Is Microsoft retiring SMS and voice MFA, and what are the deadlines?

Yes. Microsoft announced on 14 July 2026 (message centre notice MC1426371) that it will retire its Microsoft-provided SMS and voice authentication in Entra ID on 1 February 2027, with passkeys becoming the default authentication experience from 1 September 2026. SMS and voice survive after the cutoff only if a business pays a third-party telecom provider through the Microsoft Security Store.

The precision matters: SMS and voice are not being abolished as MFA methods. Microsoft is withdrawing its own telecom delivery of them. For almost every business the sensible response is a planned migration to passkeys, which costs nothing in licensing, rather than paying to keep the weakest method alive.

The key dates

1 August 2026: API support for a temporary opt-out becomes available. 1 September 2026: rollout begins gradually per tenant; users enabled for SMS or voice are auto-enabled for passkeys, the registration campaign switches to nudging all users in eligible tenants toward passkeys, and users see a skippable prompt to register a passkey at MFA sign-in. 18 September 2026: Microsoft publishes the telecom provider list, pricing and commercial terms in the Microsoft Security Store. 30 October 2026: admins can configure a customer-managed telecom provider. 1 February 2027: Microsoft-provided SMS and voice delivery is retired, users whose only method is SMS or voice hit a blocking registration prompt, and Microsoft has stated there will be no further extensions. These dates apply to the Entra ID public cloud; other cloud environments follow a separate timeline. The authoritative detail is Microsoft's retirement article on Microsoft Learn.

Who is actually in scope

The September auto-enablement covers users enabled for SMS or voice in the tenant's authentication methods policy, not users whose day-to-day method is Authenticator push. The trap is that scope is what the policy permits, not what users actually tap: SMS and voice are very commonly left enabled as a fallback even when nobody uses them, and enabled-but-unused is exactly what gets caught. Separately, the registration campaign change applies to all users in eligible tenants, so even push-only users will start seeing passkey prompts. Users already on passkeys, Windows Hello for Business, FIDO2 security keys or smart cards carry on unaffected.

What to do before 1 September 2026

Audit the authentication methods policy in every tenant now. Microsoft has published a PowerShell script, GetEntraSMSVoicePolicyUsers, that checks both the modern policy and legacy MFA settings and needs only a read-level admin role. Then decide per tenant: migrate to passkeys (the default answer), keep SMS or voice via a paid provider (rare, and it needs a real justification), or use the temporary opt-out to control when prompts reach users. The opt-out runs only from 1 September 2026 to 1 February 2027; it is a scheduling tool, not an exit. Finally, tell staff the prompt is coming and that it can be skipped at first, or the September prompts will arrive as a wave of "am I locked out?" helpdesk calls.

How Blue Arc IT Solutions helps

We run the SMS and voice exposure audit across client tenants, report per business what September will change, and manage the passkey migration end to end: policy, pilot, enrolment, enforcement and user comms. We have supported Australian businesses since 2004 and deliver nationally from Canberra. Start at our passkeys for Microsoft 365 businesses hub, check the compliance angle in do passkeys meet Essential Eight ML2, or get in touch.

Last reviewed: 20 July 2026. Microsoft is still filling in retirement detail (provider list 18 September 2026, provider configuration 30 October 2026); check the Microsoft Learn link above for the latest.

Frequently asked questions

Is Microsoft Authenticator push MFA being retired as well?

No. Push notifications in Microsoft Authenticator remain available after February 2027. However, users on push are not out of scope for the change: the passkey registration campaign applies to all users in eligible tenants from September 2026, and any user still enabled for SMS or voice in the tenant policy is auto-enabled for passkeys even if they never use SMS day to day.

Can we keep SMS MFA after 1 February 2027?

Only by contracting a third-party telecom provider through the Microsoft Security Store, configurable from 30 October 2026. Costs are per message, vary by provider and region, and are billed to your business. That is a recurring cost to preserve the weakest authentication method available, so it needs a genuine regulatory or operational justification.

What happens to users who only have SMS or voice registered?

From 1 September 2026 they are prompted to register a passkey at sign-in, and can initially skip the prompt. From 1 February 2027 the prompt becomes blocking: they cannot complete sign-in until they register a passkey, unless the tenant has a paid telecom provider in place.