Microsoft’s MFA Transition Is Coming. Is Your Business Ready?

Microsoft MFA Is Changing

Sep 3, 2026 by Taylor Krieg

Remember when adding multi-factor authentication (MFA) felt like a major security upgrade?

For years, text messages and phone calls were the default way businesses strengthened account security. They were familiar, easy to deploy, and significantly better than relying on passwords alone.

Now, Microsoft MFA is changing.

Microsoft recently announced it will retire its built-in SMS and voice authentication services in Microsoft Entra ID. For organizations that still use these methods for MFA, this change is a good reminder that the authentication landscape continues to evolve.

Beginning September 1, 2026, Microsoft will start prompting users who rely on SMS or voice authentication to register passkeys. Then, on February 1, 2027, Microsoft’s native SMS and voice authentication services will be fully retired in Microsoft Entra ID.

While February 2027 may sound far away, many organizations will notice the impact much sooner. The real question is not whether this change is coming. It’s whether your organization will be prepared when your users start asking about it.

The good news is that modern, phishing-resistant authentication options like passkeys, Windows Hello for Business, and FIDO2 security keys can provide stronger protection and a more user-friendly experience. Taking time now to prepare can help you avoid last-minute disruptions and keep your users protected.

Why Is Microsoft Retiring SMS and Voice Authentication?

Let’s start with the big question: Why fix something that seems to work?

The answer is security.

Over the last several years, cybercriminals have become much better at stealing authentication codes through phishing attacks, social engineering, and other account compromise techniques. Because of that, methods like SMS and voice authentication no longer provide the level of protection Microsoft believes organizations need moving forward.

Passkeys were designed to address those risks. Instead of relying on a code that can be intercepted or shared, passkeys use modern cryptography that’s built to resist phishing attacks and make it harder for attackers to gain access to user accounts. Other phishing-resistant authentication methods, such as Windows Hello for Business and FIDO2 security keys, may also be appropriate depending on your organization’s users, devices, and security needs.

For businesses, the takeaway is simple: Microsoft isn’t just changing authentication methods. They’re changing what they consider to be the minimum acceptable level of security.

What Happens on September 1, 2026?

Starting September 1, Microsoft will begin nudging users toward passkeys. Organizations with users enabled for SMS or voice authentication will see those users automatically enabled for passkeys and begin receiving registration prompts during MFA sign-ins.

Here’s the important part: Your users won’t suddenly lose access to their accounts on September 1.

In most cases, they’ll start seeing prompts encouraging them to register a passkey. Users can generally postpone these prompts, but Microsoft is signaling very clearly where things are headed.

And if you’re responsible for IT, you can probably already hear some of the questions coming:

  • What exactly is a passkey?
  • Why is Microsoft asking me to set this up?
  • Can I skip this for now?

That means your IT team may begin receiving questions or support tickets long before the retirement date arrives. And if you’ve ever had hundreds of employees suddenly ask, “What is this thing on my screen?” you know it’s better to get ahead of the conversation.

February 1, 2027 Is the Deadline That Matters

This is where planning ahead starts to matter.

On February 1, 2027, Microsoft will retire its built-in SMS and voice authentication services for Microsoft Entra ID. According to Microsoft’s guidance, users whose only MFA option is SMS or voice authentication will be required to register a passkey during sign-in before they can continue accessing their account. When it comes to the February 1 deadline, Microsoft leaves little room for ambiguity:

>>> “There is no opt out from this February 1 behavior. It will be enforced for all tenants.” <<<

In other words, waiting until January of 2027 is not the best strategy. If users encounter passkey registration for the first time while they’re trying to access email, Teams, or other business-critical applications, frustration and support requests can pile up quickly.

The organizations that will have the smoothest experience are the ones that start preparing now. A little planning, user education, and testing ahead of the deadline can help avoid unnecessary disruptions and give everyone confidence when the change arrives.

At the end of the day, this is about more than meeting Microsoft’s deadline. It’s about helping your users stay productive while improving the security of the accounts your business relies on every day.

What Should Your Organization Be Doing Today?

The good news is that you still have time to prepare. The better news is that a little planning now can prevent a lot of confusion later. We recommend focusing on five key areas:

1. Identify Who’s Affected

You can’t build a transition plan until you know who will be affected.

Start by identifying the users who currently rely on SMS or voice authentication. Once you know who those users are, you can better plan communications, training, and support before the changes take effect.

2. Review Your Workforce and Devices

Every organization is different. Take a look at how your employees work and what devices they use.

Do employees use company-issued mobile devices? Shared workstations? Are there any other unique workplace requirements?

These scenarios can all influence which authentication methods make the most sense for your business and users.

3. Prepare Employees for the New Experience

A simple communication plan can make a big difference.

If employees understand why they’re seeing new MFA prompts and what action they need to take, you’ll reduce confusion and avoid a flood of support tickets when passkey registration begins.

4. Review Your Authentication Strategy

This change is a good opportunity to take a step back and review your authentication strategy as a whole.

Ask yourself: Does your current approach still meet your security needs and support the way your business operates today? If not, now is the perfect time to make adjustments before the deadline arrives.

5. Decide Who Will Manage the Transition

Technology changes like this aren’t just IT projects. They require planning, communication, and user support.

If your team is already juggling day-to-day responsibilities, now is a good time to decide who will own the transition and keep it moving forward. For organizations with limited internal resources, Managed Services can help reduce the workload while keeping the project on track.

The goal isn’t just deploying a new authentication method. It’s making the transition as smooth as possible while keeping your team focused on the work that drives the business forward.

Need Help Preparing for Microsoft’s MFA Changes?

The best time to start planning is before users start calling the help desk.

At Mirazon, we help organizations navigate Microsoft changes, strengthen security, and put practical technology strategies in place that support the business. Whether you have 20 users or 2,000, we can help you understand who will be affected, evaluate your options, and build a transition plan that improves security while minimizing disruption.

Let’s talk before February 1, 2027 becomes an emergency. Contact Mirazon today to start planning your transition away from SMS and voice authentication.

Have Questions? Schedule a Discovery Call >

Press enter to search