Canary It Solutions


Microsoft is Retiring SMS and Voice MFA - What Your Organisation Needs to Know

Person signing in to Microsoft on a smartphone - Microsoft is retiring SMS and Voice MFA

Microsoft is changing the way users verify their identity when accessing Microsoft 365 and other services protected by Microsoft Entra ID. From 1 February 2027, Microsoft-provided SMS and Voice authentication methods will be retired, making now the time for organisations to prepare.

Multi-factor authentication (MFA) remains an important layer of protection against compromised accounts. However, as cyber threats evolve, Microsoft is moving organisations towards stronger, more phishing-resistant authentication methods.

What is changing?

From 1 February 2027, Microsoft-provided SMS text messages and Voice calls will no longer be available as authentication methods for Microsoft Entra ID.

Microsoft considers SMS and Voice authentication less secure than modern alternatives because these methods are more susceptible to phishing and account compromise.

Organisations currently relying on these methods will therefore need to transition affected users to an alternative authentication method.

What does this mean for your organisation?

If any users within your organisation currently receive an SMS or phone call to approve an MFA request, they will be affected by this change.

As part of our ongoing managed services program, Canary IT is helping clients transition away from SMS and Voice MFA ahead of Microsoft’s retirement date.

Our initial focus will be moving affected users to Microsoft Authenticator, including enabling number matching for MFA approvals. This provides a more secure authentication experience while keeping the process straightforward for users.

What action is required?

For most users, no immediate action is required.

Canary IT is currently identifying users who rely on SMS or Voice MFA and will contact affected organisations to coordinate the transition. Our aim is to complete these changes well ahead of Microsoft’s deadline while minimising disruption to users.

Where changes are required, we will:

  • Identify users currently using SMS or Voice MFA
  • Assist users with Microsoft Authenticator enrolment
  • Transition users to Microsoft Authenticator
  • Remove SMS as the primary MFA method where appropriate
  • Disable the ability to select SMS or Voice as an MFA method

Will this impact users?

For some users, yes.

Anyone currently using SMS text messages or phone calls for MFA will need to register the Microsoft Authenticator app on their mobile device.

Registration is typically straightforward and takes only a few minutes. Canary IT will work with affected organisations to plan and schedule the transition and provide appropriate user communications.

Looking ahead – stronger authentication options

Moving away from SMS and Voice MFA is also an opportunity to consider stronger, phishing-resistant authentication methods.

Once the initial transition is complete, organisations may choose to explore options including passkeys and Windows Hello for Business. These technologies can provide stronger protection against phishing and other identity-based attacks while improving the authentication experience for users.

What happens next?

Canary IT will contact affected managed services clients directly to discuss requirements, scheduling and user communications.

If you would like to understand how these changes may affect your organisation, or would prefer to begin planning your transition now, contact your Canary IT account manager.

To read more on this change from Microsoft, see this link 

Get In Touch