Your input shapes our product. Suggest a feature now →
  1. Home
  2. Alerts
  3. SMS MFA Retirement (MC1426371)

Microsoft 365 Is Retiring SMS and Voice MFA: What Admins Must Do

Published: August 2026. Source: Microsoft Learn: SMS and Voice Retirement (MC1426371) / Microsoft 365 Message Center MC1426371 archive

February 1, 2027. That is the date Microsoft will stop providing SMS verification codes and voice call authentication for Microsoft 365 sign-in. The change, announced via MC1426371, affects every tenant where any user's only MFA method is a phone number rather than the Microsoft Authenticator app or a passkey.

For SharePoint Online, where authentication flows through Microsoft Entra ID, this means users who have not registered a non-telephony MFA method will face a blocking prompt at sign-in and will be unable to reach any SharePoint site, team, or document until they register a passkey or authenticator app.

What MC1426371 announces

The announcement has two parts. First, passkeys (FIDO2 and device-bound credentials) will be automatically enabled for eligible users starting September 1, 2026. Microsoft will set the passkey Registration Campaign to a "Microsoft Managed" state, which means users see a prompt to register a passkey during their next MFA sign-in. The prompt can be dismissed, but it will recur.

Second, Microsoft-provided SMS and voice call authentication will be retired on February 1, 2027. After that date, users who rely on Microsoft's telephony infrastructure for MFA will hit a blocking prompt at sign-in if they have no other authentication method registered. The block is not permanent: the user can register a passkey or authenticator app in the same session, but anyone who has not been prepared for this will experience an unexpected disruption.

"Users whose only available MFA method is SMS or voice will be required to register a passkey during sign-in after the retirement date. This prompt will be blocking." - Microsoft documentation for MC1426371.

Key dates for Microsoft 365 admins

DateWhat changesAdmin action
September 1, 2026 Passkeys automatically enabled for eligible users; Registration Campaign set to Microsoft Managed No action required to enable; users will start seeing passkey registration prompts
October 30, 2026 Customer-managed telecom provider option available in the Microsoft Security Store Configure a provider if you need to retain SMS for specific user groups beyond February 2027
February 1, 2027 Microsoft-provided SMS and voice authentication retired permanently All users must have a non-telephony MFA method registered before this date

How to identify users affected by the SMS MFA retirement

The first task is finding every user whose only registered MFA method is SMS or voice. Microsoft Entra ID surfaces this through the Authentication methods activity report, available under Protection > Authentication methods > Activity in the Entra admin center.

Filter the report for users who have a telephony method registered but no authenticator app and no passkey. That filtered list is your remediation scope. For large tenants, the bulk export option produces a CSV with one row per user and one column per registered method, making it straightforward to identify SMS-only accounts with a filter or pivot.

Microsoft's own guidance recommends completing user migration at least four weeks before February 1, 2027, to allow time for testing and to handle exceptions before the blocking enforcement is active.

What to do once you have the list

  1. Run a targeted Registration Campaign. You can scope the Registration Campaign setting in Entra ID (Authentication methods > Registration campaign) to a specific group rather than all users. Target only the SMS-only users identified in the report. Users in the campaign see a prompt to add a passkey or authenticator app; users who respond complete the migration themselves without helpdesk involvement.
  2. Communicate the change to end users four to six weeks early. Users who encounter a blocking passkey registration prompt for the first time on February 1, 2027 without prior warning will generate helpdesk tickets. A brief communication explaining the change, with a short guide to setting up the Microsoft Authenticator app, significantly reduces that spike.
  3. Decide now about users who genuinely need SMS. Frontline workers on shared kiosks, contractors without smartphones, or any account type where passkeys and authenticator apps are impractical need a different path. Configure a customer-managed telecom provider through the Microsoft Security Store before October 30, 2026. This keeps SMS available for those accounts at your cost after the retirement date.

As you work through authentication readiness across your tenant, pair this review with a broader look at who holds SharePoint access. The external user audit guide covers identifying guest accounts that may also be caught by Entra authentication changes, and the guide to finding sites without an owner helps confirm every site has a responsible admin who can support users through the transition.

Frequently Asked Questions

What is MC1426371?

MC1426371 is the Microsoft 365 Message Center post announcing that Entra ID will make passkeys the default sign-in method from September 1, 2026, and will retire Microsoft-provided SMS and voice call authentication on February 1, 2027. Admins should use the Authentication methods activity report in Entra ID to identify which users rely solely on SMS or voice, then migrate them to passkeys or the Microsoft Authenticator app.

Will my SharePoint users lose access on February 1, 2027?

Users with at least one non-telephony method registered (Microsoft Authenticator, passkey, or OATH token) are not affected. Users whose only method is SMS or voice will hit a blocking passkey registration prompt at sign-in. They can complete registration in the same session and continue, but they will not be able to skip it or reach SharePoint Online until they do.

What if some users genuinely need SMS authentication?

From October 30, 2026, tenants can configure a customer-managed telecom provider in the Microsoft Security Store. Tenants that configure a provider can continue offering SMS at their own cost after February 2027. Tenants that do not configure a provider will have Microsoft-provided SMS and voice retired entirely on that date, with no grace period.

Sources: Microsoft Learn: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication; Microsoft 365 Message Center MC1426371 (merill.net archive); MC1426371 summary (pupuweb.com).

Try ShareMaster free for 14 days