Posted by admin
September 8, 2026 at 9:26 am.
SMS stands for Short Message Service, which is the technical term for text messaging. SMS is how you receive a text message on your phone.
2FA stands for Two-Factor Authentication. You might also hear the term MFA, or Multi-Factor Authentication. These security methods require two forms of verification before granting access to a site, application or server.
Think of it this way: you enter your password to check your email, and then you receive a text message containing a code that must also be entered before you can log in. That second step is 2FA.
For many of us, SMS was our introduction to two-factor authentication. First, your bank required it. Then your email provider. Now it seems like nearly every online service wants a second factor.
SMS was also widely available long before authentication apps, passkeys, hardware tokens, and other modern authentication methods became common.
If SMS is on its way out, what should you use instead?
Fortunately, there are several more secure alternatives available today.
Authenticator apps
Authenticator apps, such as Microsoft Authenticator and Google Authenticator, generate time-based security codes directly on your device rather than sending them through a text message. Because the codes never travel across the cellular network, they are far less vulnerable to SIM-jacking attacks.
For most users, an authenticator app is the easiest and most practical replacement for SMS-based authentication.
Passkeys
Passkeys are quickly becoming the gold standard for account security. Instead of using a password and SMS code, passkeys use built-in security features on your phone, tablet or computer, often combined with your fingerprint, face recognition or device PIN.
Passkeys are resistant to phishing attacks and eliminate the need to remember complex passwords.
Hardware security keys
Hardware security keys are small USB, NFC or Bluetooth devices that must be physically present to sign in. Popular examples include YubiKey and Google Titan Security Keys.
These devices provide a very high level of protection and are often used by IT professionals, business executives, and organizations with strict security requirements.
Biometrics
Many applications now support biometric authentication such as fingerprints or facial recognition. While the biometric data itself typically remains on your device, it can be combined with passkeys or authenticator apps to create a secure and user-friendly login experience.
Which option is best?
If you’re looking for the simplest upgrade from SMS, start with an authenticator app.
If your accounts support them, passkeys are quickly becoming the preferred option because they are easier to use and significantly more resistant to phishing attacks.
For users who need the highest level of protection, consider a hardware security key.
Bottom line:
Any of these options is generally more secure than receiving a code by text message. The best time to move away from SMS is before you’re forced to.
Think of SMS for 2FA like hiding your house key under the welcome mat. It’s better than leaving the door unlocked, but criminals already know where to look.
So, why is the beginning of the end for SMS-based 2FA upon us?
Microsoft has announced plans to move users away from SMS and voice-based authentication methods. The reason is simple: SMS has become increasingly vulnerable to attack. While it’s still better than having no second factor at all, it is now considered one of the weaker forms of multi-factor authentication.
Attackers also use phishing websites that look almost identical to legitimate login pages. When you enter your password and SMS code into a fake page, you might unknowingly hand both pieces of information directly to the attacker.
If you’re feeling a little confused, that’s OK. You don’t need to understand every technical detail to understand the basic problem: SMS is no longer considered a sufficiently secure authentication method.
That’s why organizations are increasingly moving toward stronger alternatives such as authenticator apps, security keys and passkeys.
Although upcoming changes might still seem far away, they really aren’t. Anyone using Microsoft products or services — whether for personal, business, educational, or non-profit purposes — should begin planning a transition away from SMS now. Waiting until the last minute often leads to frustration, long support queues, and unnecessary downtime.
If you value access to your Microsoft services, take ownership of the process and move to a more secure authentication method before you’re forced to do so.
The same advice applies to organizations. Encouraging employees, volunteers and users to make the change now can help prevent overwhelming your help desk later. Nobody wants a flood of panicked calls because everyone waited until the final week to update their authentication methods.
You’re my kind of people…
…if you’re wondering why this could signal the broader decline of SMS-based authentication.
When a company the size of Microsoft decides SMS no longer provides an acceptable level of security, other organizations pay attention. Microsoft’s decision reflects years of data showing the weaknesses of SMS authentication and the growing sophistication of modern attacks.
Other technology companies have already begun moving in the same direction. Some have limited SMS authentication for certain users, while others are investing heavily in passkeys and app-based authentication. Adoption timelines vary by industry. Technology companies tend to move quickly, while highly regulated industries, such as banking, often move more slowly.
My crystal ball has been in the shop for a while, but my best guess is that SMS-based authentication will largely disappear over the next five years. The security risks are simply too high, and attackers have become too good at exploiting them.
Microsoft’s move is not the entire iceberg; it’s just the part that’s visible above the water. Consider it a wake-up call to start making changes while you still have time to do so on your schedule rather than someone else’s.
Why wait?
While we might still have to use 2FA to get into heaven (or the other place), I’m hoping they use a biometric passkey, because I don’t plan to take my phone with me.
Jonathan Smith is the president of MBS and the Chief Technology Officer at Faith Ministries in Lafayette, Ind. He is an author and frequent conference speaker. Follow him on X @JonathanESmith
© 2025 Church Executive Magazine. All Rights Reserved. Content on this Website is copyrighted and may not be reproduced in whole or in part without the express written consent of the publisher.
Opinions expressed in Church Executive™ and its associated events are not necessarily those of the publisher or sponsors or advertisers. Content addressing legal, tax and other technical issues is not intended as professional advice and cannot be relied on as such; readers should consult with their own professional advisors.
Privacy Policy
