Microsoft Ditches SMS Authentication Amid Rise in AI-Driven Phishing Attacks
Microsoft has announced that it will be phasing out SMS and voice-based authentication for its Entra users starting September 1, due to the rise in AI-powered phishing attacks. The company claims that AI has made it easier for attackers to manipulate SMS and voice channels, allowing them to steal passwords and MFA codes with a higher success rate than pre-AI phishing attempts.
The move is part of Microsoft's efforts to strengthen its authentication methods and prevent phishing attacks. Starting September 1, users will be asked to set up a passkey during sign-in if they are currently using SMS or voice authentication. If they fail to do so, they will need to switch away from these methods before the rollout begins.
By February 1, 2027, Microsoft will fully retire SMS and voice authentication for Entra ID, and passkeys will become mandatory. Personal accounts for Outlook, Xbox, and Windows 11 users are also being phased out of SMS authentication, although there is no confirmed deadline yet.
Microsoft recommends that users set up a passkey or switch to Microsoft Authenticator to avoid being affected by the change.