Microsoft is phasing out text message and voice login codes for Microsoft 365 business accounts, nudging users onto passkey login instead.
The change has just started rolling out. It’s a gradual change, with SMS and voice code options to be fully retired by 1st February 2027.
What’s changing and why
From 1st September, anyone on a Microsoft 365 business account currently using SMS or voice codes for multi-factor authentication will be automatically enrolled into a passkey profile.
The next time the user signs in, they’ll be prompted to set up a passkey. It’s a soft switch for now, as users can snooze the prompt for later.
The hard deadline is 1st February 2027, when Microsoft will fully retire SMS and voice codes. If one of these codes is someone’s only login option at that point, they will be required to set up a passkey with no snooze or opt-out option.
Microsoft’s stated reason is phishing resistance. SMS-based authentication can be intercepted with spoofing and SIM-swap attacks.
Time-based one-time password authenticators will continue to be available.
Who it affects
Personal account users are not affected. This change is for Microsoft 365 for Business, Enterprise, and Education accounts.
If you or your staff log into a work account like email, Teams, or SharePoint with text message codes, this change will affect you.
For small business owners, this is worth making clear to staff ahead of the hard deadline. Small businesses often run without dedicated IT support, and a hard passkey prompt might cause confusion.
What to do about it
It’s easiest to set up a passkey ahead of time rather than waiting for the notification or snoozing it forever.
Check over your account’s security settings, choose passkey or “sign in without a password” and confirm it with biometrics or PIN.
If you haven’t made the switch yet, our passkeys FAQ talks about creating one and using it across devices, while our passkeys versus passwords guide shows why passkeys are worth using for business and personal accounts alike.
For more detailed information about the switch from an admin perspective, here’s Microsoft’s post.









Comments