Accelerating your transition. To the right outcome.
Our approach is based on four essential elements – Strategy, Transformation, Management, and Optimisation.
Combining these elements into an integrated approach we identify and remove the obstacles to a successful outcome, before you even know they are there.
Get the services you need with the innovation to grow. Partner with Tecala for specialist IT services.
We provide consulting, project management, integration, management expertise and a flexible engagement model. Through our services you can focus on your ICT strategic initiatives, whilst reducing your operating costs.
Discover how we’ve worked with pioneers, market leaders, and innovators who want to use technology to challenge convention, make an impact, or leave a legacy.
Our client engagement model, along with our unique process and methodology, allows us to get closer to you, your team and the entirety of your operations. This approach enables us to get a better understanding of your business and technology challenges. And ensures our clients enjoy great outcomes from their technology initiatives and investments.
Home / News / Microsoft is retiring SMS and voice authentication. The hard part? Everyone who still depends on it.
Microsoft is retiring SMS and voice authentication. The hard part? Everyone who still depends on it.
Posted on 6th Aug 2026, in Managed Services
By Andre Schoeman, Head of Product Management at Tecala
The first sign of this change will not arrive as an announcement. It will arrive as a call to the service desk from someone asking why the sign-in method they have used for years no longer works. Three dates sit behind that call.
🔶 From1 September 2026, passkeys become the default authentication experience for Microsoft Entra ID users currently enabled for SMS or voice authentication.
🔶 From 30 October 2026, organisations that still require SMS or voice must configure their own telecommunications provider through the Security Store and become responsible for the cost of that delivery.
This is a positive and necessary security improvement. SMS messages and voice calls are increasingly vulnerable to phishing, social engineering and SIM-swap attacks.
The challenge is making the transition without confusing users, overwhelming support teams or interrupting access to critical systems.
For IT teams, this may appear to be a change to an authentication policy. For an employee trying to start work, approve a payment or join an important customer meeting, it could appear as an unfamiliar prompt telling them their established sign-in method is no longer available.
This makes the move to passkeys more than a technical configuration change. It is a user migration that needs to be planned, communicated and supported.
Why SMS and voice authentication are being retired
Multifactor authentication is intended to provide another barrier when a password is stolen. If an attacker obtains a user's password, they must still satisfy a second authentication challenge before accessing the account.
The SIM-swap path
In a SIM-swap attack, an attacker impersonates the user when contacting a mobile provider. Using personal information gathered from previous data breaches, social media and other sources, the attacker attempts to persuade a support agent to move the user's mobile number to a SIM or device under the attacker's control.
If the transfer succeeds, authentication messages or calls intended for the legitimate user may be redirected to the attacker.
Social engineering the user directly
SMS and voice authentication can also be defeated through direct social engineering. A caller claiming to be from IT support may ask a user to read out a verification code. A user may be persuaded to approve a request, share their screen or follow instructions that complete an attacker's sign-in.
In these cases, the attacker does not need to break Microsoft's technology. They work around it by exploiting telecommunications processes or convincing the user to participate.
Microsoft's move to passkeys closes off many of these attack paths.
Why passkeys provide stronger protection
With passkeys there is no SMS code for an attacker to redirect through a SIM swap, and no six-digit number for a user to read aloud to someone pretending to be from the service desk. Passkeys are also associated with the legitimate online service, making them resistant to fraudulent sign-in pages designed to capture credentials.
Passkeys require the user to confirm the authentication on that device using its normal unlock method, such as a fingerprint, facial recognition or PIN. Bluetooth is used to establish that the mobile device is physically close to the computer requesting access.
This combines several important elements. The legitimate user must actively consent, the mobile device must authenticate the user, and the device must be in proximity to the computer where the sign-in is taking place.
The fallback for desktops and shared devices
Where a phone-based passkey is not practical, such as a desktop machine without built-in Bluetooth, a physical FIDO2 security key performs the same function. Security keys work well and cost more per user, which is why they are best treated as a considered fallback rather than the default.
Microsoft's direction aligns with the Essential Eight
The Australian Signals Directorate's Essential Eight Maturity Model already calls out the need for phishing-resistant MFA as cyber threats become more sophisticated.
Microsoft's announcement is therefore not an isolated technology decision. It is consistent with the broader direction of modern security practice and the controls Australian organisations are expected to adopt as they raise their Essential Eight maturity.
How Secure Workspace changes the outcome
Tecala Secure Workspaceapproaches authentication as an integral part of the managed end-user environment.
Microsoft Entra identity controls, MFA, Conditional Access, Intune device compliance and standardised security policies are managed as interconnected components. Access decisions can therefore consider both the identity of the user and the security posture of the device they are using.
Phishing-resistant MFA is embedded into the stronger Secure Workspace configurations aligned with the Essential Eight. The underlying policies are developed and tested within Tecala's standard environment before deployment, applied consistently across managed customer environments and monitored for configuration drift.
This established operating model creates a significant advantage when authentication requirements change. The organisation does not need to design its response from the beginning or manage identity, device and support dependencies through separate workstreams.
What the transition covers
🔶 The authentication methods suitable for each user group
🔶 The devices available to those users
🔶 Conditional Access and device compliance dependencies
🔶 Policy configuration and consistent deployment
🔶 Exceptions and recovery scenarios
🔶 End-user communication and registration guidance
🔶 Service desk support when users need assistance
The benefit is not simply that passkeys can be enabled. It is that stronger authentication can be introduced as part of a tested, supportable and consistently managed workplace.
Turn the Microsoft deadline into a security improvement
The retirement of Microsoft-provided SMS and voice authentication is a welcome change. It reduces reliance on methods exposed to phishing, social engineering and weaknesses outside an organisation's direct control.
Organisations should use the time before enforcement to understand their current authentication posture, prepare their users and move each workforce group to an appropriate phishing-resistant method. This will reduce disruption while creating a stronger and more sustainable identity model.
Organisations using Tecala Secure Workspace already have this built in. This is the value of an integrated managed service. Modern identity protection, device management, Conditional Access, policy consistency and end-user support are already brought together within one operating model.
The objective is to make stronger security part of the normal working experience, without leaving users to navigate the change alone.
For organisations that are not there yet, there is still time to make this a planned improvement rather than a deadline.
How Tecala can help
A Secure Workspace Assessment reviews your current authentication methods, identifies the users affected by the retirement, and sets out what moving each workforce group to a phishing-resistant method involves.
👉 Contact us to book a Secure Workspace Assessment.
Microsoft 365 Password Spray Attacks: The Configuration Gaps That Let Them In
Password spray attacks are still compromising Microsoft 365 accounts. The issue is rarely one failed control. It is the gap between what organisations believe is protected and what is actually enforced.