Table of Contents

What Businesses Need to Know

Microsoft has announced a major change to how people access Microsoft 365 and other services protected by Microsoft Entra ID.

Retiring SMS Authentication, time to use passkey

From 1 February 2027, Microsoft will stop providing SMS text messages and voice calls as authentication methods for Microsoft Entra ID. Passkeys will become the preferred authentication experience for users who currently rely on these methods.

The transition begins on 1 September 2026, so Australian businesses should start reviewing their authentication setup well before the final deadline.

This change does not mean every Microsoft 365 user will suddenly lose access. However, organisations that wait until February 2027 may face avoidable sign-in disruption, increased support requests and confusion among users.

What is Microsoft changing?

Many Microsoft 365 users currently confirm their identity by receiving a code through an SMS text message or automated voice call.

Microsoft is retiring the telecom service it currently uses to deliver these authentication requests through Microsoft Entra ID. The company is moving users towards passkeys and other phishing-resistant authentication methods.

The change primarily affects organisations with users enabled for:

  • SMS multifactor authentication
  • Voice-call multifactor authentication
  • SMS-based sign-in
  • SMS or voice methods configured under legacy MFA policies

Microsoft Authenticator is not being retired. Push notifications, passkeys stored in Microsoft Authenticator, Windows Hello, FIDO2 security keys and other supported authentication methods are separate from the SMS and voice services being retired.

Important dates for Australian businesses

1 August 2026

Microsoft makes API support and guidance available for a temporary opt-out covering the changes that begin on 1 September 2026.

Businesses already running their own passkey rollout, or planning to configure a telecommunications provider, should decide before September whether they want to use it.

1 September 2026

Users enabled for SMS or voice authentication will be automatically enabled for passkeys and may be prompted to register one when signing in.

By default this prompt can be postponed an unlimited number of times, so no one is blocked from signing in on this date.

Businesses should prepare users, review their authentication policies and begin a managed passkey rollout.

18 September 2026

Microsoft plans to publish supported telecommunications providers, pricing and commercial details.

Businesses should review the available providers if they have a genuine operational, regulatory or technical need to retain SMS or voice authentication.

30 October 2026

Administrators can begin selecting and configuring supported providers through the Microsoft Security Store.

Organisations that must retain SMS or voice authentication should configure a supported provider before the final retirement date.

1 February 2027

Microsoft-provided SMS and voice authentication will end.

Businesses should ensure affected users have registered an approved alternative or that a supported telecommunications provider has been configured.

After 1 February 2027

Users relying only on SMS or voice will receive a blocking prompt requiring them to register a passkey before proceeding.

Microsoft has confirmed that there will be no opt-out from the final change on 1 February 2027.

View Microsoft’s official SMS and voice authentication retirement timeline.

Will users be locked out?

Microsoft says users will not simply be permanently locked out on 1 February 2027.

Users whose only available authentication method is SMS or voice will instead receive a blocking prompt requiring them to register a passkey before they can continue signing in.

However, this could still cause business disruption if:

  • A user does not understand the registration prompt
  • The user does not have a suitable device
  • Passkeys have not been properly configured by the organisation
  • The user is working remotely and cannot easily contact support
  • Shared, frontline or temporary accounts have not been reviewed
  • An administrator has no alternative authentication method
  • Device or browser compatibility issues have not been tested
  • The organisation has no documented account recovery process

A planned rollout will be much easier than asking every affected user to complete registration during an urgent sign-in attempt.

Can businesses delay the September changes?

Yes, but only until 1 February 2027.

Microsoft is providing a temporary opt-out covering the changes that begin on 1 September 2026. The opt-out allows an organisation to delay the automatic passkey enablement and the registration campaign while it completes its own transition work, such as configuring a customer-managed telecommunications provider or moving users to a different authentication method.

API support and details for opting out become available on 1 August 2026.

The opt-out does not move the retirement date. Microsoft has confirmed there is no opt-out from the 1 February 2027 enforcement and that it applies to every tenant. Any user whose only available method is still SMS or voice on that date will receive the blocking passkey registration prompt.

The opt-out is worth considering for businesses that:

  • Are already part-way through a passkey rollout and do not want Microsoft’s prompt competing with their own communications
  • Intend to use a customer-managed telecommunications provider and cannot configure one until 30 October 2026
  • Are moving users to Microsoft Authenticator or FIDO2 security keys on a schedule that has already been planned and communicated
  • Operate shared, frontline or rostered devices where an unexpected registration prompt would disrupt a shift handover
  • Have not yet reviewed emergency administrator access

For most small and medium businesses, the opt-out is unnecessary. Because the registration prompt can be postponed indefinitely by default, it will not stop anyone signing in. Businesses that leave it in place gain five months of user familiarity before the deadline arrives, which is usually the better outcome.

What is a passkey?

A passkey is a secure digital credential that can replace a password and traditional SMS verification code.

Instead of receiving a code, the user confirms their identity using a trusted device and its normal security mechanism, such as:

  • Windows Hello PIN
  • Facial recognition
  • Fingerprint
  • Mobile device unlock PIN
  • Microsoft Authenticator
  • Apple Passwords or iCloud Keychain
  • Google Password Manager
  • A compatible third-party credential manager
  • A physical FIDO2 security key

Passkeys use public-key cryptography. The private credential remains protected by the user’s device or passkey provider and is not sent to the website during sign-in.

Why are passkeys more secure than SMS codes?

SMS authentication is better than relying on a password alone, but it is not considered phishing-resistant.

SMS and voice authentication can be vulnerable to:

  • Phishing websites that trick users into entering verification codes
  • SIM-swap attacks
  • Mobile number theft or reassignment
  • Social engineering
  • Interception or redirection of messages
  • Delayed or undelivered messages
  • Users approving or sharing codes without checking the request

A passkey is connected to the legitimate website or service for which it was created. This makes it much harder for a fake sign-in page to capture and reuse the credential.

These are the same techniques used in everyday business email compromise, which is why phishing and scam protection and authentication are best planned together rather than as separate projects.

Passkeys can also make signing in faster because users do not need to wait for a message, copy a code or remember another password.

Are all passkeys the same?

Microsoft Entra ID supports different passkey options. The appropriate choice depends on the user’s role, devices and security requirements.

Synced passkeys

Synced passkeys can be securely synchronised through a supported passkey provider, allowing the user to access the passkey from more than one trusted device.

Examples include:

  • Apple Passwords and iCloud Keychain
  • Google Password Manager
  • Compatible third-party credential managers

These are often convenient for standard business users because the passkey can follow the user across their approved devices.

Device-bound passkeys

A device-bound passkey remains on the device where it was created and does not synchronise through a consumer cloud account.

Examples include:

  • Passkeys in Microsoft Authenticator
  • Microsoft Entra passkeys on Windows
  • Physical FIDO2 security keys

Device-bound options may be more appropriate for administrators, executives, users with access to sensitive systems and organisations with stricter security or compliance requirements.

Because the credential is tied to a specific device, this approach works best where the business already has visibility of which devices its staff are using, which is one reason it suits organisations with managed endpoint arrangements in place.

Microsoft recommends considering device-bound passkeys for privileged users and synced passkeys for many standard users. The final choice should reflect the organisation’s security policies and risk profile.

Learn more about Microsoft Entra passkey options.

Does a passkey require a mobile phone?

Not necessarily.

Depending on the organisation’s configuration, a user may be able to use:

  • Windows Hello on a company computer
  • A passkey stored on an approved phone
  • A physical FIDO2 security key
  • A supported credential manager
  • A passkey on another approved device

Windows Hello is available on business editions of Windows, including Windows 11 Pro, and is usually the simplest option for staff who work primarily from a company computer.

This is important for users who do not have a compatible smartphone, are not permitted to use personal devices for work, or work in shared-device and frontline environments.

Businesses should identify these users early and provide a suitable alternative rather than assuming everyone can register a passkey on a personal mobile phone.

What if the business still needs SMS or voice authentication?

Microsoft will allow organisations with a legitimate operational, regulatory or technical requirement to continue using SMS or voice through a customer-managed telecommunications provider.

Supported providers will be available through the Microsoft Security Store. Administrators will be able to select and configure a provider beginning on 30 October 2026.

This option may involve:

  • Per-message charges
  • Provider-specific pricing
  • Regional availability
  • Contractual or commercial terms
  • Additional configuration and administration
  • Continued exposure to the security limitations of SMS authentication

Microsoft states that moving users from Microsoft-provided SMS or voice to passkeys does not itself attract an additional Microsoft charge. Third-party telecommunications services will have their own pricing.

For most organisations, moving users to phishing-resistant authentication is likely to be preferable to retaining SMS. However, individual operational and compliance requirements should be assessed before making that decision.

What about self-service password reset?

The retirement applies across Microsoft Entra, and that includes self-service password reset.

Any business that allows staff to reset their own password using an SMS code or a voice call will lose that option on 1 February 2027 unless a customer-managed telecommunications provider is configured.

This is easy to overlook because password reset is usually configured once and then left alone. It is worth checking separately from multifactor authentication. The two are configured in different places, and an organisation can be fully prepared for one while still exposed on the other.

Organisations in this position have three options:

  • Move password reset verification to Microsoft Authenticator, email or security questions
  • Configure a customer-managed telecommunications provider through the Microsoft Security Store from 30 October 2026
  • Move users to passwordless sign-in, which reduces the day-to-day need to reset a password at all

Microsoft has also indicated it is developing password change support for users who sign in without a password, with further details to come.

If password resets already generate a steady volume of calls, this is a good opportunity to review how those requests are handled alongside your IT support arrangements.

What should businesses do now?

  1. Identify affected users

    Review which users are registered or actively signing in with SMS or voice authentication.

    Microsoft Entra provides authentication method reports that can help administrators understand which methods are registered and being used across the organisation.

    Microsoft has also published a PowerShell script that lists every user still enabled for SMS or voice. Running it requires the Global Reader, Authentication Policy Administrator or Security Reader role, and any result above zero means the tenant is in scope.

    Do not assume that because Microsoft Authenticator is installed, the user no longer relies on SMS. Some users may have several methods registered while continuing to select SMS as their normal method.

  2. Review current authentication policies

    Check the Microsoft Entra Authentication Methods Policy, legacy MFA settings and any relevant Conditional Access policies.

    If your current setup was configured some time ago, our guide on how to set up multi-factor authentication covers where these settings live in the Microsoft Entra admin centre.

    Administrators should determine:

    • Which authentication methods are currently enabled
    • Which users or groups are targeted
    • Whether legacy authentication settings remain
    • Whether passkeys are already permitted
    • Whether different user groups need different passkey profiles
    • Whether stronger requirements should apply to privileged accounts
    • Whether SMS or voice is also used for self-service password reset
  3. Choose the right methods for different users

    One solution may not suit the entire organisation.

    A business might choose:

    • Synced passkeys for most standard users
    • Device-bound passkeys for administrators
    • FIDO2 security keys for privileged or regulated users
    • Windows Hello for users with managed Windows devices
    • A third-party telecommunications provider for limited exceptional cases

    Licensing can affect which controls are available. Conditional Access, which many of these policies depend on, requires Microsoft Entra ID P1, included in Microsoft 365 Business Premium.

  4. Run a controlled pilot

    Test passkeys with a small group before deploying them across the business.

    The pilot group should include users with different:

    • Roles and permission levels
    • Windows and macOS computers
    • iPhones and Android phones
    • Office and remote-working arrangements
    • Technical confidence levels
    • Accessibility requirements

    Testing helps identify device, policy, communication and support issues before the wider rollout.

  5. Prepare clear user instructions

    Users should be told:

    • Why the sign-in experience is changing
    • When they may see a registration prompt
    • Which passkey option the business has approved
    • Whether personal devices may be used
    • How to register the passkey
    • How future sign-ins will work
    • Who to contact for assistance
    • What to do if a device is lost or replaced

    Users should also be warned not to approve unexpected authentication requests or register credentials following links in suspicious emails.

  6. Plan for lost or replaced devices

    Before deployment, document what happens when:

    • A phone is lost, stolen or replaced
    • A computer is replaced
    • A staff member changes roles
    • A user leaves the organisation
    • A physical security key is lost
    • A passkey is accidentally deleted
    • A user cannot complete registration
    • A privileged administrator loses access

    Where appropriate, users should have an approved backup method. Emergency administrator access should be separately secured, monitored and tested.

  7. Protect administrators first

    Administrators and other privileged users present a higher security risk because their accounts can access sensitive settings, data and systems.

    These accounts should be prioritised for phishing-resistant authentication. Businesses should also review:

    • The number of privileged accounts
    • Whether administrators use separate everyday and administrative identities
    • Conditional Access policies
    • Emergency access arrangements
    • Unused or outdated administrator accounts
    • Authentication and sign-in monitoring
  8. Complete the transition before February 2027

    The final deadline should not be treated as the rollout date.

    Ideally, affected users should be migrated, trained and tested well in advance, leaving time to handle exceptions and resolve problems before Microsoft-provided SMS and voice authentication ends.

Frequently asked questions

Is Microsoft Authenticator being retired?

No. Microsoft Authenticator is not being retired as part of this change. It can continue to support authentication and can also store a device-bound passkey where enabled by the organisation.

Is Microsoft removing MFA?

No. Microsoft is strengthening MFA by moving users away from weaker SMS and voice methods towards phishing-resistant authentication.

Are passwords disappearing completely?

Not necessarily. A business may continue using passwords in some situations, depending on its identity configuration. Passkeys can provide passwordless authentication, but the exact experience depends on the organisation’s policies, devices and applications.

Will users need to register a passkey on 1 September 2026?

Beginning on that date, users currently enabled for SMS or voice may be prompted to register a passkey during an MFA sign-in.

Microsoft says the initial prompt can be postponed during the transition period, but registration becomes blocking for users relying only on SMS or voice after 1 February 2027.

Can we delay the 1 September 2026 changes?

Yes. A temporary opt-out is available from 1 August 2026 and covers the period through to 1 February 2027. It delays the automatic passkey enablement and the registration prompt only. The February retirement itself cannot be deferred.

Does the change apply to personal Microsoft accounts?

This business guidance concerns work and school accounts managed through Microsoft Entra ID. Microsoft is also reducing reliance on SMS for personal Microsoft accounts, but that is managed separately.

Does this timeline apply to every Microsoft tenant?

The published timeline applies to public cloud environments, which covers the majority of Australian businesses. Other cloud environments will follow on a later schedule. Passkey support for guest and B2B users is expected by the end of 2026, and those users are included in the retirement.

Can users use Face ID or a fingerprint?

Yes, if supported and permitted. Face ID, fingerprint recognition or a device PIN can unlock the passkey stored on a trusted device. The biometric information itself is not sent to Microsoft as the authentication credential.

Can a business keep using SMS?

Yes, but after 1 February 2027 it will need to configure a supported customer-managed telecommunications provider. Provider availability, charges and security considerations should be evaluated first.

Will this affect password resets as well as sign-in?

Yes. Self-service password reset is included in the retirement. Businesses using SMS or voice for password reset verification will need an alternative method or a customer-managed telecommunications provider.

Will passkeys cost extra?

Microsoft says migrating users from Microsoft-provided SMS and voice to passkeys does not incur an additional charge.

There may still be implementation, hardware or support costs. For example, a business may decide to purchase physical FIDO2 security keys for selected users.

How Databox Solutions can help

Databox Solutions can help Australian businesses prepare for Microsoft’s authentication changes before they affect users.

Our team can assist with:

  • Reviewing your Microsoft Entra ID environment
  • Identifying users who rely on SMS or voice
  • Assessing existing MFA and authentication policies
  • Reviewing self-service password reset configuration
  • Recommending suitable passkey options
  • Planning a staged deployment
  • Protecting administrator and privileged accounts
  • Preparing user communication and registration guidance
  • Reviewing Conditional Access and account recovery arrangements
  • Supporting users during the transition

This work sits alongside our broader cybersecurity services and Microsoft modern workplace support, so authentication changes can be planned with the rest of your environment rather than in isolation.

Prepare now and avoid sign-in disruption

Microsoft’s February 2027 deadline may seem some distance away, but authentication changes affect users, devices, policies and support processes across the organisation.

Starting early gives your business time to test the right approach, train users and resolve exceptions without interrupting normal operations.

Contact Databox Solutions to request a Microsoft Authentication Review.

If you would like a wider review of your security posture at the same time, you can also book a free cybersecurity audit.

Call 1300 603 404 or speak with the Databox Solutions team to begin preparing your organisation.

Information in this article is based on Microsoft’s published guidance available in July 2026. Dates and implementation details may be updated by Microsoft.

Related services: Cybersecurity · Managed IT Services · Microsoft Modern Workplace · Microsoft 365 Business Premium · IT Support

Further reading: How to Set Up Multi-Factor Authentication · Microsoft 365 Price Changes · Types of Cyber Attacks · Small Business Cybersecurity · Remote Work Setup