CampaignSMS

Microsoft Plans to End SMS and Voice Authentication for Entra ID – techrepublic.com

Image: Simon Ray/Unsplash
Microsoft is reportedly phasing out SMS and voice authentication in Entra ID. See the claimed deadlines and what IT administrators should do next.
Microsoft reportedly plans to phase out SMS and voice authentication for Microsoft Entra ID users, pushing organizations toward passkeys and other phishing-resistant sign-in methods.
According to an administrator notice first reported by Windows Latest, affected users will have to register a passkey before Microsoft disables the phone-based authentication methods.
“We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication,” the reported notice states.
Microsoft said SMS and voice authentication provide weaker protection against cyber threats such as phishing, SIM-swapping, and replay attacks. AI-assisted social engineering adds to that risk by helping attackers create more convincing campaigns designed to steal credentials and one-time codes.
Microsoft has laid out a strict, mandatory timetable for its corporate Entra ID platform:
“There is no opt out from this enforcement; it applies to all tenants,” the reported notice states.
Everyday consumers will eventually face the same reality. Microsoft confirmed in support documentation spotted by Windows Latest that it is phasing out text verification and account recovery across personal Microsoft accounts, which power Windows 11, Xbox, and Outlook. While Microsoft has not set a formal cut-off date for home users, the company declared that “the future of authentication is passwordless, secure, and user-friendly,” Windows Latest reported.
Forcing an entire corporate ecosystem off SMS solves a glaring security loophole, but it introduces immediate operational friction. The universal appeal of the text message was its absolute convenience: virtually every mobile device, regardless of age or operating system, can receive an SMS without user configuration.
Passkeys rely on device-level biometric hardware and modern authenticator apps. Organizations must now navigate the logistics of onboarding non-technical staff and supporting workers on older hardware or restrictive bring-your-own-device policies.
Moreover, because text codes have long functioned as the default safety net for forgotten credentials, locking out SMS account recovery creates a higher risk of permanent account lockouts if a user loses access to their primary authentication device. Companies and individual users alike should audit their recovery options and establish passkeys before Microsoft pulls the safety cord entirely.
Read more: Bitwarden’s passkey support for Windows 11 gives Microsoft Entra ID users a phishing-resistant alternative to traditional login credentials.
Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. He has written for a wide range of technical and business audiences, from IT professionals and cybersecurity leaders to small business owners, executives, and technology buyers. His work has appeared in publications including: TechRepublic eWEEK Channel Insider Geekflare Enterprise Networking Planet eSecurity Planet CIO Insight Webopedia With a background in computer science, Aminu specializes in translating complex technical subjects into clear, practical, and accessible content. His writing helps readers understand emerging technologies, evaluate business software, strengthen cybersecurity strategies, and make more informed decisions about technology investments. Across his work, Aminu focuses on the real-world impact of technology, connecting technical innovation with business value, operational efficiency, security, and long-term digital transformation.
Practical tips, shortcuts, and cheat sheets to help professionals get more value from Windows, Office, and the Microsoft ecosystem. Delivered Mondays and Wednesdays.

Microsoft has sharply reduced its China footprint, but Azure and AI demand from Chinese companies operating abroad are giving it a reason to stay.

See what you missed in Daily Tech Insider from August 10–14.

Microsoft is consolidating its consumer Copilot and Microsoft 365 Copilot apps into one experience, with several feature retirements beginning Aug. 18 and a broader desktop rollout following in September.

Microsoft’s August Patch Tuesday fixes about 400 security flaws, including an actively exploited Windows zero-day and multiple 9.8-rated RCE bugs.

We use cookies and other data collection technologies to provide the best experience for our customers. You may request that your data not be shared with third parties here: Do Not Sell My Data.
© 2026 TechnologyAdvice. All rights reserved.

source

Leave a Reply

Your email address will not be published. Required fields are marked *