Microsoft is turning off SMS and phone-call multi-factor authentication
Here is what is changing, when it happens, and exactly how to move your account to the Microsoft Authenticator app before you lose access.
What is actually changing
Multi-factor authentication (MFA) is the second step after your password: a code by text message, an automated call, or a prompt in an app. Microsoft has announced it will stop providing SMS and voice-call verification for Microsoft Entra ID (the sign-in system behind Microsoft 365) and for self-service password reset.
The reason is security. Text messages and phone calls can be intercepted, redirected through SIM-swap fraud, or phished in real time by an attacker relaying the code on a fake login page. App-based approvals and passkeys cannot be replayed that way, because they are tied to your physical device.
Who this affects
Any Microsoft 365 / Entra ID work or school account that has a phone number enabled for verification. Note that this includes people who normally approve sign-ins in the Microsoft Authenticator app but still have a phone number listed as a backup — having a phone number on the account is what puts you in scope, not which method you happen to use day to day. Check your sign-in methods using the steps below.
The timeline
- September 1, 2026 Passkeys become a default sign-in option. Anyone still set up for SMS or voice is automatically enabled for passkeys and starts seeing prompts to register one. These prompts can usually be postponed for now, though some organizations configure them to require registration after a few skips.
- September 18, 2026 Microsoft publishes the third-party telecom providers and pricing available to organizations that must keep SMS for regulatory reasons. Relevant to administrators planning budget, not to individual users.
- October 30, 2026 Organizations with a regulatory or operational requirement for SMS can begin configuring their own third-party telecom provider, at their own cost.
- February 1, 2027 — the hard deadline Microsoft-provided SMS and voice verification stops working. If it is the only method on your account, you will hit a registration screen you cannot skip the next time you sign in.
Microsoft has stated there is no opt-out past February 1, 2027. A temporary deferral exists for administrators between September 2026 and that date, but it only delays the prompts, not the retirement.
How to check what you are using right now
Sign in at mysignins.microsoft.com/security-info with your work account and look at the list of sign-in methods.
Seeing Phone — text or Phone — call with nothing else? Follow the steps below. You can add the app yourself in about five minutes.
Set up the Microsoft Authenticator app
You will need your computer and your mobile phone side by side. On your phone, install Microsoft Authenticator from the Apple App Store or Google Play first. It is free, and the publisher must be listed as Microsoft Corporation.
-
Start the setup
On your computer, go to aka.ms/mysecurityinfo and choose Add sign-in method → Microsoft Authenticator. If your organization has already required this, you may instead be prompted automatically the next time you sign in.
If you see this prompt when signing in, choose Next to begin. -
Confirm you have the app installed
The wizard confirms you have Microsoft Authenticator on your phone. Install it if you have not already, then choose Next on your computer.
Leave this screen open on your computer while you install the app on your phone. -
Add your work account in the app
Open Microsoft Authenticator on your phone. Allow notifications when asked — the app cannot send you approval prompts without this. Tap the + icon, then choose Work or school account. Then select Next on your computer.
Allow notifications, then add a Work or school account in the app. -
Scan the QR code
Your computer displays a QR code. In the app, choose Scan a QR code and point your phone camera at the screen. This is what links the app to your account. Choose Next once it is scanned.
Scan this with the app, not your phone's regular camera app. If the code will not scan, choose Can't scan image? to enter the details manually. -
Approve the test notification
Microsoft sends a test prompt to confirm everything works. Your computer displays a number — type that number into the app on your phone and tap Approve.
This number-matching step is normal and is there to stop attackers spamming you with approval requests. -
Confirm it worked
Once you approve, the wizard confirms the app is connected to your account.
Choose Next to continue. -
Finish
You will see a success screen. Microsoft Authenticator is now your verification method, and you will approve future sign-ins from the app instead of waiting on a text message.
Setup complete. Choose Done.
Before you remove your phone number
Test the app on a real sign-in first. Once you are confident it works, you can delete the old Phone method from your Security info page. Keeping an unused method on the account is an unnecessary risk, but do not remove it until the app is proven.
Recommended: also add a passkey
The Authenticator app satisfies the February 2027 requirement. A passkey goes further — it replaces your password entirely with your phone's fingerprint, face, or PIN unlock, and it is the method Microsoft is steering everyone toward. A passkey cannot be phished, because it will only work on the genuine Microsoft sign-in page.
Once your account is in Microsoft Authenticator, open the app, tap your account, and choose Create a passkey. Your phone will need a screen lock enabled, and you will be asked to allow Authenticator to act as a passkey provider in your phone's settings.
For business owners and IT administrators
If you are responsible for a tenant, the work is larger than a single user changing a setting. In priority order:
- Inventory who is affected. Pull a report of every user with SMS or voice enabled in the Authentication Methods Policy, including any accounts still on legacy per-user MFA settings.
- Watch the accounts nobody owns. Shared mailboxes, break-glass admin accounts, service accounts, and long-tenured staff who set up MFA years ago are where this bites. A break-glass account that can only verify by SMS becomes a locked door on February 1, 2027.
- Enable passkeys in the tenant and turn on a registration campaign so users are nudged well before the deadline rather than on the morning of.
- Plan for staff without smartphones or who refuse to use a personal device for work. FIDO2 hardware security keys and Windows Hello for Business are the usual answers.
- Set a Temporary Access Pass process so your help desk can get someone back in when a phone is lost, broken, or replaced.
- Decide about a third-party SMS provider only if you truly need one. It is available from late October 2026, it costs money per message, and it keeps a weaker method alive. For most small and mid-sized businesses it is not the right call.
Guest and external collaborator accounts deserve their own pass, since you do not control how those users are set up.
One scoping note: these dates apply to the Microsoft public cloud. If you operate in GCC High, DoD, or another sovereign cloud environment, your timeline is separate and should not be planned against the dates above.
Common questions
Will I be locked out of my account on February 1, 2027?
Not locked out permanently. If SMS or voice is your only method, you will hit a registration screen at sign-in that you cannot skip, and you will have to set up a stronger method before you can continue. That means doing it on your phone, under time pressure, possibly in front of a client. It is far less disruptive to spend five minutes on it now.
Does this affect my personal Microsoft account too?
This announcement covers Microsoft Entra ID, which is the work and school account system behind Microsoft 365. Microsoft has been moving personal accounts toward passkeys as well, so setting one up on your personal account is worth doing regardless.
I do not have a work phone. Do I have to install this on my personal phone?
That is a fair question to raise with your employer. The Authenticator app on its own does not give your employer control over your personal phone, but if you would rather not install it, a FIDO2 hardware security key is a physical alternative that plugs into your computer. Ask your IT contact which options your organization supports.
What happens when I get a new phone?
Plan ahead where you can. Microsoft Authenticator has a cloud backup feature, but be aware that for work and school accounts it only restores the account name — you still have to verify your identity and sign in again on the new device to finish the restore. Backups also do not transfer between iPhone and Android.
The simplest approach is to set up the app on the new phone before you retire the old one, while you can still approve prompts on the old device. If you have already lost access, your IT administrator can issue a Temporary Access Pass so you can register the new phone.
What if my phone has no signal or no data?
This is one of the advantages over SMS. If push notifications cannot get through, open Microsoft Authenticator and use the six-digit verification code it displays. That code is generated on the device and works completely offline.
Is a passkey required, or is the app enough?
The Authenticator app meets the requirement. Passkeys are what Microsoft is actively promoting and are the stronger option, so we recommend adding one, but the app alone will keep you signing in after February 2027.