Microsoft is making a major change to how users verify their identities when signing in to Microsoft 365.
Beginning February 1, 2027, Microsoft-provided text-message and voice-call authentication will be retired in Microsoft Entra ID. Businesses that currently rely on SMS verification codes or automated phone calls for multifactor authentication will need to move affected users to a stronger authentication method.
For organizations throughout Delray Beach, Palm Beach County, Broward County, and Martin County, now is the time to review your Microsoft 365 authentication settings and begin preparing employees for this transition.
Why Is Microsoft Retiring SMS and Voice Authentication?
SMS and voice authentication provide more protection than a password alone, but they are no longer considered sufficiently secure for modern business environments.
These authentication methods remain vulnerable to attacks such as:
- Phishing and stolen verification codes
- SIM-swapping and phone-number takeover
- Text-message interception
- Attacker-in-the-middle phishing websites
- Social-engineering attacks
- Unauthorized phone-number transfers
Cybercriminals have become increasingly effective at convincing users to provide verification codes or redirecting phone numbers to devices under an attacker’s control.
Microsoft is moving toward phishing-resistant authentication methods, including passkeys, Windows Hello, Microsoft Authenticator, and compatible physical security keys.
What Is a Passkey?
A passkey is a modern sign-in method designed to replace traditional passwords and verification codes.
Depending on the device and account configuration, a passkey may be accessed using:
- A fingerprint
- Facial recognition
- A device PIN
- Microsoft Authenticator
- Windows Hello
- A compatible physical security key
Unlike passwords and SMS codes, passkeys cannot easily be captured through a fake login page and reused by an attacker. The sign-in credential remains securely associated with the authorized device or security key.
Important Microsoft MFA Dates
Businesses should be aware of two important dates.
September 1, 2026
Microsoft will begin automatically enabling passkeys for users who are currently configured to use SMS or voice authentication.
Affected users may begin receiving prompts to register a passkey while completing multifactor authentication.
February 1, 2027
Microsoft-provided SMS and voice authentication will be retired.
Users who only have text-message or voice-call authentication configured may be required to register a passkey before they can continue signing in to Microsoft 365.
What Should Businesses Do Now?
Organizations should begin identifying employees who still rely on text messages or automated phone calls for MFA.
Those users should be moved to passkeys or another approved phishing-resistant authentication method well before the February 2027 deadline.
A successful transition should include:
- Reviewing current Microsoft 365 authentication methods
- Identifying users who rely only on SMS or voice calls
- Confirming that emergency administrator accounts remain accessible
- Configuring approved authentication policies
- Testing passkey registration on company devices
- Providing employees with clear enrollment instructions
- Removing outdated authentication methods after testing is complete
Waiting until Microsoft begins enforcing the change could result in unexpected sign-in interruptions, confused employees, and unnecessary support calls.
Starting early allows your business to test the process, resolve device compatibility issues, and complete the transition on your own schedule.
Avoid Unplanned Authentication-Policy Changes
Microsoft 365 authentication policies should be changed carefully.
Incorrectly modifying Microsoft Entra ID authentication settings can prevent employees—and potentially administrators—from accessing email, files, Teams, SharePoint, and other Microsoft 365 services.
Businesses should also verify that they have properly protected emergency administrative access before disabling existing authentication methods.
For many organizations, this is not simply a matter of turning on a new setting. Authentication methods should be reviewed as part of the company’s broader computer cybersecurity strategy.
How TMD Technology Services Can Help
TMD Technology Services can help businesses prepare for Microsoft’s upcoming authentication changes.
Our team can:
- Review your Microsoft 365 environment
- Identify users who still rely on SMS or voice authentication
- Configure appropriate Microsoft Entra ID authentication policies
- Assist users with passkey and Microsoft Authenticator registration
- Review administrative and emergency-access accounts
- Test sign-in methods before older options are removed
- Help prevent unnecessary business interruptions
We also provide professional Microsoft 365 setup and migration services and ongoing managed IT services for businesses throughout South Florida.
The goal is to complete the transition before Microsoft begins enforcing the change—without disrupting your employees, email access, or business operations.
Prepare Your Microsoft 365 Environment Today
February 2027 may seem far away, but businesses should not wait until the deadline to address this change.
Early preparation provides time to identify affected users, test compatible devices, train employees, and correct any authentication-policy issues before they cause sign-in problems.
For assistance preparing your Microsoft 365 environment, contact TMD Technology Services at 561-830-3003.
TMD Technology Services provides Microsoft 365 support, cybersecurity services, computer support, and managed IT services for businesses in Delray Beach, Palm Beach County, Broward County, and Martin County, Florida.






