Microsoft is rolling out a massive authentication update for Entra ID, setting a strict February 1, 2027 deadline to eliminate built-in SMS and voice verification. Beginning September 1, 2026, the identity platform will automatically enable passkeys for accounts reliant on text or phone calls, pushing organizations toward modern, phishing-resistant credentials.
The Death Clock for SMS and Voice Authentication
The enterprise identity landscape is shifting under our feet. For years, multi-factor authentication (MFA) has relied on text messages and automated phone calls as a fallback security blanket. That blanket is officially being pulled.
According to Neowin, Microsoft has started emailing Entra ID administrators to warn them of the upcoming deprecation timeline. SMS and voice authentication methods will vanish entirely on February 1, 2027. If an organization fails to transition its user base away from these legacy vectors before that date, users will slam into a non-bypassable sign-in block.
They will not get past the login portal until they generate a cryptographic passkey.
The engineering rationale here is straightforward and ruthless. SMS and voice codes are fundamentally broken in modern threat environments. They leave organizations wide open to SIM-swapping attacks and sophisticated Adversary-in-the-Middle (AitM) phishing frameworks. Attackers routinely intercept or trick users out of these transient verification codes. Passkeys change the math entirely.
How the Automated Rollout Unfolds
The transition plan moves in carefully orchestrated phases. On September 1, 2026, Entra ID will automatically enable passkeys for anyone currently authenticating via SMS or voice. During everyday sign-ins, the system will actively nudge these users to register their new credentials.
Admins do not have to sit back and watch the chaos unfold. Security teams can take immediate control by auditing their current SMS and voice usage metrics inside the Authentication Methods Policy. Proactively migrating users to Microsoft Authenticator or hardware security keys prevents user friction and avoids surprise deployment hurdles.
Public-key cryptography powers these passkeys, binding credentials securely to a trusted device. Because private keys never leave the local hardware, credential theft and automated AI-driven social engineering campaigns lose their primary attack vector.
Compliance Exceptions and Enterprise Realities
Not every enterprise can flip a switch and abandon legacy telecom overnight. Certain highly regulated sectors are legally bound to maintain SMS or voice verification to satisfy strict compliance frameworks.

Microsoft has accounted for this edge case, though it comes with administrative overhead. Organizations requiring continued SMS or voice support must route their traffic through a customer-managed telecom provider via the Microsoft Security Store. Pricing details for these specialized provider configurations are scheduled to drop on September 18, 2026, with configuration portals opening shortly after on October 30, 2026.
For everyone else, the roadmap is clear. The industry is moving past the era of vulnerable text messages. IT leaders must audit their directory services now, phase out legacy MFA, and embrace hardware-backed authentication before the hard block hits in 2027.