Microsoft is switching off text message logins. Here is what it means for your business.
If your team logs in to Microsoft 365 and gets a six digit code by text message or a phone call, that is about to stop working.
Microsoft has confirmed it is retiring SMS and voice call verification from Microsoft Entra ID (the identity system behind Microsoft 365). Passkeys become the default way people sign in, and the old code by text method gets turned off for good.
The first change lands on 1 September 2026. The hard cutoff is 1 February 2027. There is no opting out of the second one.
Here is the plain English version of what is happening, what your staff will actually notice, and what you need to do about it.
What is changing
Right now, multi factor authentication (MFA) in Microsoft 365 can work a few different ways. An app prompt, a security key, Windows Hello, or the old favourite: a code sent to your mobile by text or read out over a phone call.
That last option is going away. Microsoft is doing two things:
- Making passkeys the default sign in experience for everyone.
- Turning off the text message and voice call delivery it currently provides.
A passkey is a login credential stored on your phone, laptop or a small USB security key. It uses your fingerprint, face or device PIN instead of a code you type in. If you have ever unlocked a banking app with your thumb, you already know how it feels. We have written a separate guide on how passkeys work and how to set one up.
Why Microsoft is doing this
Text message codes were a genuine step up from passwords alone, back when they were introduced. The problem is that attackers caught up years ago.
Three things go wrong with SMS codes:
Fake login pages. A convincing email leads a staff member to a page that looks exactly like the Microsoft sign in screen. They type their password, then type the code from their phone. Both go straight to the attacker, who uses them within seconds. The code being a real code does not help, because the person handed it over willingly.
SIM swapping. Someone contacts a mobile carrier pretending to be your employee, gets the number transferred to a SIM they control, and starts receiving the codes. This is a big enough problem in Australia that the ACMA brought in mandatory identity checks for telcos specifically to slow it down.
Interception and delays. Messages can be intercepted, and in regional and rural areas patchy coverage means codes sometimes arrive late or not at all. Anyone who has stood in a paddock waiting for a text knows the feeling.
Microsoft's position is blunt: SMS and voice are among the weakest authentication options still in common use. This is not just a Microsoft opinion either. The Australian Signals Directorate's own guidance on implementing MFA ranks methods by how well they hold up, and SMS sits near the bottom. Passkeys cannot be phished, because there is nothing to type in and hand over. The credential only works on the real Microsoft site, and it never leaves your device.
The dates that matter
| Date | What happens |<br>| --- | --- |<br>| 1 September 2026 | Anyone currently set up for SMS or voice gets automatically enabled for passkeys. Next time they log in and complete MFA, they get prompted to set one up. They can dismiss it, as many times as they like. |<br>| 18 September 2026 | Microsoft publishes details of third party telco providers, for organisations that genuinely need to keep using SMS. |<br>| 30 October 2026 | Those third party providers can be selected and configured. |<br>| 1 February 2027 | Microsoft provided SMS and voice are switched off completely. |<br>| After 1 February 2027 | Anyone whose only MFA option is SMS or voice hits a prompt to register a passkey that cannot be dismissed. They set one up, or they do not get in. |
A temporary opt out exists for the September to February window, so you can hold off the automatic changes while you sort out your own plan. It does not extend past 1 February 2027. Nothing does.
What the actual impact and change will be
This is the part most articles skip over, so here it is properly.
What your staff will notice
From September, a new prompt. After they log in and pass MFA, some people will see a screen asking them to set up a passkey. It takes about a minute. They can hit "skip" and carry on, and they can keep skipping it indefinitely, which is exactly why relying on the nudge alone is a bad plan. The people most likely to keep skipping are the ones who will cause you the most grief in February.
From February, that prompt stops being optional. If a staff member's only second factor is a text message, they cannot get past the screen without registering a passkey. They will be doing it on the spot, possibly at 7am before a site visit, possibly on a phone with no signal, possibly while ringing you in a panic. Multiply that by however many people are still on SMS.
Password resets change too. If your staff use self service password reset and verify their identity by text, that path is affected as well. Worth checking before someone locks themselves out on a Friday afternoon.
What does not change
If your people already use the Microsoft Authenticator app prompts, Windows Hello (face or fingerprint login on a work laptop), or a physical security key, they are fine. Nothing breaks for them. This only bites where a phone number is the second factor.
Your passwords do not disappear either. Passkeys can replace the whole login, but in most setups the password stays in place for a while yet. This is not a big bang switch to passwordless.
What it costs
Moving people to passkeys costs nothing extra. It is included in what you already pay Microsoft.
Keeping SMS costs money. If your business has a real regulatory or operational reason to keep text message verification, you can contract a telco provider through Microsoft's Security Store from late October. Pricing is per message and varies by provider and region, so you are taking on a bill you do not currently have. For the vast majority of regional businesses, this is not worth it. Passkeys are the better answer on both security and cost.
What happens if you do nothing
Nobody gets permanently locked out. That is the good news. Microsoft has been clear that the February behaviour is a blocking registration prompt, not a lockout.
The bad news is that "not a lockout" still means every affected person in your business hits a wall at the worst possible moment, with no warning, and works out passkeys on their own with no help. That is a bad Monday for them and a very long day for whoever answers the phone.
The difference between a smooth transition and a chaotic one is entirely about whether you deal with this in the next few months or in February.
What to do now
- Find out who is affected. Someone needs to run a report on your tenant to identify which accounts still have SMS or voice as an authentication method. If the answer is zero, you can relax. Any other number and you are in scope.
- Turn passkeys on properly. Make sure passkeys are enabled and configured in your tenant before the September nudges start, so people who do try to register can actually complete it.
- Pick your approach per group. Office staff with company laptops, field staff on phones, and shared or kiosk accounts all need slightly different handling. Shared logins in particular need thinking about early, because passkeys are tied to a person and a device.
- Tell your team what is coming. A short, clear heads up beats a surprise prompt. Explain what a passkey is, why it is changing, and where to get help.
- Run a small pilot. Half a dozen people, a couple of weeks, then roll out with the wrinkles already ironed out.
- Do not forget password resets. Check how your self service password reset is configured and fix it while you are in there.
Where to read more
- Microsoft's official retirement notice, including the full timeline and FAQ
- Microsoft's guide to planning a passkey rollout, for the technical detail
- Australian Signals Directorate guidance on implementing MFA, which explains why some methods beat others
- ACMA rules on telco identity checks, the Australian response to SIM swap fraud
- OAIC notifiable data breach statistics, if you want the numbers on how Australian businesses are actually getting hit
On that last point, it is worth knowing that 2025 was the worst year on record for reported data breaches in Australia, with 1,205 notifications to the OAIC, up 8 per cent on 2024. Stolen credentials remain one of the front doors attackers walk through.
The short version
Text message logins are finished. September is the warning shot, February is the deadline, and there is no extension. Passkeys are free, faster to use than typing codes, and considerably harder to steal.
If you are not sure whether your business is affected, or you would rather someone else handled the whole thing, get in touch with the GBS team. We can check your tenant, tell you exactly who is affected, and run the changeover without your staff losing a day to it.
Simple tech. Smart thinking. Regional roots.