Copilot-Header-image-no-type-no-logo

Microsoft is retiring SMS and voice authentication. The hard part? Everyone who still depends on it.

The first sign of this change will not arrive as an announcement. It will arrive as a call to the service desk from someone asking why the sign-in method they have used for years no longer works. Three dates sit behind that call.

🔶 From 1 September 2026, passkeys become the default authentication experience for Microsoft Entra ID users currently enabled for SMS or voice authentication.

🔶 From 30 October 2026, organisations that still require SMS or voice must configure their own telecommunications provider through the Security Store and become responsible for the cost of that delivery.

This is a positive and necessary security improvement. SMS messages and voice calls are increasingly vulnerable to phishing, social engineering and SIM-swap attacks.

The challenge is making the transition without confusing users, overwhelming support teams or interrupting access to critical systems.

For IT teams, this may appear to be a change to an authentication policy. For an employee trying to start work, approve a payment or join an important customer meeting, it could appear as an unfamiliar prompt telling them their established sign-in method is no longer available.

This makes the move to passkeys more than a technical configuration change. It is a user migration that needs to be planned, communicated and supported. 

Multifactor authentication is intended to provide another barrier when a password is stolen. If an attacker obtains a user's password, they must still satisfy a second authentication challenge before accessing the account.

In a SIM-swap attack, an attacker impersonates the user when contacting a mobile provider. Using personal information gathered from previous data breaches, social media and other sources, the attacker attempts to persuade a support agent to move the user's mobile number to a SIM or device under the attacker's control.

If the transfer succeeds, authentication messages or calls intended for the legitimate user may be redirected to the attacker.

SMS and voice authentication can also be defeated through direct social engineering. A caller claiming to be from IT support may ask a user to read out a verification code. A user may be persuaded to approve a request, share their screen or follow instructions that complete an attacker's sign-in.

In these cases, the attacker does not need to break Microsoft's technology. They work around it by exploiting telecommunications processes or convincing the user to participate.

Microsoft's move to passkeys closes off many of these attack paths. 

With passkeys there is no SMS code for an attacker to redirect through a SIM swap, and no six-digit number for a user to read aloud to someone pretending to be from the service desk. Passkeys are also associated with the legitimate online service, making them resistant to fraudulent sign-in pages designed to capture credentials.

Passkeys require the user to confirm the authentication on that device using its normal unlock method, such as a fingerprint, facial recognition or PIN. Bluetooth is used to establish that the mobile device is physically close to the computer requesting access.

This combines several important elements. The legitimate user must actively consent, the mobile device must authenticate the user, and the device must be in proximity to the computer where the sign-in is taking place.

Where a phone-based passkey is not practical, such as a desktop machine without built-in Bluetooth, a physical FIDO2 security key performs the same function. Security keys work well and cost more per user, which is why they are best treated as a considered fallback rather than the default.

The Australian Signals Directorate's Essential Eight Maturity Model already calls out the need for phishing-resistant MFA as cyber threats become more sophisticated.

Microsoft's announcement is therefore not an isolated technology decision. It is consistent with the broader direction of modern security practice and the controls Australian organisations are expected to adopt as they raise their Essential Eight maturity.

Tecala Secure Workspace approaches authentication as an integral part of the managed end-user environment.

Microsoft Entra identity controls, MFA, Conditional Access, Intune device compliance and standardised security policies are managed as interconnected components. Access decisions can therefore consider both the identity of the user and the security posture of the device they are using.

Phishing-resistant MFA is embedded into the stronger Secure Workspace configurations aligned with the Essential Eight. The underlying policies are developed and tested within Tecala's standard environment before deployment, applied consistently across managed customer environments and monitored for configuration drift.

This established operating model creates a significant advantage when authentication requirements change. The organisation does not need to design its response from the beginning or manage identity, device and support dependencies through separate workstreams.

🔶 The authentication methods suitable for each user group

🔶 The devices available to those users

🔶 Conditional Access and device compliance dependencies

🔶 Policy configuration and consistent deployment

🔶 Exceptions and recovery scenarios

🔶 End-user communication and registration guidance

🔶 Service desk support when users need assistance

The benefit is not simply that passkeys can be enabled. It is that stronger authentication can be introduced as part of a tested, supportable and consistently managed workplace.

The retirement of Microsoft-provided SMS and voice authentication is a welcome change. It reduces reliance on methods exposed to phishing, social engineering and weaknesses outside an organisation's direct control.

Organisations should use the time before enforcement to understand their current authentication posture, prepare their users and move each workforce group to an appropriate phishing-resistant method. This will reduce disruption while creating a stronger and more sustainable identity model.

Organisations using Tecala Secure Workspace already have this built in. This is the value of an integrated managed service. Modern identity protection, device management, Conditional Access, policy consistency and end-user support are already brought together within one operating model.

The objective is to make stronger security part of the normal working experience, without leaving users to navigate the change alone.

For organisations that are not there yet, there is still time to make this a planned improvement rather than a deadline.

A Secure Workspace Assessment reviews your current authentication methods, identifies the users affected by the retirement, and sets out what moving each workforce group to a phishing-resistant method involves.

👉 Contact us to book a Secure Workspace Assessment.

blog

Your AP Team Isn’t as Automated as You Think.

Bought an OCR tool and still processing invoices by hand? Straight Through Processing shows the real gap, and how to close it.

blog

Microsoft 365 Password Spray Attacks: The Configuration Gaps That Let Them In

Password spray attacks are still compromising Microsoft 365 accounts. The issue is rarely one failed control. It is the gap between what organisations believe is protected and what is actually enforced.