Farewell, SMS and voice authentication. We had a good run, but it’s finally coming to an end.
From 1 September 2026, Microsoft will be using passkeys as its default authentication method in Entra ID (its access management and identity service), and voice authentication and SMS will be fully retired by 1 February 2027.
This means your 2022 MFA rollout may have just become a liability. In this post, we’ll take a look at what’s about to happen here and what you need to do.
Why is Microsoft doing this?
The move, like so much else these days, has its roots in AI. Microsoft Threat Intelligence has observed AI-driven phishing campaigns getting click-through rates as high as 54%, compared to about 12% for traditional phishing.
In other words, AI is getting seriously good at phishing, and authentication methods based on voice and SMS are much easier to target via phishing.
What does this mean for Australian businesses?
Phishing is a big problem in Australia. It was recorded in 60% of incidents reported to the ASD in 2024-5, and compromised accounts or credentials featured in about 42% of significant incidents.
Plus, business email compromise now makes up about 15% of business-related cybercrime, and email compromise without direct loss adds another 19%. That means about one in every three security incidents now starts with email.
These are the failure modes that are most vulnerable to phishable MFA.
What’s changing practically?
Here’s the timeline you need to be aware of:
- On September 1, 2026, passkeys become the default for Microsoft, and any SMS and voice users are told they need to adopt this method
- On 1 February, 2027, any Microsoft-provided SMS or voice authentication will be switched off entirely and enforced across all tenants
- After 1 February, 2027, any remaining voice or SMS users will be forced to register a passkey to access their accounts
Source: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement
The steps you need to take
To make sure you transition properly and in time, here’s what you need to do.
- Audit who’s still on SMS and voice MFA right now in your company
- Set up passkey support in Entra ID and run a phased registration campaign. It’s best to do this department by department.
- Start training your staff on device enrolment and how to use biometrics and security keys safely
- Watch out for any compliance-driven need for SMS and voice, since this now costs extra via a telecom partner
Ideally, you should budget about 6 months for the full phase-out, as this allows you to deal with any issues or roadblocks without being overwhelmed with stress.
Figure out your MFA posture with Aryon
Earlier this year, we posted about how MFA might no longer be effective, and this latest move from Microsoft is another sign you need to be careful in this area.
Cyber insurers are now scrutinising authentication maturity, and phishing-resistant MFA is seen as a baseline expectation. If you want to stay compliant, insured, and secure, you need to be airtight here.
We can help. Get in touch with Aryon to find out how we can help you improve your MFA posture ahead of the upcoming changes.