Managed Services / Insight

Microsoft is retiring SMS and voice authentication. The hard part? Everyone who still depends on it.

The move to passkeys is more than a technical configuration change. It is a user migration that needs to be planned, communicated and supported.

Andre Schoeman Last updated: 5 min read
Identity & access security
At a glance

Three things to know

  • Microsoft is moving users from SMS and voice authentication towards phishing-resistant methods such as passkeys.
  • The transition needs user communication, device planning, exception handling and service desk support.
  • Secure Workspace brings identity, device compliance, security policies and end-user support together within one managed environment.

The first sign of this change will not arrive as an announcement. It will arrive as a call to the service desk from someone asking why the sign-in method they have used for years no longer works. Three dates sit behind that call.

  1. 1 September 2026

    passkeys become the default authentication experience for Microsoft Entra ID users currently enabled for SMS or voice authentication.

  2. 30 October 2026

    organisations that still require SMS or voice must configure their own telecommunications provider through the Security Store and become responsible for the cost of that delivery.

  3. 1 February 2027

    Microsoft-provided SMS and voice authentication will be retired.

Microsoft announcement

This is a positive and necessary security improvement. SMS messages and voice calls are increasingly vulnerable to phishing, social engineering and SIM-swap attacks.

The challenge is making the transition without confusing users, overwhelming support teams or interrupting access to critical systems.

For IT teams, this may appear to be a change to an authentication policy. For an employee trying to start work, approve a payment or join an important customer meeting, it could appear as an unfamiliar prompt telling them their established sign-in method is no longer available.

This makes the move to passkeys more than a technical configuration change. It is a user migration that needs to be planned, communicated and supported.

Why SMS and voice authentication are being retired

Multifactor authentication is intended to provide another barrier when a password is stolen. If an attacker obtains a user’s password, they must still satisfy a second authentication challenge before accessing the account.

The SIM-swap path

In a SIM-swap attack, an attacker impersonates the user when contacting a mobile provider. Using personal information gathered from previous data breaches, social media and other sources, the attacker attempts to persuade a support agent to move the user’s mobile number to a SIM or device under the attacker’s control.

If the transfer succeeds, authentication messages or calls intended for the legitimate user may be redirected to the attacker.

Social engineering the user directly

SMS and voice authentication can also be defeated through direct social engineering. A caller claiming to be from IT support may ask a user to read out a verification code. A user may be persuaded to approve a request, share their screen or follow instructions that complete an attacker’s sign-in.

In these cases, the attacker does not need to break Microsoft’s technology. They work around it by exploiting telecommunications processes or convincing the user to participate.

Microsoft’s move to passkeys closes off many of these attack paths.

Why passkeys provide stronger protection

With passkeys there is no SMS code for an attacker to redirect through a SIM swap, and no six-digit number for a user to read aloud to someone pretending to be from the service desk. Passkeys are also associated with the legitimate online service, making them resistant to fraudulent sign-in pages designed to capture credentials.

Passkeys require the user to confirm the authentication on that device using its normal unlock method, such as a fingerprint, facial recognition or PIN. Bluetooth is used to establish that the mobile device is physically close to the computer requesting access.

This combines several important elements. The legitimate user must actively consent, the mobile device must authenticate the user, and the device must be in proximity to the computer where the sign-in is taking place.

The fallback for desktops and shared devices

Where a phone-based passkey is not practical, such as a desktop machine without built-in Bluetooth, a physical FIDO2 security key performs the same function. Security keys work well and cost more per user, which is why they are best treated as a considered fallback rather than the default.

Microsoft’s direction aligns with the Essential Eight

The Australian Signals Directorate’s Essential Eight Maturity Model already calls out the need for phishing-resistant MFA as cyber threats become more sophisticated.

Microsoft’s announcement is therefore not an isolated technology decision. It is consistent with the broader direction of modern security practice and the controls Australian organisations are expected to adopt as they raise their Essential Eight maturity.

How Secure Workspace changes the outcome

Tecala Secure Workspace approaches authentication as an integral part of the managed end-user environment.

Microsoft Entra identity controls, MFA, Conditional Access, Intune device compliance and standardised security policies are managed as interconnected components. Access decisions can therefore consider both the identity of the user and the security posture of the device they are using.

Phishing-resistant MFA is embedded into the stronger Secure Workspace configurations aligned with the Essential Eight. The underlying policies are developed and tested within Tecala’s standard environment before deployment, applied consistently across managed customer environments and monitored for configuration drift.

This established operating model creates a significant advantage when authentication requirements change. The organisation does not need to design its response from the beginning or manage identity, device and support dependencies through separate workstreams.

What the transition covers

  • The authentication methods suitable for each user group
  • The devices available to those users
  • Conditional Access and device compliance dependencies
  • Policy configuration and consistent deployment
  • Exceptions and recovery scenarios
  • End-user communication and registration guidance
  • Service desk support when users need assistance

The benefit is not simply that passkeys can be enabled. It is that stronger authentication can be introduced as part of a tested, supportable and consistently managed workplace.

Turn the Microsoft deadline into a security improvement

The retirement of Microsoft-provided SMS and voice authentication is a welcome change. It reduces reliance on methods exposed to phishing, social engineering and weaknesses outside an organisation’s direct control.

Organisations should use the time before enforcement to understand their current authentication posture, prepare their users and move each workforce group to an appropriate phishing-resistant method. This will reduce disruption while creating a stronger and more sustainable identity model.

Organisations using Tecala Secure Workspace already have this built in. This is the value of an integrated managed service. Modern identity protection, device management, Conditional Access, policy consistency and end-user support are already brought together within one operating model.

The objective is to make stronger security part of the normal working experience, without leaving users to navigate the change alone.

For organisations that are not there yet, there is still time to make this a planned improvement rather than a deadline.

Secure Workspace

How Tecala can help

A Secure Workspace Assessment reviews your current authentication methods, identifies the users affected by the retirement, and sets out what moving each workforce group to a phishing-resistant method involves.

Contact us to book a Secure Workspace Assessment
FAQ

Frequently asked questions

What is phishing-resistant MFA?

Phishing-resistant MFA uses methods such as passkeys, Windows Hello for Business and FIDO2 security keys to protect sign-ins. Unlike SMS codes, these methods are tied to the legitimate service, helping prevent attackers from capturing and reusing credentials through fake sign-in pages.

Why is Microsoft retiring SMS and voice authentication?

SMS and voice authentication can be exposed to SIM-swap attacks, phishing and social engineering. Microsoft is moving towards passkeys to reduce reliance on these methods and strengthen account protection.

How should organisations prepare for the transition?

Identify users who still rely on SMS or voice, choose suitable phishing-resistant methods and test them across your devices and applications. Plan registration guidance, recovery options and service desk support so users can make the change with minimal disruption.

About the author

Andre Schoeman

Andre Schoeman is Tecala’s Head of Product Management, with extensive experience in IT and telecommunications. Combining technical and business expertise, he turns technology into practical services that deliver customer value and improve business efficiency.

Continue reading