Text-Message Sign-In Codes for Microsoft 365 End on February 1. Are Your Staff Ready?

· by IDE Solutions
Short answer: Microsoft stops sending sign-in codes by text message and phone call for most Microsoft 365 users on February 1, 2027. Staff who rely only on those codes will be forced to set up a passkey at their next sign-in. It costs nothing extra, but it needs planning. Start with a list of who still uses SMS.
Many owners assume the text message that arrives when an employee signs in is the safe part of the process. Microsoft now says the opposite. Its own documentation calls SMS and voice codes among the most vulnerable authentication methods available today and is switching off its delivery of them.
The change lands on ordinary offices, because a text code is what most small companies set up when they first turned on multi-factor authentication. If you use Microsoft 365 for your business, some of your people are almost certainly in scope. Below: what happens on which date, what it costs, and a plan that fits into an afternoon of admin work and a short email to staff.
Quick answers
Are text-message codes being switched off completely? Only Microsoft's own delivery of them. From February 1, 2027 Microsoft no longer sends SMS or voice codes for Entra ID, the sign-in system behind Microsoft 365. You can still use them if you contract a telephone provider yourself, at your own cost.
Will my employees be locked out on February 1? Not permanently. Microsoft says users whose only method is SMS or voice get a blocking prompt to register a passkey before they can continue. Nobody can skip it, but nobody is stranded either.
Does the Microsoft Authenticator app stop working? No. The retirement covers the Microsoft-provided SMS and voice pipeline, not app-based approvals, Windows Hello or hardware keys. Users already on those methods change nothing.
What does the move to passkeys cost? Microsoft states that migrating SMS and voice users to passkeys incurs no additional cost. The real cost is the time it takes each person to register one.
What happens on which date?
There are four dates, and only the second and third force anything. Microsoft's retirement page for SMS and voice authentication lays them out like this.
| Date | What changes | What you do |
|---|---|---|
| September 1, 2026 | Passkeys are switched on automatically for everyone enabled for SMS or voice. After their next MFA sign-in they are nudged to register one, and they can snooze it without limit. | Tell staff a prompt is coming |
| October 30, 2026 | You can configure a paid telephone provider in the Microsoft Security Store if you truly need SMS. | Decide whether you need it, most will not |
| February 1, 2027 | Microsoft's SMS and voice delivery ends for all users except Global Administrators and external users. The passkey prompt becomes blocking. | Have everyone on a phishing-resistant method |
| July 1, 2027 | The same applies to Global Administrators and external users. | Move admin accounts too |
Two details matter for a small company. First, the September 1 nudge has already started if your tenant had users enabled for SMS, so some staff may have seen a passkey prompt this month. Second, guests who are internal to your organisation follow the February date, not the July one.
Why is Microsoft dropping something everyone knows?
A text code proves that someone holds the phone number, not that the right person is signing in. Criminals can trick a mobile carrier into moving a number to a new SIM card, and they can talk staff into reading a code aloud on a fake support call. A phishing page can also ask for the code and forward it to the real sign-in within seconds. We described one such campaign in our article on phishing that gets around MFA to read payroll email.
A passkey works differently. It is a cryptographic key stored on the device, unlocked with a fingerprint, face or PIN, and it only answers to the genuine Microsoft sign-in address. There is nothing to read out, so there is nothing to give away. Microsoft says passkeys are resistant to phishing, SIM swapping and replay attacks.
The change is also a sign of where the market is heading. If your cyber insurer or a customer questionnaire asks about MFA, text codes are likely to look weaker every year, and the "strong MFA" answer you can give in 2027 is a passkey or an authenticator app.
Which of your people are actually affected?
Not everyone. Users who already sign in with the Microsoft Authenticator app, Windows Hello or a security key can carry on. The people at risk are those whose only method is a phone number. In the offices we support, that usually means the long-serving staff who set MFA up years ago, part-timers who use a personal phone, and shared or reception accounts that no one wants to touch.
Microsoft publishes a free PowerShell script that lists every user still enabled for SMS or voice. A non-zero result means you are in scope. If you have never opened the Entra admin centre, this is a good moment to hand it to whoever looks after your IT, because it takes minutes and produces a concrete list.
Watch for three awkward groups:
- Employees without a smartphone, for example warehouse or production staff, who need a hardware key or a Windows Hello device instead.
- Accounts shared by several people. They should not exist, and this change is a good reason to replace them with named accounts.
- Outside partners you invited as guests. Passkey support for them is planned for the end of 2026, so agree with them how they will sign in.
Should you keep SMS by paying a telephone provider?
Almost certainly not. Microsoft describes the telephone provider route as meant for regulated industries or genuine operational needs, and it is a separate contract with its own per-message charges. Pricing varies by provider and region, and the first providers are still in private preview.
There is one honest exception. If a site has no smartphones and no budget for security keys, a paid SMS channel can bridge the gap for a handful of accounts. Even then, treat it as a temporary measure and document why you kept it.
The other tempting option is the opt-out. Microsoft offers a temporary switch, a Graph setting called passkeyDynamicMigration, that delays the automatic passkey enablement between September 1 and February 1. It does not delay enforcement. On the retirement date the blocking prompt arrives regardless, so all the opt-out buys you is a quieter autumn and a noisier February.
A four-step plan for a 20-person company
Here is the order we would follow in a tenant of about twenty users. The work is small when it is spread over a few weeks and painful when it is left to the last morning.
Step 1: Count. Run the script above and note who is SMS-only. Add anyone with a shared login or without a smartphone to a separate list.
Step 2: Choose the method per group. Office staff with a smartphone get a passkey in Microsoft Authenticator or their phone's own credential manager. Staff on Windows laptops can use Windows Hello. People without either get a hardware security key. Plan the key purchase now, because that is the only step with a real price tag.
Step 3: Tell people before the prompt does. Send a short message that says what is changing, why, and how long it takes. Microsoft provides end-user communication templates you can adapt. In our experience the emails that get read are the ones that name the date and promise it takes about two minutes.
Step 4: Do administrators first. Global Administrators have until July 1, 2027, but nobody should wait. An admin account protected only by a text code is the most valuable target in the company. Move those accounts now, and keep at least one emergency account protected by a hardware key stored in a safe place.
If you would rather not do this alone, our Microsoft 365 security assessment checks which authentication methods each user has registered, alongside the other settings that decide how exposed your tenant is. It gives you the list from step 1 and a prioritised fix order.
What could go wrong during the switch?
Most problems come from a few predictable places, and none of them is technical.
The first is a lost or replaced phone. A passkey stored on one device does not follow a person to a new one unless it is synced through a credential manager. Decide beforehand whether you allow synced passkeys, which are convenient, or only device-bound ones, which are stricter. Microsoft supports both, and the passkey deployment guide explains the trade-off.
The second is password reset. Microsoft's retirement also covers self-service password reset, so a user whose only recovery method is a text message can no longer reset their own password with it. Since the reset flow itself is changing this autumn, read our note on the September 2026 password reset change before you brief the help desk.
The third is travel and roaming. Staff abroad often cannot receive texts at all, which is one more argument for moving off them. A passkey works on a phone in flight mode, because the check happens on the device.
The fourth is simply forgetting the guests and shared mailboxes. Ownership of those tends to be unclear, so name a person for each one before February.
Is this worth doing well, or just fast?
For a small company the forced passkey prompt is not the risk. The risk is treating February 1 as the goal and stopping there. Once everyone has a passkey, you have the chance to switch off SMS as an allowed method entirely, tighten Conditional Access so that admin sign-ins require a phishing-resistant method, and remove old registered phone numbers. That is the difference between meeting a deadline and lowering the odds of a stolen account.
It also supports your compliance story. Some customer questionnaires ask which type of MFA you use, not only whether you have it. If you are working towards NIS2 or a customer security questionnaire, phishing-resistant sign-in for all staff is an easy and visible line to tick, and our governance and compliance support can map it to the controls those frameworks list.
Get every sign-in method sorted before February
We check your tenant for users who still depend on text codes, choose the right passkey or key for each group, write the message your staff will actually read, and move your admin accounts first.
You get a short list of names, a rollout date and no surprises on February 1. If you also want the wider picture of how well your accounts are protected, we can cover that in the same visit through our cloud security service.
This article was drafted with AI assistance and reviewed, edited and approved by IDE Solutions before publication. More in our Impressum.