Miscellaneous topics that do not fit into specific categories.
Microsoft Authenticator push or software OATH TOTP remains sufficient for ordinary Entra MFA after February 1, 2027; a passkey becomes mandatory under the retirement enforcement only when SMS or voice is the user’s only available MFA method.
Effect on users with multiple methods
For a regular user who has SMS/voice plus Microsoft Authenticator push or software OATH TOTP:
- Microsoft-provided SMS and voice stop working on February 1, 2027.
- The registered Authenticator or TOTP method is not retired and can continue satisfying a normal MFA requirement.
- The user is not subject to the retirement’s blocking passkey-registration requirement, because SMS/voice is not their only available MFA method. The blocking requirement is explicitly limited to users whose only available MFA method is SMS or voice.^1^
There is an important distinction between MFA-capable and phishing-resistant:
- Authenticator push, Authenticator OTP and software OATH TOTP can satisfy ordinary MFA.
- They are not classified as phishing-resistant methods.
- The built-in phishing-resistant authentication strength accepts methods such as passkeys/FIDO2, Windows Hello for Business or platform credentials, and multifactor certificate-based authentication.^2^
Consequently, Authenticator or TOTP will not be sufficient if your organization separately applies a Conditional Access policy requiring phishing-resistant MFA. That would be a tenant policy requirement, not a direct consequence of SMS/voice retirement.
Will those users still be prompted for a passkey?
Yes, they may be prompted, but the normal migration prompt is not initially mandatory.
Starting September 1, 2026, users enabled for SMS or voice are automatically enabled for passkeys and brought into a Microsoft-managed passkey registration campaign. After completing MFA, eligible users can be nudged to register a passkey—even if they already have another MFA method.^1^
For that Microsoft-managed passkey campaign:
- Users can select Skip for now.
- Passkey campaigns use unlimited snoozes by default.
- A user needs an eligible passkey profile to receive the prompt.^3^
Therefore:
| User state | Result |
|---|---|
| Authenticator/TOTP plus SMS/voice | SMS/voice stops working; Authenticator/TOTP continues for ordinary MFA; passkey nudge may appear but is normally skippable |
| Only SMS/voice | Blocking passkey registration after the applicable retirement date |
| Authenticator/TOTP, with Conditional Access requiring phishing-resistant MFA | Must register and use an allowed phishing-resistant method |
| Already using a passkey, Windows Hello or another phishing-resistant method | Continues using that method |
Dates and exceptions
- February 1, 2027: retirement for most users, including internal guest users.
- July 1, 2027: retirement for Global Administrators and external users.^4^
Administrators should still migrate users proactively to passkeys or another phishing-resistant method. However, having Authenticator push or OATH TOTP means a user is not forced to enroll a passkey merely because Microsoft-provided SMS and voice are retired.
References