Microsoft Ditches SMS Login Amid Surge in AI-Powered Phishing Attacks
Microsoft is phasing out SMS-based login authentication due to rising concerns over AI-powered phishing attacks. The company has notified IT administrators to shift away from SMS and voice verification methods, citing that generative AI has made these tactics more effective for attackers.
According to Microsoft, the increased use of generative AI has lowered the barrier for attackers to target SMS and voice channels, allowing them to easily redirect phone numbers to devices they control. This trend is reflected in a significant surge in AI-powered password and multifactor code thefts, which have shown higher success rates compared to previous phishing attempts.
As part of its efforts to combat this issue, Microsoft will replace SMS-based login with passkeys as the default sign-in method for its Entra ID identity and access management platform. Passkeys are stored on users' devices, making them more secure against theft by fraudulent login pages.
The transition process is scheduled to occur in several phases. Starting September 1, 2026, all users of Entra ID with enabled SMS or voice authentication will be enrolled in passkeys automatically and required to register their passkeys during the next multifactor authentication session. Those who want more time can temporarily opt out using the Microsoft Graph feature starting August 1, 2026.
Microsoft-provided SMS and voice authentication will be retired on February 1, 2027. Tenant accounts that haven't configured a customer-managed telecom provider through the Microsoft Security Store by then will find affected users locked out of SMS or voice sign-in entirely.