# Microsoft is switching off text-message MFA. What to do now

> Microsoft retires SMS and voice MFA on 1 February 2027, and passkey prompts began in September 2026. What Irish SMBs should do before the deadline.

*Source: https://panoptic.ie/blog/microsoft-sms-voice-mfa-retirement-what-to-do*

# Microsoft is switching off text-message MFA. What to do now

The first stage landed on 1 September 2026 and the hard deadline is 1 February 2027. Here is what changes, who it affects in your team, and the two jobs worth doing this month.

David Griffith, Managing Director · 10 September 2026

![Graphic announcing that Microsoft is retiring SMS and voice authentication methods for Microsoft 365 sign-in.](https://panoptic.ie/_astro/Microsoft_are_set_to_retire_SMS_Voice_authentication_methods_92f754277f_1HkdVt.webp)

In short

Microsoft is retiring SMS and voice one-time codes for Microsoft 365 sign-in. Passkey prompts began on 1 September 2026, and from 1 February 2027 Microsoft stops sending codes itself. Staff whose only second factor is a text message will meet a registration prompt they cannot dismiss. Move them to passkeys or another phishing-resistant method before then, or contract your own telecom provider and pay per message.

If some of your team sign in to Microsoft 365 with a six digit code sent by text, that arrangement now has an end date. Microsoft is retiring its own SMS and voice delivery. The first stage landed on 1 September, and the final one falls on 1 February 2027.

## The four dates that matter

Microsoft has published the schedule on its [SMS and voice retirement page](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement), and it runs in four steps.

**1 September 2026.** Passkeys became the default sign-in experience. Users who were enabled for SMS or voice were automatically enabled for passkeys, and the registration campaign settings moved to a Microsoft-managed state. Those users are now prompted to register a passkey the next time they complete multi-factor authentication. The prompt can be snoozed, and by default there is no cap on how often.

**18 September 2026.** Microsoft publishes the telecom providers you can contract with directly, in the Security Store.

**30 October 2026.** You can select and configure one of those providers, if you want to keep sending codes at your own cost.

**1 February 2027.** Microsoft stops delivering SMS and voice codes itself. Anyone whose only registered method is a text message or a phone call meets a passkey registration prompt they cannot dismiss.

That last date is the one to plan around. It applies to every tenant, and there is no opt-out.

## What happens to a user in February

This is worth stating precisely, because the coverage has been loose. Nobody loses their account. Microsoft's [retirement FAQ](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement-faq) answers the question directly: the affected user is prompted to register a passkey, and the prompt blocks progress until they do.

For a receptionist at eight on a Monday with a waiting room filling up, the gap between "blocked until you register" and "locked out" is academic. That is the disruption worth avoiding, and avoiding it costs about twenty minutes per person if you do it in advance rather than at the desk.

## Why Microsoft is doing this

A code sent by text is a shared secret travelling over a network that was never built to carry one. Two attacks beat it routinely.

In a SIM swap, someone persuades a mobile operator to move a number onto a new SIM, and the codes follow them. In a real-time phishing relay, a fake sign-in page passes the password and the code straight through to Microsoft while the attacker keeps the session. Your employee sees a genuine Microsoft screen, because it is one.

Passkeys close both. There is no code to intercept, and the key only works on the real Microsoft domain. We set out the rollout order we use in [passkeys and conditional access without disrupting your team](https://panoptic.ie/blog/passkeys-conditional-access-microsoft-365-rollout).

## Find out how many people this affects

The answer is a number, not a guess. Your administrator can pull the authentication methods report from Microsoft Entra ID, which lists every user and what they can sign in with. What you want from it is the count of people whose only second factor is SMS or voice.

In most firms we onboard, that number is higher than the owner expects. It tends to be whoever was set up first, years ago, and never revisited: the practice manager, the part-time bookkeeper, the person covering reception.

Ask your IT provider for that list this month. If they cannot produce it, that tells you something separate.

## Your three options before February

**Move people to passkeys.** A passkey lives on the phone or laptop the person already uses and unlocks with a fingerprint, a face scan or the device PIN. For most staff this needs no new hardware and no new spend. Registration takes a few minutes each.

**Use another phishing-resistant method.** Hardware security keys suit the people passkeys do not: anyone who will not put a work credential on a personal phone, and anyone working a shared desk. Budget for a small number of them rather than arguing the point.

**Contract your own telecom provider.** From 30 October you can connect your own SMS provider and keep text codes running past February. It carries a per-message cost that varies by provider and region, and it keeps the weakest method in place. It exists for organisations with a real constraint, such as a workforce with no smartphones at all. For most Irish SMBs it is not the answer.

One caution before you plan around any of this. What a given Microsoft 365 licence includes changes, and the tier names move with it. Confirm what your own tenant covers before you commit to an approach, rather than assuming from the bundle name on your invoice.

## The parts that catch small firms out

**The shared reception computer.** A passkey belongs to a person and their device, and a front desk used by four people through one account fits that badly. The usual fix is a security key each, so everyone signs in as themselves. It is also a better position to be in when you need to know who did what.

**The employee with no company phone.** Some staff will decline to register a work credential on a personal device, and you cannot compel them. Hardware keys settle it.

**Password resets.** Self-service password reset is in scope for the same retirement, so a member of staff who relies on a text to reset their own password needs another method registered as well.

**The break-glass administrator.** Keep at least one administrator account that can still get in when a change goes wrong, with its credentials held somewhere physical, and test it before February rather than during.

Practices in regulated trades have a paper trail interest here too. Moving staff off SMS is a decision worth recording in whatever file you keep, and it is the kind of thing we handle as a matter of course for [dental practices](https://panoptic.ie/industries/dental) where the same question comes round at review time.

## What to do this month

Two jobs, both short.

Get the list of users whose only second factor is SMS or voice, and count them. That number sets your timeline, and it is the only figure you need before October.

Then decide the awkward cases now: the shared desks, and the people who will not use a personal phone. Those are the ones that stall a rollout in week three, and they are cheaper to settle in September than in January.

If you would rather not run this yourself, it is part of what we do under [managed IT](https://panoptic.ie/services/managed-it). Tell us how many staff you have and we will come back with a realistic timeline. [Get in touch](https://panoptic.ie/contact).

Will our staff be locked out of Microsoft 365 on 1 February 2027?

No. Microsoft's retirement FAQ states that users whose only method is SMS or voice are prompted to register a passkey, and the prompt blocks progress until they complete it. The account is not disabled and no data is lost. In practice it still means someone cannot start work until they have registered, which is why it is worth doing in advance.

Can we keep using text-message MFA after February 2027?

Only by contracting your own telecom provider through the Microsoft Security Store, which becomes possible from 30 October 2026. Microsoft stops delivering the messages itself on 1 February 2027. Running your own provider carries a per-message cost that varies by provider and region, and it keeps the method that SIM swapping and real-time phishing both defeat.

What happens if an employee refuses to use their personal phone for work sign-in?

Buy them a hardware security key. It is a small physical device that holds the credential, costs less than an hour of downtime, and removes the argument entirely. The same answer covers shared desks, where no single person owns the machine. Budget for a handful rather than trying to make a personal-device policy stretch across everyone.

Does this affect password resets as well as sign-in?

Yes. Self-service password reset is covered by the same retirement, so any member of staff who currently receives a reset code by text needs a second method registered before February 2027. It is easy to miss, because password reset is configured separately from multi-factor authentication and rarely gets reviewed at the same time.

Can we delay the passkey prompts that started in September 2026?

Users can snooze the prompt, and by default there is no limit on how many times. That makes it easy to ignore for months, which is the risk rather than the relief. The prompt becomes non-dismissible on 1 February 2027 for anyone with no alternative method, so the snooze only postpones the work.

[All blog posts](https://panoptic.ie/blog)

## Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.

[Talk to us ](https://panoptic.ie/contact)[See how we onboard](https://panoptic.ie/how-we-onboard)
