Frankly, It’s About Time.
If you’ve ever signed into Microsoft 365, Outlook, Teams or any business application that asks you to verify your identity, chances are you’ve already used Microsoft Entra ID—even if you’ve never heard the name.
Think of Microsoft Entra ID as your organisation’s digital gatekeeper. It manages who is allowed into your Microsoft environment, confirms that users are who they claim to be, and controls access to everything from email and SharePoint through to line-of-business applications. Whether you’re a sole trader with a Microsoft 365 subscription or a multinational enterprise, Entra ID sits quietly in the background making thousands of security decisions every day.
One of those decisions is how you prove you are really you.
For years, the answer was simple: send a text message or make an automated phone call containing a verification code. It wasn’t perfect, but compared to just using passwords, it was an added layer of protection.
Microsoft has announced that from 1 February 2027, it will retire its own SMS and voice authentication services for Microsoft Entra ID. Starting from 1 September 2026, users who currently rely on SMS or voice verification will see prompts to register passkeys, Microsoft’s preferred phishing-resistant authentication method.
For many organisations, this won’t require any action at all. For others, it will require planning over the next few months.
Why now?
This announcement isn’t really about SMS or voice. It’s about AI.
There was a time when we thought biometrics were the future. Voice recognition. Face recognition. Fingerprints. They felt almost magical because they measured something unique about us.

The problem is that AI has fundamentally changed the playing field. A convincing voice clone can now be generated from seconds of audio. High-quality face synthesis and real-time video manipulation are frighteningly accessible, deepfakes have been around for much longer than the most recent LLM explosion into the zeitgeist.
Even the old security questions we’ve relied on for decades are even more vulnerable when AI can piece together personal information from public sources and social media in a fraction of a second.
The uncomfortable reality is this:
If authentication relies on something that can be copied, replayed or socially engineered, AI can exploit it already. That security gate has been blown away.
SMS had its issues. Criminals have long used SIM-swapping attacks, message interception and phishing sites to steal one-time codes.
And now, voice authentication doesn’t have much better street cred in today’s AI frontier.
While biometrics held the promise of unbreakable security with science-fiction levels of ease, they are no longer the silver bullet many people believed they were.
The new (but really retro) gold standard in security is proving that you possess a trusted device that holds a credential that cannot simply be copied into a fake website, or mimicked.
That’s what passkeys are designed to do.
Who needs to pay attention?
Almost everyone using Microsoft 365 for business is already using Microsoft Entra ID behind the scenes. So the defining point is whether you’re still proving your identity using SMS text messages or automated phone calls.
Your next steps will depend on the size of your organisation.
Sole traders and small business
If you’re the only person using your Microsoft 365 account, this change is relatively straightforward. Think about how you currently verify your sign-in.
If you normally receive a text message with a six-digit code, or an automated phone call, you’ll need to change your authentication method before the 1 February 2027 deadline.
If you’re already using Microsoft Authenticator, Windows Hello or passkeys, you’re well ahead of the transition, and will likely experience minimal disruption.
If you manage a business with staff
The challenge is a little different. This isn’t just about your own account; it’s about everyone who signs into your organisation’s Microsoft 365 environment.
The first step is to find out where your organisation stands.
Ask your IT provider or internal administrator:
- Are any users still relying on SMS or voice authentication?
- Do we already have passkeys enabled?
- What’s our plan for moving users befor February 2027?
For most businesses, this is less of a technical project and more of a communication exercise. Staff need to understand why the change is happening and be given time to adopt the new authentication method before it becomes mandatory.
Why passkeys?
Unlike passwords and SMS codes, passkeys don’t rely on secrets that users have to remember, or codes that can intercepted in transit.

Instead, your device securely stores a cryptographic key that only works for the genuine service you’re trying to access.
That means even if someone builds a perfect-looking fake Microsoft login page, the passkey simply won’t authenticate to it.
That’s why Microsoft describes passkeys as phishing-resistant.
They’re designed to remove the human error that attackers have relied on for years.
My take
Anyone who knows me knows I’m rarely accused of being Microsoft’s biggest fan.
I’ve spent enough years working with Microsoft technologies to know that, as an organisation, they can sometimes feel less like a technology company and more like a flotilla of giant cruise ships. Different divisions, different priorities and different timetables—all trying to head in roughly the same direction but rarely turning at the same speed. That’s the reality of an organisation their size.
So while I think Microsoft has absolutely reached the right conclusion, I also think they’ve arrived at it later than they should have. Personally, I would have expected to see this direction being announced towards the end of 2025, not midway through 2026. The pace of AI-driven identity attacks hasn’t been a surprise, and in my view this response is characteristic of Microsoft: eventually the right decision, but not always at the speed the threat demands.
That said, the timing doesn’t change the conclusion.
Advice that represented best practice five years ago is now often just the minimum acceptable standard. AI has dramatically lowered the barrier to creating convincing phishing campaigns, cloning voices, impersonating trusted people and automating attacks at a scale that simply wasn’t practical before.
We can’t keep defending modern businesses with authentication methods that were designed for a very different internet.
This won’t be the last change we’ll see. If anything, I expect this is the beginning of a much broader reframing of identity verification and what it means to prove the person on the other side of the screen is who they say they are. AI has changed the security equation.


