Microsoft SMS and Voice Authentication Retirement

Aug 31st, 2026

Overview

Microsoft is retiring its native SMS and voice authentication services in Microsoft Entra ID and is transitioning users toward more secure, phishing-resistant authentication methods such as passkeys, Microsoft Authenticator, Windows Hello for Business, and FIDO2 security keys. Starting September 1, 2026, eligible users may begin receiving Microsoft-managed prompts encouraging passkey registration. Beginning February 1, 2027, Microsoft-provided SMS and voice authentication services will be retired. Users who rely solely on SMS or voice authentication will need to register an alternative supported authentication method to continue signing in. 


What is Changing?

Microsoft is making passkeys the default authentication experience in Microsoft Entra ID. As part of this change:

September 1, 2026
Users enabled for SMS or voice authentication may begin receiving prompts encouraging them to register a passkey during sign in. According to Microsoft's current documentation, these prompts are intended to encourage registration and are not expected to block access.  

February 1, 2027
Microsoft-provided SMS and voice authentication services will be retired. Users whose only authentication methods are SMS or voice will be required to register a supported alternative authentication method in order to continue accessing their accounts. 


Why is Microsoft Making This Change?

SMS and voice authentication are considered vulnerable to phishing, social engineering, SIM swapping, and account takeover techniques. Microsoft and the broader industry are moving toward phishing-resistant authentication methods that provide stronger protection for user accounts. 

Examples of phishing-resistant authentication methods include:

  • Passkeys
  • Microsoft Authenticator
  • Windows Hello for Business
  • FIDO2 security keys

What is Memorial University Doing?

To prepare for this Microsoft-driven change, OCIO has:

  • Identified users who currently rely on phone-based authentication methods.
  • Restricted new SMS registrations outside of a managed legacy-user population.
  • Begun communicating directly with impacted users.
  • Developed support documentation and service desk procedures.
  • Established a process for users who require security keys or alternative authentication options. 

Frequently Asked Questions

Will I lose access to my account on September 1, 2026?

No.

Microsoft's current documentation indicates that eligible users may begin receiving prompts encouraging passkey registration beginning September 1, 2026. These prompts are intended to encourage adoption and are not expected to prevent sign in.  


Do I need to do anything right now?

If you already use Microsoft Authenticator, a passkey, Windows Hello for Business, or a FIDO2 security key, you may already have an alternative authentication method available.

If you currently use SMS or phone-call authentication, we encourage you to review the options below and ensure that you have at least one alternative authentication method available.  


What if I don't have a smartphone?

Memorial University will continue to support users who require alternative authentication options. 

Staff who cannot use a smartphone or who prefer not to use a personal mobile device may be eligible to use a FIDO2 security key.

Additional information about requesting a security key will be provided separately.


What is a Passkey?

A passkey is a modern authentication method that uses the security features built into your device rather than passwords or codes delivered by SMS.

Passkeys are designed to be resistant to phishing attacks and provide a more secure sign-in experience. 


What authentication methods are recommended?

OCIO recommends adding one or more of the following authentication methods by signing in to My Sign-Ins | Security Info | Microsoft.com with your memorial credentials:

Preferred 

  • Passkeys
  • FIDO2 Security Keys
  • Windows Hello for Business

Supported

  • Microsoft Authenticator

These methods provide significantly stronger protection than SMS or voice authentication.  


Need Help?

If you have questions about authentication methods, passkeys, Microsoft Authenticator, or security keys, please contact the OCIO Service Desk.