26 August 2026 | By James Thomas
Four challenges every organisation must solve to adopt AI safely
Discover four key challenges affecting AI adoption and how organisations can build confidence in their approach.
Read moreFor many organisations, multifactor authentication (MFA) has become a routine part of everyday working life. Employees regularly complete an extra security check before accessing applications and data, helping to keep business information protected.
However, the authentication methods businesses have relied on for years are becoming increasingly vulnerable to modern cyber threats. Microsoft has announced that SMS and voice-based MFA within Microsoft Entra will be retired in February 2027, giving organisations a limited window to review their authentication strategy and prepare for the move to alternatives such as phishing-resistant passkeys.
For organisations still relying on SMS or voice MFA, now is the time to review authentication policies, device readiness and user adoption plans.
Imagine securing your office with a key that works, but can be copied more easily than newer alternatives. That is essentially where SMS-based MFA finds itself today.
While SMS and voice authentication remain significantly more secure than passwords alone, attackers have become increasingly sophisticated. AI-powered phishing campaigns, social engineering attacks and account takeover attempts are making it easier to trick users into handing over authentication codes or approving access requests.
Microsoft’s response is to move customers away from authentication methods that can be intercepted, shared, or manipulated, and towards phishing-resistant alternatives. The goal isn’t simply stronger security, but reducing opportunities for human error.
Passkeys are becoming the new standard
Starting from 1 September 2026, passkeys will become the default authentication experience for users currently using SMS or voice authentication within Microsoft Entra.
Instead of entering passwords or waiting for a text message with a code, users verify their identity using:
Think of a passkey like having a house key that is designed to work only with you. Rather than relying on a code sent across a network, passkeys use cryptographic credentials securely stored on a trusted device.
For users, authentication becomes quicker and more seamless. And for organisations, it becomes significantly harder for attackers to compromise accounts through phishing attacks.
Although February 2027 may feel a long way off, the reality is that authentication projects rarely happen overnight.
Most organisations still have users who rely heavily on SMS-based authentication, and moving to passkeys isn’t simply a technical change. It requires planning, communication and user adoption.
A good starting point is to answer four questions:
1. How many users still rely on SMS or voice MFA?
Understanding the scale of the challenge will help determine the effort required.
2. Are your devices ready?
Not all devices and user scenarios support modern authentication methods in the same way.
3. What user training is needed?
Many employees have never used passkeys before.
4. Do you have a migration strategy?
Organisations that start early can introduce changes gradually rather than rushing to meet Microsoft’s deadline.
One important point to note: Microsoft has stated there is no opt-out from this migration, meaning organisations should begin preparing now rather than waiting until the final stages.
This change is about more than replacing one MFA method with another. Many organisations discover that authentication is only one part of a broader cyber security conversation.
Areas worth reviewing include:
For many organisations, preparing for the move to passkeys highlights wider security considerations that may have been overlooked. Taking the opportunity to review these areas can help strengthen your overall security posture, not just your authentication strategy.
The organisations that experience the smoothest transition won’t be the ones that react closest to the deadline. They’ll be the organisations that start preparing today.
Getting users comfortable with passkeys not only helps secure the business, it can also encourage stronger security habits in employees’ personal lives.
Microsoft’s MFA changes are a reminder that cyber security is constantly evolving. What was considered best practice a few years ago may no longer offer the same level of protection today.
Bistech’s Cyber Security Health Check helps organisations identify security gaps, assess identity and access controls, review Microsoft security configurations and build a practical roadmap for improvement.
Whether you’re preparing for Microsoft’s MFA changes or reviewing your wider cyber security strategy, our experts can help you understand where you are today and what should come next.
Start with a complimentary Cyber Security Health Check today