Skip to the content
  • Why Vertex
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Startups, Scaleups & FinTechs
    • Small & Medium Enterprises
    • Expertise in Education
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • Tools
    • Cyber Budget Planner
    • SME Cyber Cost Calculator
  • News
  • Contact
  • Why Vertex
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Startups, Scaleups & FinTechs
    • Small & Medium Enterprises
    • Expertise in Education
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • Tools
    • Cyber Budget Planner
    • SME Cyber Cost Calculator
  • News
  • Contact
LOG IN

Microsoft Is Retiring SMS and Voice Authentication: Why Moving to Passkeys Is a Crucial Upgrade for Your Security

In a major step forward for global digital security, Microsoft has announced that it will be retiring telecommunications-based authentication, specifically SMS text messages and automated voice calls, across Microsoft Entra ID and Microsoft 365 environments.

For many years, security professionals at Vertex have advocated for phishing-resistant authentication methods. We are thoroughly pleased to see industry leaders phasing out legacy verification options that no longer provide adequate protection against modern cyber threats.

If your organisation currently relies on SMS or voice calls for verification, now is the ideal moment to evaluate your authentication methods and prepare for a seamless transition to more resilient controls such as passkeys.

Why Are SMS and Voice Authentication Being Retired?

While receiving a six-digit code via text message or telephone call was once considered a vast improvement over standard passwords, the threat landscape has evolved significantly. Sophisticated attack techniques now routinely bypass telecommunications-based verification.

There are several vulnerabilities associated with legacy options:

  • Phishing and Adversary-in-the-Middle Attacks: Attackers can deploy automated tools that intercept SMS codes in real time as users type them into deceptive login pages.
  • SIM-Swapping Techniques: Criminals can trick mobile network operators into transferring a victim’s phone number to a secondary SIM card owned by the attacker, effectively hijacking incoming security codes.
  • Replay Attacks: Intercepted codes can be captured and reused rapidly before their validity period expires.

Because of these persistent vulnerabilities, SMS and voice verification provide significantly weaker protection compared to modern alternatives.

Understanding the Microsoft Retirement Timeline

Microsoft is introducing this transition progressively to give organisations sufficient time to update their security practices. The key dates to keep in mind include:

  • 1 September 2026: Users enabled for SMS or voice verification will automatically have passkey authentication enabled. During their next login prompt, users will be invited to register a passkey.
  • 1 February 2027: Microsoft-provided SMS and voice delivery will be fully retired within Microsoft Entra ID. After this deadline, users whose sole authentication method remains SMS or voice will encounter a mandatory prompt requiring them to register a passkey before continuing.

Organisations using customer-managed telecommunication providers configured through the Microsoft Security Store will not be affected by the retirement of Microsoft-provided delivery, though evaluating phishing-resistant alternatives remains highly recommended.

What Are Passkeys and How Do They Protect You?

Passkeys represent the modern gold standard for secure login procedures. Built upon open standards established by the Fast Identity Online Alliance and the World Wide Web Consortium, passkeys replace traditional credentials with public-key cryptography.

When a user authenticates with a passkey, the private key remains safely stored on their personal device or hardware security token, while only the public key is registered with the service.

Passkeys provide enhanced defence because they are cryptographically bound to the legitimate website address. Even if an employee is tricked into visiting a sophisticated fake login page, the browser or operating system will recognize the mismatch and refuse to share the passkey credentials. This structural design effectively neutralises standard phishing attempts.

Practical Steps to Enhance Your Organisation Authentication Security

Rather than waiting for automatic prompts, taking early control of your authentication strategy can help ensure minimal disruption to daily operations.

Audit Your Current User Base

Consider performing an immediate review of your Microsoft Entra ID directory to identify which users or department groups currently depend on SMS or voice call verification.

Formulate a Transition Strategy

Begin testing passkeys and FIDO2-compliant hardware security keys within designated focus groups. Evaluating how passkeys interact with your current device management policies helps smooth out potential friction before full deployment.

Deliver Proactive Guidance

Communicating upcoming security improvements early helps build user confidence. Clear instructions regarding why passkeys are being introduced and how employees can register their devices ensure a positive user experience.

Review Specific Operational Needs

If your organisation operates under unique regulatory frameworks that explicitly require traditional telecom delivery, investigate customer-managed telecom integrations available through the Microsoft Security Store ahead of the configuration deadlines.

Strengthen Your Security Posture with Vertex

At Vertex, we have championed phishing-resistant multi-factor authentication for ten years, and we welcome Microsoft’s decision to make passkeys the default standard. Moving away from legacy authentication is one of the most effective measures an organisation can implement to mitigate credential compromise.

Navigating identity platforms and establishing tailored security controls can be a complex process. If you would like professional guidance on migrating your team to passkeys or evaluating your overall security posture, contact the expert team at Vertex Cyber Security today, or visit the Vertex website to discover how our services can assist your business.

CATEGORIES

Uncategorised

TAGS

cyber security - Microsoft Entra ID - multi-factor authentication - Passkeys - Phishing-Resistant MFA

SHARE

SUBSCRIBE

PrevPreviousThe Island Mentality Fallacy: Why Australian Organisations Are Targeted by Cyber Attacks and Paying Millions in Ransoms

Follow Us!

Facebook Twitter Linkedin Instagram
Cyber Security by Vertex, Sydney Australia

Your partner in Cyber Security.

Terms of Use | Privacy Policy

Accreditations & Certifications

iso27001-certified
blank
iso277001-certified
blank
blank
blank
  • 1300 229 237
  • Suite 10 30 Atchison Street St Leonards NSW 2065
  • 477 Pitt Street Sydney NSW 2000
  • 121 King St, Melbourne VIC 3000
  • Lot Fourteen, North Terrace, Adelaide SA 5000
  • Level 2/315 Brunswick St, Fortitude Valley QLD 4006, Adelaide SA 5000

(c) 2026 Vertex Technologies Pty Ltd (ABN: 67 611 787 029). Vertex is a private company (beneficially owned by the Boyd Family Trust).

download (2)
download (4)

We acknowledge Aboriginal and Torres Strait Islander peoples as the traditional custodians of this land and pay our respects to their Ancestors and Elders, past, present and future. We acknowledge and respect the continuing culture of the Cammeraygal people of the Eora nation and their unique cultural and spiritual relationships to the land, waters and seas.

We acknowledge that sovereignty of this land was never ceded. Always was, always will be Aboriginal land.