Microsoft is changing the way users verify their identity when accessing Microsoft 365 and other services protected by Microsoft Entra ID. From 1 February 2027, Microsoft-provided SMS and Voice authentication methods will be retired, making now the time for organisations to prepare.
Multi-factor authentication (MFA) remains an important layer of protection against compromised accounts. However, as cyber threats evolve, Microsoft is moving organisations towards stronger, more phishing-resistant authentication methods.
What is changing?
From 1 February 2027, Microsoft-provided SMS text messages and Voice calls will no longer be available as authentication methods for Microsoft Entra ID.
Microsoft considers SMS and Voice authentication less secure than modern alternatives because these methods are more susceptible to phishing and account compromise.
Organisations currently relying on these methods will therefore need to transition affected users to an alternative authentication method, such as :
- Microsoft Authenticator – The Microsoft Authenticator app provides a simple and secure MFA experience and is Microsoft’s recommended replacement for SMS and Voice authentication.
- Passkeys – Passkeys represent the next generation of authentication and provide a passwordless sign-in experience that is highly resistant to phishing and credential theft.
- Windows Hello for Business – For organisations using Microsoft-managed endpoints, Windows Hello for Business can provide secure biometric or PIN-based authentication while improving the user experience.
What action is required?
If any of your users currently receive a text message or phone call to verify their identity when signing in to Microsoft 365 or other Microsoft services, they will be affected by this change.
Without a planned transition, users may experience authentication issues once support for these methods is removed.
Organisations should use this period to:
- Identify users currently using SMS or Voice MFA
- Transition users to Microsoft Authenticator
- Remove SMS or Voice as the primary MFA method where appropriate
- Disable the ability to select SMS or Voice as an MFA method
How Canary IT Can Help
Transitioning away from legacy authentication methods is an opportunity to strengthen your organisation’s overall security posture.
Canary IT can assist with:
- Assessing your current MFA configuration
- Identifying users affected by Microsoft’s retirement of SMS and Voice MFA
- Planning and managing the migration to Microsoft Authenticator
- Developing user communication and adoption strategies
- Implementing phishing-resistant authentication technologies
- Reviewing broader Microsoft Entra ID security settings and identity controls
Our team works with organisations across Australia to modernise identity security while minimising disruption to end users.
Start Planning Today
Although Microsoft will not retire SMS and Voice MFA until 1 February 2027, organisations that begin planning early will be better positioned to avoid user disruption and improve their security posture.
If you’re unsure whether your organisation is affected, or would like advice on the best authentication strategy for your environment, contact the Canary IT team for assistance.
Learn More
For Microsoft’s announcement and guidance, visit the Microsoft Security Blog: Microsoft Entra ID Security Updates



