Six years ago, Microsoft’s own identity security lead wrote a blog post telling the industry to hang up on phone-based authentication for good. It didn’t land the way you’d expect a warning from the company that built the world’s most-used identity platform to land. SMS codes stuck around. Voice calls stuck around. “It’s better than nothing” won the argument, quietly, for years — right up until this summer, when Microsoft stopped asking and started enforcing.
Starting February 1, 2027, SMS and voice one-time passcodes will no longer work as an MFA or first-factor sign-in method in Entra ID — for every tenant, with no opt-out. Global Administrators and external guest users get until July 1, 2027, but that’s a grace period, not an exemption. Passkeys have already been the default authentication experience for SMS/voice users since September 1, 2026. By the time enforcement hits, this won’t feel sudden to anyone who’s been paying attention. It’ll feel overdue.
The Argument Passwordless Advocates Have Been Making All Along
This is the same argument security teams have been making for years — Microsoft just stopped letting anyone ignore it. SMS and voice codes travel over infrastructure nobody who relies on them actually controls: a phone number can be SIM-swapped by convincing a carrier rep, a code can be relayed through a real-time phishing kit, a text can be intercepted at the network level. These are decade-old, well-documented failure modes, not edge cases.
What’s different now is who’s saying it, and how bluntly. Microsoft’s own documentation doesn’t hedge: SMS and voice verification remain vulnerable to phishing, interception, and social engineering, and simply don’t offer the security passkeys do. A competitor could say that and you’d file it under marketing. Coming from the vendor that built the feature, it reads more like a confession.
Why a Deadline Changes the Conversation
Security guidance without a deadline is a recommendation. Security guidance with a hard cutoff and no opt-out is a mandate — and mandates move budgets in a way “best practice” articles never quite manage. For years, the passwordless pitch has competed against inertia: SMS mostly works, migrating takes effort, there’s always a more urgent fire. Microsoft just removed “it mostly works” as an option.
That’s a meaningful shift for teams building their internal case. “Our MFA is weaker than it should be” is a hard argument to prioritize. “Our MFA stops functioning on a date the vendor already announced” is not.
What Microsoft Is Actually Asking For
The detail that matters most isn’t the deprecation — it’s what organizations are being asked to move to. Not a different flavor of one-time code, not a push notification. Passkeys: cryptographically bound to a device, resistant by design to phishing, replay, and SIM-swapping, because there’s no shared secret traveling over a network to intercept. That’s not a lateral move from SMS — it’s a categorically different model, and Microsoft is right to draw the line there.
One more thing worth saying: this isn’t really an AI story. Microsoft ties part of its reasoning to AI-accelerated attacks, but SIM-swapping and real-time phishing relays aren’t new tricks — they’re old ones, just faster now. Passwordless authentication was making this case long before “AI threat” showed up in anyone’s deck.
Deadlines like this don’t come along often in identity security, and they rarely come from the platform vendor itself. Whatever internal case you’ve been building for stronger authentication, Microsoft just handed you the closing argument.