If your team still approves sign-ins by text message or an automated phone call, you are not alone. It is familiar, it works on any phone, and it is often the first MFA method a business ever turns on.
Microsoft has now put a firm date on moving away from Microsoft-provided SMS and voice for Entra ID. February 1, 2027 sounds far away, until you picture chasing down registrations across a busy company.
What is changing (and why you should care now)
Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication in Microsoft Entra ID on February 1, 2027. After that date, users who still rely on Microsoft-managed SMS or voice will not be able to use those methods to satisfy MFA requirements, and Microsoft will enforce passkey registration for affected users during sign-in. If you truly need SMS or voice for a subset of users, Microsoft’s stated path is to use a customer-managed telecom provider via the Microsoft Security Store.
The practical takeaway for a growing business is simple: you want to transition on your timeline, not during a Monday morning sign-in surprise.
Your transition checklist (use this as a project plan)
This is written in the order we usually run it, because the sequence matters.
-
Confirm who is actually using SMS and voice today. Do not rely on what you “think” is configured. Check both your Authentication Methods Policy and any legacy MFA settings that might still be in play, then identify the users who have only phone-based methods registered.
-
Pick your target methods (and keep it simple). Most businesses do best with a short menu:
-
Passkeys (FIDO2). This can be a passkey stored on a FIDO2 security key, in Microsoft Authenticator, or via supported platform passkey providers.
-
Microsoft Authenticator (app). Still very common as a stepping stone, especially for users who are not ready for security keys.
-
Windows Hello for Business. A strong option for staff on managed Windows devices.
-
Decide how strict you will be for different roles. Your finance team, executives, and admins should not have the same “fallback” options as a general user. Plan a tighter requirement for privileged roles and high-risk groups.
-
Create a registration drive, not a vague announcement. You will get much better adoption if you turn this into a short campaign with a deadline and clear steps.
-
Run a pilot first. Choose a small group that represents real life: a few office staff, a few remote staff, at least one exec, and at least one person who travels. Fix the rough edges before you scale.
-
Roll out in waves and track progress. Make it someone’s job to watch registration numbers and chase the last 10 to 20%.
-
After each wave, reduce the blast radius. Once a group has registered the new methods, remove SMS and voice for that group so you are not carrying unnecessary risk and complexity.
The user communication plan that avoids helpdesk chaos
Most MFA projects fail in the “people part”, not the technical part. Your goal is to make the change feel expected, supported, and routine.
-
Start with the why, in one paragraph. Tell staff the business is moving away from text and phone call approvals, and that the new methods are designed to reduce phishing and account takeovers.
-
Be specific about dates. Use real calendar dates in your messages, not “soon”. For example:
-
Pilot starts: October 2026
-
Company-wide registration window: November to December 2026
-
SMS/voice turned off for most users: January 2027
-
Microsoft retirement date: February 1, 2027
-
Tell them what to expect on sign-in. People panic when they see a new prompt. A simple line like “You may see a prompt to register a passkey during sign-in” prevents a flood of tickets.
-
Give one clear place to get help. A single internal page or short PDF with screenshots, plus a mailbox or ticket category, beats scattered Teams messages.
-
Plan for travel and new hires. Make sure onboarding includes registering the new methods on day one, and have a process for staff who are travelling during the registration window.
Registration drives: how to get it done quickly
If you are using Microsoft Entra, you have tools to nudge or drive registration. Use them intentionally.
-
Use a Registration Campaign where it fits. Registration Campaigns can encourage users to set up stronger methods like a passkey or Microsoft Authenticator, depending on your configuration.
-
Do short “registration clinics”. A 30-minute drop-in session twice a week for a month is often enough. People bring their phone or security key, get it done, and go back to work.
-
Have a clean fallback for people who get stuck. If a user cannot register because they lost a phone or changed numbers, you need a controlled way to get them back in without weakening your overall policy.
Do not skip break-glass (emergency access) accounts
When you change authentication, you can accidentally lock out admins. Microsoft’s own guidance is to maintain at least two emergency access (break-glass) accounts.
-
Create at least two emergency access accounts. Redundancy matters. One account can fail (or be unavailable) at the exact wrong time.
-
Make them cloud-only and independent. Avoid dependencies on on-premises federation or a single identity system that might be down during an outage.
-
Use phishing-resistant methods on the emergency accounts. Microsoft recommends phishing-resistant options such as passkeys (FIDO2) or certificate-based authentication.
-
Exclude them from Conditional Access policies that could block sign-in. The whole point is that these accounts still work when a policy misconfiguration is what caused the outage.
-
Store credentials and recovery steps safely, and test quarterly. If nobody has tested the process in 90 days, you are guessing.
If you still need phone-based methods for a small subset of users
Some businesses really do have edge cases: staff without smartphones, staff in roles where personal phones are not allowed, or a regulatory requirement that pushes you toward telephony.
Here is the clean way to handle that without keeping everyone on SMS.
-
Define the exception group in writing. Make it a named group with an owner, a business justification, and a review date.
-
Keep the group small and reviewed. If the exception group grows quietly, you will end up back where you started.
-
Use a customer-managed telecom provider for those users. Microsoft’s guidance is that continuing SMS or voice after the February 1, 2027 retirement requires configuring a customer-managed telecom provider through the Microsoft Security Store.
-
Do not use SMS sign-in as “primary authentication”. Microsoft’s guidance is clear that SMS sign-in as a primary authentication method is not supported as a path forward, even with a customer-managed telephony provider.
-
Give exceptions stronger compensating controls. For example, tighter Conditional Access rules, stricter device requirements, and closer sign-in monitoring for that group.
A simple success check before you turn anything off
Before you disable SMS and voice broadly, make sure you can answer “yes” to these.
-
Everyone has at least two working methods. Not two phone numbers, two real options (for example, passkey plus Authenticator, or FIDO2 key plus Windows Hello).
-
Admins are covered. Privileged accounts have phishing-resistant methods, and emergency access accounts are in place and tested.
-
Your helpdesk has a script. A one-page runbook for “new phone”, “lost phone”, “travelling”, and “can’t register” saves hours.
-
You have a clean cutover date. Pick a date in January 2027 to remove Microsoft-managed SMS and voice for most users, so February 1, 2027 is a non-event.
Want a second set of eyes before February 2027?
This transition is very doable, but the details matter, especially around Conditional Access, registration prompts, and emergency access. If you would like help building your SMS and voice retirement plan and running the rollout, the Flexnet Networks team can help you get it done calmly.
Sources
- FAQ for Microsoft-provided SMS and voice retirement - Microsoft Entra ID, Microsoft Learn
- Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID, Microsoft Security Blog
- Frequently asked questions about telephony providers in Microsoft Entra ID, Microsoft Learn
- Manage emergency access admin accounts, Microsoft Learn
- Require Multifactor Authentication, Cybersecurity and Infrastructure Security Agency (CISA)



