Goodbye, text authentication! It's time to move to phishing-resistant authentication.
Microsoft is making sign-ins more secure against phishing attempts, by retiring SMS and phone-call verification, and moving exclusively to passkey sign-in using the authenticator app.
Microsoft-provided SMS and voice authentication will be retired on 1 February 2027, but you may start seeing prompts from Microsoft from September 2026 asking you to set up the authenticator app.
Here’s what you need to know:
What you need to do if you use SMS or phone calls for MFA:
Watch for notifications from Microsoft about this change.
Follow the instructions in those notifications to set up a passkey when prompted.
Complete the setup as soon as possible to avoid being prevented from signing in.
You may start seeing prompts from Microsoft from 1 September 2026.
If you do not use SMS or phone calls for MFA, you do not need to take any action.
Important dates
From 1 September 2026
You will be prompted by Microsoft notifications to register a passkey when completing MFA.
1 February 2027
Microsoft will stop providing SMS and voice authentication. Anyone who only has SMS or voice available will be required to set up a passkey before they can sign in.
What should you expect?
You may receive emails and/or see prompts from Microsoft asking you to set up a passkey. Please do not ignore these notifications. Follow Microsoft's instructions and complete the setup when prompted.
Contact AQUA if you have any questions or concerns.
We're here to keep your IT Stress-Free 😌

