Skip to content

The End of SMS Sign-In Is Coming: Is Your Organization Ready?

| September 8, 2026

The End of SMS Sign-In Is Coming: Is Your Organization Ready?

Microsoft is phasing out one of the most common ways employees sign into email, Teams, and business applications, and the deadline is already set.

Many organizations still rely on text message verification when employees sign into Microsoft 365 and Microsoft Entra ID. By February 2027, that method is going away. At the same time, Microsoft is moving everyone toward a new standard: passwordless authentication using passkeys.

 

This Isn't Just an IT Update

On paper, this looks like a simple security setting change. In practice, it touches something much more critical: how every employee accesses your business systems, every day.

If this transition isn't planned properly, the impact shows up quickly:

  • Employees can't sign in
  • Support teams get overwhelmed
  • Productivity drops
  • Confidence in the experience erodes

This is why leading organizations are getting ahead of it now, not waiting for the deadline.

Where This Becomes Complicated

The challenge isn't the technology. It's your workforce.

Most organizations have a mix of users who:

  • Don't have company-issued phones
  • Prefer not to use personal devices for work
  • Work in shared or frontline environments

Today, SMS-based sign-in fills that gap. When it goes away, those users don't automatically have an alternative. That's where organizations get caught off guard.

What's Actually Changing

There are two key shifts happening across Microsoft 365 and Microsoft Entra ID:

  1. Passwords and text codes are being phased out as the primary sign-in experience
  2. Passkeys and passwordless authentication are becoming the default

Microsoft isn't just replacing one method with another, they're changing the model. The expectation going forward is simple: sign-in should be secure, seamless, and not dependent on phone-based codes.

The Timeline

September 2026 Passwordless sign-in (passkeys) becomes the default. Users who rely on text or phone codes will start being prompted to register a new sign-in method.

October 2026 Organizations can configure a third-party telecom provider if they need to continue using SMS or voice authentication temporarily.

February 2027 Microsoft-provided SMS and voice authentication are fully retired. Text messages and phone calls will no longer work as sign-in methods.

After February 2027 Users who haven't transitioned will be forced to adopt passkeys at sign-in. There is no opt-out.

What This Means for Your Organization

At a high level, you'll need to answer one question: how will your employees sign in after SMS is gone?

For most organizations, that leads to a combination of:

  • Passwordless sign-in on managed devices
  • Alternative methods for frontline or no-device users

The right mix depends on how your workforce is structured, but the important part is making a decision early.

The Trap to Avoid

There will be a natural temptation to say: "Can we just keep using text codes for now?"

Short term, sure. But that path:

  • Introduces new cost
  • Doesn't improve security
  • Ultimately still leads to the same transition later

In other words, it delays the problem. It doesn't solve it.

A Better Approach

The organizations that handle this well are doing three things:

  • Treating it as a business decision, not just a technical setting
  • Focusing on people, not tools, ensuring every user has a clear, workable sign-in experience
  • Planning early, so the transition is controlled, not reactive

How We're Approaching This With Customers

Our focus is simple: make this a non-event for your users. That means:

  • Understanding where you're exposed
  • Aligning the right authentication approach to your workforce
  • Guiding the rollout so there's no disruption

Bottom Line

This change is coming on a fixed timeline. The only variable is how it impacts your organization.

  • Leave it late → you manage disruption
  • Plan early → your users barely notice the change

Next Step

If you're unsure where your users currently rely on SMS or phone-based sign-in, that's the place to start. A short review is usually enough to understand where the exposure is, what your options are, and how to move forward without disruption.

Back to blog