MSP Insights··6 min read

Microsoft is retiring SMS MFA: a passkey rollout plan for MSPs

Microsoft stops providing SMS and voice MFA in Entra from 1 February 2027. Here is a four-step passkey rollout an MSP can run across every client tenant.

By Pardeep Sharma

The short version: Microsoft is retiring its own SMS and voice MFA in Entra. From 1 February 2027, users whose only MFA method is a text or call will be forced to register a passkey before they can sign in. If you manage Microsoft 365 for clients, you have about four months to find those users, move them over and tell their owners. Start with admin accounts and your biggest tenant.

What exactly is changing, and when?

Microsoft's Entra documentation sets out three dates. From 1 September 2026, passkeys became the default sign-in experience, and users enabled for SMS or voice are automatically enabled for passkeys and nudged to register one when they sign in with MFA. On 1 February 2027, Microsoft-provided SMS and voice is retired for all users except Global Administrators and external users. For those two groups the date is 1 July 2027.

After the cut-off, a user whose only MFA method is SMS or voice must register a passkey at sign-in. Microsoft calls the prompt blocking and says there is no opt out from it. A temporary opt-out exists for the September-to-February automatic nudges only, and it does not move the February date.

Why should an MSP care now?

Because a blocked sign-in on a Monday morning lands in your queue. If 20 clients each have a handful of SMS-only users, that is a pile of simultaneous tickets in the first week of February, which is also insurance renewal season.

There is a second reason. SMS never met the Essential Eight at Maturity Level 2, where ASD expects phishing-resistant MFA. A clean passkey rollout now also moves ML2 and SMB1001 clients forward, and gives you dated evidence of the change.

Step 1: Find every SMS-only user

Microsoft publishes a PowerShell script on GitHub (the entra-sms-voice-usage-analyzer) to list users enabled for SMS or voice. It needs Global Reader, Security Reader or Authentication Policy Administrator. Run it per tenant and save the output with the date in the file name.

Sort the result into three piles:

  • Admins: most urgent. Their date is July 2027, but they hold the keys.
  • Staff with a company laptop or phone: easy. A passkey fits their devices.
  • Shared mailboxes, kiosk users, people with no smartphone: the hard ones. Plan hardware security keys or Windows Hello for these.

Step 2: Decide the passkey type per group

Microsoft supports two types. Synced passkeys live in a credential manager such as iCloud Keychain or Google Password Manager and follow the user across devices. Device-bound passkeys live on one device, such as Passkey in Microsoft Authenticator, a Windows device or a FIDO2 hardware key.

A practical rule: device-bound for admins and regulated clients, because you control where the credential sits. Synced for staff who swap phones often.

Step 3: Run a registration campaign, with warning

In the Entra admin centre, go to Authentication methods, then Registration campaign. Target the group of SMS and voice users and set the state to Microsoft Managed. The campaign prompts users to set up a passkey after their next MFA sign-in. Microsoft notes the default allows unlimited snoozes, so set an expectation with the client about a deadline.

Tell users before the prompt appears. Microsoft recommends three messages: awareness, action with steps for Windows, iPhone and Android, then a reminder. Scope them to the SMS-user group only.

For new starters and anyone locked out, use a Temporary Access Pass. It is a time-limited passcode, one hour by default, that lets the user register a passkey without needing a weaker method first. If you enforce one-time passes, the user must finish registering within 10 minutes of signing in.

Step 4: Handle the clients who say they need SMS

Some clients will have a rule that requires a text code. Microsoft's route is a telephony provider from Microsoft Security Store, with selection opening from 30 October 2026. Soprano and Telesign are the initial private-preview providers. Microsoft expects you to document the reason. Treat it as the exception and price the extra cost into the client's plan.

If you're a small business

Ask your IT provider: "Does anyone here sign in with a text message code, and what is the plan before 1 February?" Make sure the date is in the plan and that someone tells your staff what the passkey prompt will look like.

If you're an MSP

Make it a project with a start date, a fixed fee or a line in the plan, and a report at the end. The report is the product: a before and after count of SMS-only users per tenant, saved with dates. It doubles as evidence for the client's next insurance renewal or assessment. See the evidence pack for how to file it.

Worked example

A 20-person accounting firm has 18 staff signing in with Authenticator push or SMS, and two admins on SMS. In October the MSP runs the script, finds 11 SMS-only users and moves the two admins to device-bound passkeys first, using a Temporary Access Pass. It starts a registration campaign for the other nine in November, with a notice email and a one-page guide. In January it re-runs the script, confirms the count is zero and files both reports. Nothing breaks on 1 February.

Where CYBERWHITE fits

CYBERWHITE scans each client's Microsoft 365 tenant and reads the Conditional Access setup behind the Essential Eight MFA controls, so you see which clients are under their target level before you start. Where a Conditional Access MFA policy is missing, AutoFix can deploy one with a break-glass exclusion, a snapshot first and rollback available. It does not register passkeys for users. That step stays with you and the user. See MSP solutions, the free Essential 8 assessment or pricing.

Your checklist

  • Run Microsoft's SMS and voice usage script in every tenant and save the dated output.
  • Move all admin accounts to device-bound passkeys first.
  • Keep at least one monitored break-glass account.
  • Set up the Temporary Access Pass policy for onboarding and recovery.
  • Start a registration campaign for the SMS-user group.
  • Send the three user messages: awareness, action, reminder.
  • List clients that need a telephony provider and quote them.
  • Re-run the script in January and file the result.

Sources

  • Microsoft Learn: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication, Microsoft Entra ID
  • Microsoft Learn: Configure a Temporary Access Pass in Microsoft Entra ID
  • Australian Signals Directorate: Essential Eight Maturity Model, cyber.gov.au

Keep reading: Essential 8 MFA Requirements: What Counts, What Doesn't, and Phishing-Resistant MFA and The evidence problem

Frequently asked questions

When does Microsoft stop providing SMS and voice MFA in Entra?
Microsoft's documentation says Microsoft-provided SMS and voice authentication is retired on 1 February 2027 for all users except Global Administrators and external users. For those two groups the date is 1 July 2027. Internal guest users follow the February date.
What happens to a user whose only MFA method is SMS after the cut-off?
Microsoft says they must register a passkey at sign-in before they can continue. The prompt is blocking, and Microsoft states there is no opt out from that behaviour for users in scope.
Can a client keep using SMS codes?
Only through a telephony provider. Microsoft says customers with a genuine regulatory or operational need can choose a provider in Microsoft Security Store, with selection opening from 30 October 2026. Soprano and Telesign are the initial private-preview providers. Passkeys remain Microsoft's recommended path.
Does this change what the Essential Eight requires?
No. The Essential Eight is set by ASD, not Microsoft. At Maturity Level 2 and above, ASD expects phishing-resistant MFA, which SMS never met. Microsoft's change makes the move to passkeys the easier path for clients aiming at ML2.
How do we get a new or locked-out user onto a passkey safely?
Issue a Temporary Access Pass. It is a time-limited passcode that lets the user sign in and register a passkey without any weaker method. Microsoft's default lifetime is one hour, and a one-time pass must be used to finish registration within 10 minutes of sign-in.

Ready to assess your compliance?

CYBERWHITE helps Australian businesses reach Essential 8 and SMB1001 audit-readiness faster. Start with our free 5-minute assessment.