Microsoft Entra Retires Native SMS and Voice MFA in 2027—Prepare for Passkeys Now

Beginning September 1, 2026, Microsoft will start auto-enabling passkeys and registration nudges for SMS- and voice-enabled users in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided SMS and voice delivery ends; organizations must migrate affected users to a phishing-resistant method or configure a customer-managed telecom provider.

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudBriefing · 5 min read
Executive summary

What you need to know

Beginning September 1, 2026, Microsoft will start auto-enabling passkeys and registration nudges for SMS- and voice-enabled users in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided SMS and voice delivery ends; organizations must migrate affected users to a phishing-resistant method or configure a customer-managed telecom provider.

Potentially affected

Microsoft Entra ID and Microsoft 365 administrators; identity, security, compliance, and service-desk teams; public-cloud tenants with users enabled for SMS or voice in Authentication Methods Policy or legacy MFA settings. SSPR and B2B/internal guest scenarios also require review.

DSE recommendation

Inventory affected users, select and pilot replacement methods, communicate the change, and complete migration before February 1, 2027.

Bottom line: Beginning September 1, 2026, Microsoft will start rolling out passkeys as the default authentication experience for users enabled for SMS or voice in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided telecom delivery for SMS and voice will end. Affected organizations should move users to a phishing-resistant method before that deadline or, where there is a documented need to retain SMS or voice, configure a customer-managed telecom provider.

Source fact: what Microsoft is changing

Microsoft is not eliminating every possible use of SMS and voice. It is retiring the native telecom delivery that Microsoft currently provides for those methods in Entra ID. Microsoft says SMS and voice provide weaker protection than phishing-resistant credentials because telephone channels can be phished, intercepted, redirected, or compromised through attacks such as SIM swapping.

Microsoft recommends passkeys as the primary migration path. Entra ID supports synced passkeys and device-bound credentials, including Microsoft Authenticator passkeys, Entra passkeys on Windows, and FIDO2 security keys. Other phishing-resistant options may also fit particular environments.

Key dates

DateMicrosoft changeWhat organizations should know
September 1, 2026Microsoft begins the public-cloud rollout. As it reaches an organization, users enabled for SMS or voice in the Authentication Methods Policy or legacy MFA settings are auto-enabled for passkeys. The registration campaign is placed in a Microsoft-managed state for those users, who are nudged to register after completing MFA.This is a rollout, not a claim that every Entra user changes simultaneously. The automatic cohort is users currently enabled for SMS or voice.
September 18, 2026Microsoft plans to publish supported telecom providers, deployment guidance, pricing, and commercial terms in the Microsoft Security Store.Organizations with a genuine regulatory, technical, or operational need for SMS or voice can begin comparing options.
October 30, 2026Admins are scheduled to be able to select and configure a supported customer-managed telecom provider.Microsoft recommends testing the provider with a pilot group before broad deployment. Partner telecom costs are the customer’s responsibility.
February 1, 2027Microsoft-provided SMS and voice delivery ends in public-cloud Entra ID.Without a configured customer-managed provider, Microsoft-managed SMS or voice can no longer satisfy authentication requirements.
After February 1, 2027A user whose only available MFA method is SMS or voice receives a blocking passkey-registration prompt and must register before continuing sign-in.There is no opt-out from this enforcement.

Scope and important exceptions

  • The published dates apply to Microsoft Entra ID public-cloud environments only. Other cloud environments will receive separate dates and guidance.
  • The native SMS and voice retirement applies across Entra, including self-service password reset.
  • B2B and internal guest users are included in the retirement scope. Microsoft says passkey support for those users is planned by the end of calendar year 2026.
  • If a tenant has no users enabled for SMS or voice, Microsoft says no action is required for this change. Administrators should verify that condition rather than assume it.

The temporary opt-out is not a migration plan

Microsoft Learn documents a temporary opt-out for the automatic passkey enablement and registration-campaign rollout between September 1, 2026, and February 1, 2027. It is configured through Microsoft Graph using the passkeyDynamicMigration opt-out setting and requires the Policy.ReadWrite.AuthenticationMethod permission. Microsoft also notes that moving users out of SMS or voice in the Authentication Methods Policy before September 1 prevents the automatic passkey nudge for those users.

The opt-out does not postpone retirement. Beginning February 1, 2027, the enforcement timeline applies regardless of that setting, and Microsoft provides no opt-out from the final requirement. Because the documented configuration uses a Microsoft Graph beta endpoint, administrators should confirm the current Microsoft procedure immediately before making the change.

DSE recommendation: migration action plan

The following steps are DSE recommendations for managing the transition. Microsoft’s announced requirements and dates are described above.

  1. Inventory now. Identify every user enabled for SMS or voice in both the Authentication Methods Policy and legacy MFA settings. Review actual method-registration and usage data, SSPR dependencies, guest users, privileged roles, shared-device workflows, and recovery processes.
  2. Choose the target experience. Prefer passkeys where supported, then document approved alternatives for devices or workflows that need a different phishing-resistant method.
  3. Pilot before expanding. Test registration, normal sign-in, device replacement, account recovery, temporary access, and help-desk escalation with representative users and devices.
  4. Drive enrollment deliberately. Enable the target method, use a controlled registration campaign, and give users device-specific instructions before prompts appear. Track completion instead of treating policy enablement as proof of adoption.
  5. Prioritize privileged and high-risk users. Move administrators, executives, finance personnel, remote-access users, and other frequently targeted groups first. Apply authentication-strength controls in stages after confirming recovery paths.
  6. Use the temporary opt-out only with an owner and exit date. It can create implementation time, but it should not become a reason to defer the project.
  7. Retain telecom only for a documented exception. If SMS or voice is necessary, review provider information on September 18, configure and pilot beginning October 30, and complete deployment before Microsoft’s February deadline.
  8. Finish early. DSE recommends completing production migration by December 15, 2026, leaving time to resolve exceptions and support users before enforcement.

What users should expect

Users already signing in with a passkey, Windows Hello for Business, a FIDO2 security key, or another approved phishing-resistant method can continue using it. Users who remain enabled for SMS or voice may see a prompt to register a passkey after completing MFA as the rollout reaches their organization. Microsoft currently documents unlimited snoozes during the pre-retirement registration campaign, but the post-retirement prompt for users who have no other method will be blocking.

Related DSE guidance

Official reference

Source review completed August 11, 2026. Microsoft may revise implementation details; confirm current guidance before changing production policy.

Primary reference

Review the official source

Microsoft Learn: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication · Published August 10, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE