time codes.
Microsoft will automatically enable passkey support for users who currently use SMS or voice authentication starting in September 2026. Users will receive prompts to register a passkey after completing MFA sign-ins.