Microsoft MFA retirement: What you need to know before 2027

The most common way employees verify their identity is about to change

For many organisations, multifactor authentication (MFA) has become a routine part of everyday working life. Employees regularly complete an extra security check before accessing applications and data, helping to keep business information protected.

However, the authentication methods businesses have relied on for years are becoming increasingly vulnerable to modern cyber threats. Microsoft has announced that SMS and voice-based MFA within Microsoft Entra will be retired in February 2027, giving organisations a limited window to review their authentication strategy and prepare for the move to alternatives such as phishing-resistant passkeys.

For organisations still relying on SMS or voice MFA, now is the time to review authentication policies, device readiness and user adoption plans.

Why is Microsoft making this change?

Imagine securing your office with a key that works, but can be copied more easily than newer alternatives. That is essentially where SMS-based MFA finds itself today.

While SMS and voice authentication remain significantly more secure than passwords alone, attackers have become increasingly sophisticated. AI-powered phishing campaigns, social engineering attacks and account takeover attempts are making it easier to trick users into handing over authentication codes or approving access requests.

Microsoft’s response is to move customers away from authentication methods that can be intercepted, shared, or manipulated, and towards phishing-resistant alternatives. The goal isn’t simply stronger security, but reducing opportunities for human error.

What’s replacing SMS and voice MFA?

Passkeys are becoming the new standard

Starting from 1 September 2026, passkeys will become the default authentication experience for users currently using SMS or voice authentication within Microsoft Entra.

Instead of entering passwords or waiting for a text message with a code, users verify their identity using:

  • Fingerprint recognition
  • Facial recognition
  • Device PIN
  • Trusted device authentication

Think of a passkey like having a house key that is designed to work only with you. Rather than relying on a code sent across a network, passkeys use cryptographic credentials securely stored on a trusted device.

For users, authentication becomes quicker and more seamless. And for organisations, it becomes significantly harder for attackers to compromise accounts through phishing attacks.

Why IT leaders should start planning now

Although February 2027 may feel a long way off, the reality is that authentication projects rarely happen overnight.

Most organisations still have users who rely heavily on SMS-based authentication, and moving to passkeys isn’t simply a technical change. It requires planning, communication and user adoption.

A good starting point is to answer four questions:

1. How many users still rely on SMS or voice MFA?

Understanding the scale of the challenge will help determine the effort required.

2. Are your devices ready?

Not all devices and user scenarios support modern authentication methods in the same way.

3. What user training is needed?

Many employees have never used passkeys before.

4. Do you have a migration strategy?

Organisations that start early can introduce changes gradually rather than rushing to meet Microsoft’s deadline.

One important point to note: Microsoft has stated there is no opt-out from this migration, meaning organisations should begin preparing now rather than waiting until the final stages.

The wider security opportunity

This change is about more than replacing one MFA method with another. Many organisations discover that authentication is only one part of a broader cyber security conversation.

Areas worth reviewing include:

  • Conditional Access policies
  • Privileged accounts
  • Security configuration
  • Identity-related risks

For many organisations, preparing for the move to passkeys highlights wider security considerations that may have been overlooked. Taking the opportunity to review these areas can help strengthen your overall security posture, not just your authentication strategy.

Don’t wait until 2027

The organisations that experience the smoothest transition won’t be the ones that react closest to the deadline. They’ll be the organisations that start preparing today.

Getting users comfortable with passkeys not only helps secure the business, it can also encourage stronger security habits in employees’ personal lives.

Is your cyber security posture ready for what’s next?

Microsoft’s MFA changes are a reminder that cyber security is constantly evolving. What was considered best practice a few years ago may no longer offer the same level of protection today.

Bistech’s Cyber Security Health Check helps organisations identify security gaps, assess identity and access controls, review Microsoft security configurations and build a practical roadmap for improvement.

Whether you’re preparing for Microsoft’s MFA changes or reviewing your wider cyber security strategy, our experts can help you understand where you are today and what should come next.

Start with a complimentary Cyber Security Health Check today


Mark Murray, Solutions Consultant

Mark Murray is a Senior Microsoft Consultant at Bistech with extensive experience across Microsoft 365, Azure and cybersecurity. He leads the delivery of many of our Microsoft projects, helping organisations modernise, secure and optimise their IT environments while ensuring measurable business value.