If your team gets a six-digit code by text message or an automated phone call when they log in to Microsoft 365, this one’s for you.
Microsoft has notified every Entra ID tenant: text message and phone call verification are being retired. Passkeys become the default. The announcement was short. The timeline is not generous.
One thing this isn’t about: your copier, your alarm system, or the software that emails your invoices. Those send mail a different way, and Microsoft is changing that separately — we covered it in What’s Sending Mail Through Your Microsoft 365 Tenant. Same vendor, same year, two unrelated projects. Don’t let one distract you from the other.
The dates
September 1, 2026. Anyone using text or phone verification gets automatically enabled for passkeys and starts seeing a prompt to set one up. It’s a nudge, not a wall — people can dismiss it and carry on.
February 1, 2027. Microsoft stops delivering codes by text and phone. The method is gone.
After that. Anyone whose only verification method was text or phone hits a blocking prompt. No sign-in until they register something else. Microsoft has said plainly there is no opt-out and no exceptions — this one applies to every tenant.
Five months of runway — and the first prompts land this month, which means your team will have questions before you’ve finished planning the answer.
Why texts were always the weak link
Getting a code by text feels secure. It stopped being secure a while ago.
Three things go wrong. Someone calls your mobile carrier, impersonates you well enough, and moves your number to their own SIM card — now your codes arrive on their phone. Or you land on a login page that looks exactly like Microsoft’s, type your code in, and the attacker relays it to the real site within seconds. Or the message is simply intercepted in transit, which is easier than it should be.
All three work because a texted code is just a number. It doesn’t know which website asked for it, and it doesn’t care who types it in.
A passkey does. It’s tied to the actual site that issued it, so a fake login page has nothing to collect — there’s no code to hand over. That’s the whole reason Microsoft is moving.
What your people will use instead
A passkey. Face, fingerprint, or device PIN — the same gesture that unlocks the phone. Nothing to read off a screen and nothing to type. This is Microsoft’s recommendation and the strongest of the options.
The Microsoft Authenticator app. Signing in shows a two-digit number on screen; you type it into the app to approve. Roughly three seconds. Worth knowing: the Authenticator app is not affected by this change. If your team is already approving sign-ins there, they’re fine.
Most people land on one of these in under two minutes, once. Then it stops being something they think about.
Who this gets awkward for
Both options assume a phone. Not everyone has one at work.
Front desk and shift logins that several people share. Shop floor and warehouse terminals. Drivers and field techs on flip phones. Anyone who won’t install a work app on a personal device — a conversation that has nothing to do with technology and everything to do with how it gets asked.
These are solvable. Hardware security keys, dedicated devices, restructuring a shared login into individual ones. What they aren’t is solvable in the week before the deadline, which is the actual argument for starting now.
You can keep text messages. You probably shouldn’t
There is an escape hatch. Microsoft is retiring its own text and phone delivery, not the concept — you can bring your own telecom provider through the Microsoft Security Store and keep sending codes. Microsoft publishes provider pricing starting September 18 and opens configuration October 30.
This exists for organizations with a regulatory or contractual requirement to offer phone-based verification. If that’s you, you know it already.
For everyone else it’s paying a monthly bill to keep the least secure option on the menu. It also doesn’t buy time — it buys permanence, on the method attackers have gotten best at. Skip it.
What to do now
Find out who’s still on text or phone. Not from memory — from the tenant. It’s a report your IT provider can pull in a few minutes, and the number is usually higher than anyone guesses.
Handle the awkward accounts first. Shared logins, no-smartphone staff, anything on a shop floor. These take the longest and they don’t get easier in January.
Move everyone else in batches. A department at a time, on a normal Tuesday, with somebody available to answer questions. This is a two-minute task per person when it’s scheduled and a support ticket when it’s a surprise.
Tell your team before Microsoft does. Microsoft’s prompts start appearing this month. An unexplained security prompt from Microsoft is indistinguishable from a phishing attempt, and the right instinct — not clicking it — works against you here.
The bottom line
Text-message codes stop working February 1, 2027, and there’s no version of this where you opt out. The only real decision is whether your people move on a schedule you set or on the morning they can’t log in.
If you’re a K&J client, we’re already working through this across the environments we manage and we’ll be in touch with a plan for your team. If you’re not and you’d like to know how many of your users are still on text verification, reach out — it’s a quick look and you’ll have the number either way.
Sources

