Impact of SMS/Voice MFA Retirement – February 2027

Dino Anzellotti 0 Reputation points
2026-10-09T14:06:21.1766667+00:00

Hello,

just two questions:

  1. What happens if a user has Microsoft Authenticator or TOTP registered alongside SMS/voice authentication methods when SMS and voice are retired on February 1, 2027? Will the user be required to register a phishing-resistant method, or will Microsoft Authenticator or TOTP be sufficient?1. An user who have already registered a valid MFA method other than a passkey will still be prompted to register a passkey as a more secure authentication method (even if not mandatory)?

Thanks in advance

Dino

Microsoft 365 and Office | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-09T14:07:15.6533333+00:00

    Microsoft Authenticator push or software OATH TOTP remains sufficient for ordinary Entra MFA after February 1, 2027; a passkey becomes mandatory under the retirement enforcement only when SMS or voice is the user’s only available MFA method.

    Effect on users with multiple methods

    For a regular user who has SMS/voice plus Microsoft Authenticator push or software OATH TOTP:

    • Microsoft-provided SMS and voice stop working on February 1, 2027.
    • The registered Authenticator or TOTP method is not retired and can continue satisfying a normal MFA requirement.
    • The user is not subject to the retirement’s blocking passkey-registration requirement, because SMS/voice is not their only available MFA method. The blocking requirement is explicitly limited to users whose only available MFA method is SMS or voice.^1^

    There is an important distinction between MFA-capable and phishing-resistant:

    • Authenticator push, Authenticator OTP and software OATH TOTP can satisfy ordinary MFA.
    • They are not classified as phishing-resistant methods.
    • The built-in phishing-resistant authentication strength accepts methods such as passkeys/FIDO2, Windows Hello for Business or platform credentials, and multifactor certificate-based authentication.^2^

    Consequently, Authenticator or TOTP will not be sufficient if your organization separately applies a Conditional Access policy requiring phishing-resistant MFA. That would be a tenant policy requirement, not a direct consequence of SMS/voice retirement.

    Will those users still be prompted for a passkey?

    Yes, they may be prompted, but the normal migration prompt is not initially mandatory.

    Starting September 1, 2026, users enabled for SMS or voice are automatically enabled for passkeys and brought into a Microsoft-managed passkey registration campaign. After completing MFA, eligible users can be nudged to register a passkey—even if they already have another MFA method.^1^

    For that Microsoft-managed passkey campaign:

    • Users can select Skip for now.
    • Passkey campaigns use unlimited snoozes by default.
    • A user needs an eligible passkey profile to receive the prompt.^3^

    Therefore:

    User state Result
    Authenticator/TOTP plus SMS/voice SMS/voice stops working; Authenticator/TOTP continues for ordinary MFA; passkey nudge may appear but is normally skippable
    Only SMS/voice Blocking passkey registration after the applicable retirement date
    Authenticator/TOTP, with Conditional Access requiring phishing-resistant MFA Must register and use an allowed phishing-resistant method
    Already using a passkey, Windows Hello or another phishing-resistant method Continues using that method

    Dates and exceptions

    • February 1, 2027: retirement for most users, including internal guest users.
    • July 1, 2027: retirement for Global Administrators and external users.^4^

    Administrators should still migrate users proactively to passkeys or another phishing-resistant method. However, having Authenticator push or OATH TOTP means a user is not forced to enroll a passkey merely because Microsoft-provided SMS and voice are retired.


    References

    1. Passkeys by default and retirement of Microsoft-provided SMS and voice ...
    2. Conditional Access authentication strengths
    3. Run a registration campaign to set up a passkey or Microsoft Authenticator
    4. FAQ for Microsoft-provided SMS and voice retirement - Microsoft Entra ...
    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.