The End of SMS Sign-In Is Coming: Is Your Organization Ready?
The End of SMS Sign-In Is Coming: Is Your Organization Ready?
Microsoft is phasing out one of the most common ways employees sign into email, Teams, and business applications, and the deadline is already set.
Many organizations still rely on text message verification when employees sign into Microsoft 365 and Microsoft Entra ID. By February 2027, that method is going away. At the same time, Microsoft is moving everyone toward a new standard: passwordless authentication using passkeys.
This Isn't Just an IT Update
On paper, this looks like a simple security setting change. In practice, it touches something much more critical: how every employee accesses your business systems, every day.
If this transition isn't planned properly, the impact shows up quickly:
- Employees can't sign in
- Support teams get overwhelmed
- Productivity drops
- Confidence in the experience erodes
This is why leading organizations are getting ahead of it now, not waiting for the deadline.
Where This Becomes Complicated
The challenge isn't the technology. It's your workforce.
Most organizations have a mix of users who:
- Don't have company-issued phones
- Prefer not to use personal devices for work
- Work in shared or frontline environments
Today, SMS-based sign-in fills that gap. When it goes away, those users don't automatically have an alternative. That's where organizations get caught off guard.
What's Actually Changing
There are two key shifts happening across Microsoft 365 and Microsoft Entra ID:
- Passwords and text codes are being phased out as the primary sign-in experience
- Passkeys and passwordless authentication are becoming the default
Microsoft isn't just replacing one method with another, they're changing the model. The expectation going forward is simple: sign-in should be secure, seamless, and not dependent on phone-based codes.
The Timeline
September 2026 Passwordless sign-in (passkeys) becomes the default. Users who rely on text or phone codes will start being prompted to register a new sign-in method.
October 2026 Organizations can configure a third-party telecom provider if they need to continue using SMS or voice authentication temporarily.
February 2027 Microsoft-provided SMS and voice authentication are fully retired. Text messages and phone calls will no longer work as sign-in methods.
After February 2027 Users who haven't transitioned will be forced to adopt passkeys at sign-in. There is no opt-out.
What This Means for Your Organization
At a high level, you'll need to answer one question: how will your employees sign in after SMS is gone?
For most organizations, that leads to a combination of:
- Passwordless sign-in on managed devices
- Alternative methods for frontline or no-device users
The right mix depends on how your workforce is structured, but the important part is making a decision early.
The Trap to Avoid
There will be a natural temptation to say: "Can we just keep using text codes for now?"
Short term, sure. But that path:
- Introduces new cost
- Doesn't improve security
- Ultimately still leads to the same transition later
In other words, it delays the problem. It doesn't solve it.
A Better Approach
The organizations that handle this well are doing three things:
- Treating it as a business decision, not just a technical setting
- Focusing on people, not tools, ensuring every user has a clear, workable sign-in experience
- Planning early, so the transition is controlled, not reactive
How We're Approaching This With Customers
Our focus is simple: make this a non-event for your users. That means:
- Understanding where you're exposed
- Aligning the right authentication approach to your workforce
- Guiding the rollout so there's no disruption
Bottom Line
This change is coming on a fixed timeline. The only variable is how it impacts your organization.
- Leave it late → you manage disruption
- Plan early → your users barely notice the change
Next Step
If you're unsure where your users currently rely on SMS or phone-based sign-in, that's the place to start. A short review is usually enough to understand where the exposure is, what your options are, and how to move forward without disruption.
Back to blog