Move Beyond SMS and Voice Authentication

Prepare your organization for changes to SMS and voice authentication by adopting phishing-resistant sign-in methods and resilient recovery processes.

  • Inventory every system and account that still relies on SMS or voice for MFA.
  • Prioritize passkeys or FIDO2 security keys for administrators and high-risk users.
  • Treat authenticator app codes as an interim improvement, not the strongest end state.
  • Protect MFA reset and recovery workflows as carefully as the sign-in process.
  • Track exceptions with an owner and a target date for remediation.

SMS text messages and phone calls have long been familiar ways to deliver one-time passcodes for multi-factor authentication (MFA). They are easy to explain, work on nearly any phone, and can be useful as a temporary enrollment or recovery option.

They are also increasingly poor choices for protecting business accounts. Attackers can target phone numbers through social engineering, SIM-swapping, call forwarding, malicious mobile apps, and convincing fake sign-in pages. A user who reads a code from a text message and enters it into a fraudulent website may unintentionally give an attacker exactly what they need.

At the same time, identity providers, software vendors, and carriers continue to change which authentication methods they support and how they treat SMS and voice. Organizations should not assume that a current phone-based MFA process will remain their preferred long-term option. The right response is not to wait for a deadline. It is to build a practical plan to move users toward phishing-resistant authentication now.

Microsoft has now formally announced the retirement of Microsoft-provided SMS and voice authentication in Microsoft Entra ID as part of its broader move to phishing-resistant authentication. Beginning September 1, 2026, passkeys will become the default authentication experience, and users currently relying on SMS or voice authentication will be prompted to register a passkey. Microsoft-provided SMS and voice authentication services will be fully retired on February 1, 2027. Organizations that still require phone-based authentication after that date will need to configure a customer-managed telecom provider through the Microsoft Security Store. Microsoft cites the growing threat of phishing, SIM-swapping, adversary-in-the-middle attacks, and other social engineering techniques as key drivers behind this change, reinforcing the industry-wide shift toward stronger authentication methods such as passkeys, Windows Hello for Business, and FIDO2 security keys.

What phishing-resistant authentication means

Phishing-resistant authentication is designed to prevent a user from authenticating to a fake website, even if that site looks convincing. The method binds the sign-in process to the legitimate service or domain rather than asking the user to copy a reusable or one-time code into a webpage.

Common examples include:

  • Passkeys, which can use a device's built-in biometric or device PIN
  • FIDO2 security keys, including USB, NFC, or Bluetooth hardware keys
  • Certificate-based authentication in appropriate managed-device environments

These methods are different from simply using an authenticator app. Time-based codes generated by an app are generally more secure than SMS because they are not delivered through the phone network. However, users can still be tricked into entering those codes on a fraudulent sign-in page. Push notifications can also be vulnerable to repeated approval prompts, often called MFA fatigue.

For many small and midsize organizations, passkeys and FIDO2 security keys provide the most practical path to stronger authentication. The best fit depends on your identity platform, endpoint management, workforce, applications, and recovery requirements.

Why SMS and voice create business risk

Phone-based MFA is not automatically unsafe, but it has weaknesses that are difficult for an organization to control. The phone number is often treated as the identity anchor, even though mobile carriers, personal devices, and end users all influence its security.

A typical attack can unfold quickly. An attacker obtains a user's password through a phishing email, password reuse, or a breached third-party service. The attacker then sends the user to a replica of the real sign-in page. When the user receives an SMS code and enters it into the fake site, the attacker can use that code in real time to access the account.

Voice calls present similar risks. They can be redirected, intercepted through account takeover, or exploited through social engineering. They also create accessibility and support challenges when employees travel, change numbers, have limited mobile coverage, or use shared phone lines.

For healthcare and financial services organizations, a compromised identity can expose more than email. It may provide access to patient information, financial records, cloud files, accounting systems, payment workflows, and administrative controls. Many compliance frameworks expect organizations to use safeguards appropriate to the sensitivity of the data and systems involved. Stronger MFA is a meaningful control, but it must be implemented with governance and operational resilience in mind.

Start with an authentication inventory

Before selecting a replacement method, understand where and how people authenticate today. An inventory prevents a common mistake: securing the primary email platform while overlooking privileged accounts, remote access, legacy applications, or third-party portals.

Document the following for each critical system:

  • The identity provider or local authentication method in use
  • Whether MFA is required, optional, or unavailable
  • The factors users currently rely on, including SMS, voice, app codes, and push prompts
  • User populations, such as employees, contractors, administrators, and external partners
  • Privileged accounts and emergency access accounts
  • Device requirements and whether users have managed computers or mobile devices
  • Available recovery methods and who can approve them
  • Vendor support for passkeys, FIDO2 keys, or other phishing-resistant methods

Rank systems by business impact. Prioritize administrative accounts, email, remote access, cloud storage, financial systems, clinical applications, and systems containing regulated or confidential data. Those are the accounts attackers most often use to expand access after an initial compromise.

Choose methods for real-world users

A technically strong option is only useful if employees can adopt it consistently. Most organizations benefit from offering a primary method and a limited, controlled backup method rather than allowing every possible factor.

Passkeys can be convenient for users with managed laptops and phones. They reduce the need to type passwords and codes, and device biometrics can simplify the experience. Before deployment, confirm how passkeys are stored, synchronized, recovered, and governed when a user changes devices or leaves the organization.

FIDO2 security keys are often well suited for administrators, executives, finance staff, and users with access to sensitive systems. They provide a physical factor that can be centrally purchased, assigned, replaced, and tracked. Issuing two keys to high-risk users can reduce disruption if one is lost.

For employees who cannot use a passkey or security key immediately, an authenticator app may be an interim improvement over SMS. Treat it as a transition state, not the final destination for your highest-risk accounts. Set a clear date for reviewing exceptions and moving eligible users to phishing-resistant methods.

Build secure enrollment and recovery processes

Enrollment and account recovery are frequent weak points. An attacker who cannot defeat MFA directly may instead try to convince the help desk to reset it.

Create written procedures for enrolling, replacing, and recovering authentication factors. At minimum, define:

  • Who is authorized to approve MFA resets for standard and privileged users
  • How the support team verifies identity without relying only on a phone number or email reply
  • How replacement security keys are issued and recorded
  • Whether a waiting period or secondary approval is required for high-risk changes
  • How users report a lost device, unexpected prompt, or suspected account compromise
  • How emergency access accounts are secured, monitored, and tested

Avoid making SMS the permanent fallback for every user. A broadly available SMS fallback can undermine the protection gained from deploying a security key or passkey. Instead, use tightly governed recovery workflows and document the business reason for any exception.

Roll out in phases and measure adoption

A phased rollout lowers disruption and gives your IT team time to improve documentation and support processes. Start with a pilot group that includes IT administrators, security-conscious business leaders, and users with different device types. Test enrollment, daily sign-in, lost-device replacement, offboarding, and help-desk escalation.

After the pilot, move high-risk accounts first. Communicate in plain language: explain what is changing, why it matters, what users need to do, and where to get help. Short instructions with screenshots or a brief live demonstration are often more effective than a long policy document.

Track practical measures during the rollout:

  • Percentage of users enrolled in phishing-resistant methods
  • Number of accounts still dependent on SMS or voice
  • Exceptions, their owners, and target remediation dates
  • Authentication-related help-desk requests
  • Failed sign-ins and suspicious MFA activity
  • Completion status for privileged and high-impact application accounts

Review these measures with leadership regularly. Authentication is not only an IT setting; it is a business continuity, fraud prevention, and compliance decision.

Do not wait for a forced change

There may not be one universal date when all SMS or voice authentication options disappear. Support and policy decisions vary by vendor, service, and tenant configuration. That uncertainty is another reason to plan early rather than rely on phone-based MFA as a permanent control.

A governance-first approach is straightforward: identify dependency on SMS and voice, prioritize sensitive systems, deploy phishing-resistant methods, control recovery, and maintain a documented exception process. This gives your organization time to make thoughtful choices instead of reacting to a vendor change or an account takeover.

The goal is not to make sign-in harder for employees. It is to make it substantially harder for an attacker to impersonate them while giving your team a reliable way to support users when something goes wrong.