Is Microsoft retiring SMS and voice MFA, and what are the deadlines?
Yes. Microsoft announced on 14 July 2026 (message centre notice MC1426371) that it will retire its Microsoft-provided SMS and voice authentication in Entra ID on 1 February 2027, with passkeys becoming the default authentication experience from 1 September 2026. SMS and voice survive after the cutoff only if a business pays a third-party telecom provider through the Microsoft Security Store.
The precision matters: SMS and voice are not being abolished as MFA methods. Microsoft is withdrawing its own telecom delivery of them. For almost every business the sensible response is a planned migration to passkeys, which costs nothing in licensing, rather than paying to keep the weakest method alive. New to the term? See what a passkey actually is first.
The key dates
1 August 2026: API support for a temporary opt-out becomes available. 1 September 2026: rollout begins gradually per tenant; users enabled for SMS or voice are auto-enabled for passkeys, the registration campaign switches to nudging all users in eligible tenants toward passkeys, and users see a skippable prompt to register a passkey at MFA sign-in. 18 September 2026: Microsoft publishes the telecom provider list, pricing and commercial terms in the Microsoft Security Store. 30 October 2026: admins can configure a customer-managed telecom provider. 1 February 2027: Microsoft-provided SMS and voice delivery is retired, users whose only method is SMS or voice hit a blocking registration prompt, and Microsoft has stated there will be no further extensions. These dates apply to the Entra ID public cloud; other cloud environments follow a separate timeline. The authoritative detail is Microsoft's retirement article on Microsoft Learn.
Who is actually in scope
The September auto-enablement covers users enabled for SMS or voice in the tenant's authentication methods policy or in legacy per-user MFA settings, not users whose day-to-day method is Authenticator push. The trap is that scope is what the policy permits, not what users actually tap: SMS and voice are very commonly left enabled as a fallback even when nobody uses them, and enabled-but-unused is exactly what gets caught. Separately, the registration campaign change applies to all users in eligible tenants, so even push-only users will start seeing passkey prompts. Users already on passkeys, Windows Hello for Business, FIDO2 security keys or smart cards carry on unaffected.
What to do before 1 September 2026
Audit the authentication methods policy and legacy per-user MFA settings in every tenant now, using Microsoft's own SMS/Voice Usage Analyzer script, which needs only a Global Reader, Authentication Policy Administrator or Security Reader role. If a tenant simply should not be swept up in September, Microsoft's own guidance is that the simplest lever is removing SMS and voice from the authentication methods policy before 1 September, not the temporary opt-out API. Reserve the opt-out (available 1 September 2026 to 1 February 2027) for tenants genuinely mid-transition to a telecom provider or another method; either way it delays the change, it does not exempt a tenant from the February enforcement. Check self-service password reset configuration at the same time: the retirement applies across Entra ID, including SSPR, so a tenant relying on SMS or voice to reset passwords loses that path too on 1 February 2027. Finally, tell staff the prompt is coming and that it can be skipped, with no limit on snoozes, until the blocking prompt arrives in February, or the September rollout will arrive as a wave of avoidable helpdesk calls.
How Blue Arc IT Solutions helps
We run the SMS and voice exposure audit across client tenants, report per business what September will change, and manage the passkey migration end to end: policy, pilot, enrolment, enforcement and user comms. We have supported Australian businesses since 2004 and deliver nationally from Canberra. Start at our passkeys for Microsoft 365 businesses hub, check the compliance angle in do passkeys meet Essential Eight ML2, or get in touch.
Last reviewed: 23 July 2026, against Microsoft's Learn article (updated 13 July 2026) and Microsoft's tenant notification email. Microsoft is still filling in retirement detail (provider list 18 September 2026, provider configuration 30 October 2026); check the Microsoft Learn link above for the latest.
Frequently asked questions
Is Microsoft Authenticator push MFA being retired as well?
No. Push notifications in Microsoft Authenticator remain available after February 2027. However, users on push are not out of scope for the change: the passkey registration campaign applies to all users in eligible tenants from September 2026, and any user still enabled for SMS or voice in the tenant policy is auto-enabled for passkeys even if they never use SMS day to day.
Can we keep SMS MFA after 1 February 2027?
Only by contracting a third-party telecom provider through the Microsoft Security Store, configurable from 30 October 2026. Costs are per message, vary by provider and region, and are billed to your business. That is a recurring cost to preserve the weakest authentication method available, so it needs a genuine regulatory or operational justification.
What happens to users who only have SMS or voice registered?
From 1 September 2026 they are prompted to register a passkey at sign-in, and can initially skip the prompt. From 1 February 2027 the prompt becomes blocking: they cannot complete sign-in until they register a passkey, unless the tenant has a paid telecom provider in place.
Does the retirement affect password reset as well as sign-in MFA?
Yes. The Microsoft-provided SMS and voice retirement applies across Entra ID, including self-service password reset, not only MFA at sign-in. A tenant that relies on SMS or voice for SSPR needs an alternative reset method in place before 1 February 2027.