Microsoft Retires Sms Mfa

Microsoft is retiring SMS and voice‑based multi‑factor authentication (MFA) in its Entra ID service, affecting all users and administrators, because AI‑powered attacks can easily bypass these methods; passkeys will become the default authentication method by February 2027. This shift aims to strengthen security and protect accounts from sophisticated threats.
Why is Microsoft retiring SMS and voice MFA?
The rise of AI‑powered attacks has significantly increased the risk associated with traditional MFA methods. These attacks can mimic human behavior, making it difficult for conventional security measures to detect and prevent them.
How do passkeys improve security compared to SMS and voice MFA?
Passkeys use public‑key cryptography to authenticate users, which is much harder for attackers to compromise. They are also resistant to phishing attacks, a common tactic used to bypass traditional MFA methods.
What steps should IT administrators take to prepare for the change?
Microsoft has provided a timeline for the retirement, giving administrators time to act. Administrators can start migrating users to passkeys immediately to ensure a seamless transition by the retirement date.
What does this mean for you?
Users will need to adopt a new authentication method, which may require some initial effort. However, the enhanced security of passkeys makes the transition a worthwhile investment, keeping accounts and data safe from emerging threats.
Frequently asked questions
When will SMS and voice MFA be retired in Entra ID?
Microsoft will retire SMS and voice‑based MFA by February 2027, after which passkeys become the default authentication method.
Why are AI‑powered attacks a concern for traditional MFA?
AI‑powered attacks can mimic human behavior, allowing them to bypass SMS and voice MFA, which rely on factors that can be intercepted or simulated.
What makes passkeys more secure than SMS or voice MFA?
Passkeys rely on public‑key cryptography and are resistant to phishing, making them far harder for attackers to compromise compared to code‑based SMS or voice verification.
How should organizations begin the migration to passkeys?
Organizations should start migrating users to passkeys now, following Microsoft’s timeline, to ensure a smooth transition before the February 2027 retirement deadline.
