BIP America

collapse
Home / Daily News Analysis / Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop

Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop

Aug 14, 2026  Twila Rosenbaum  5 views
Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop

Microsoft has issued a clear directive to IT administrators around the world: the era of SMS and voice-based authentication is coming to an end. The company announced that Entra ID tenants will be transitioned to passkeys, and by February 1, 2027, SMS and voice authentication will be fully retired. The reason for this shift is equally clear: AI-powered phishing has made traditional phone-based verification methods far too dangerous to trust.

Key facts

  • Microsoft is retiring SMS and voice authentication for Entra ID.
  • Starting September 1, users who rely on SMS or voice authentication will be prompted to set up a passkey during sign-in.
  • February 1, 2027 is the hard retirement deadline for SMS and voice authentication.
  • There is no opt-out; every Entra ID tenant will be affected.
  • AI-powered phishing and SIM swapping are the primary reasons for the change.
  • Personal Microsoft accounts are also being moved away from SMS for authentication and account recovery.

Why SMS authentication is no longer safe

For years, SMS-based two-factor authentication was considered a basic but acceptable security option. A code sent to your phone added a second layer beyond your password. However, that layer has become increasingly brittle. Attackers have learned how to intercept SMS messages, trick mobile carriers into transferring phone numbers to attacker-controlled SIM cards, and use social engineering to convince victims to share their codes. SIM swapping, in particular, has grown easier as AI tools help attackers gather personal information and craft convincing stories.

Microsoft specifically cited the rise of AI-driven attacks targeting passwords and MFA codes. These attacks are more successful than older phishing attempts because they can be automated and personalized at scale. AI can generate realistic text messages, emails, and voice calls that imitate legitimate businesses. It can also analyze stolen data to make phishing messages more convincing. In this environment, even a second factor delivered by SMS or voice can be compromised.

The passkey alternative

Passkeys are a phishing-resistant alternative to passwords and one-time codes. Instead of relying on something you know, passkeys use cryptographic key pairs. One private key remains on your device, and a public key is stored on the service. When you sign in, the device proves possession of the private key through a secure challenge. This design makes phishing ineffective because the authentication is tied to the exact website or app you are trying to access.

Microsoft, alongside other tech companies, has been pushing passkeys for several years as part of the FIDO2 standard. Passkeys can be synced across devices through major platforms, making them convenient and portable. Microsoft Authenticator also supports passkey management and can be used as a companion for cross-device sign-ins. For organizations, passkeys reduce the risk of credential theft and account takeover while simplifying the user experience.

What the timeline means for enterprises

The September 1 date is important for administrators. On that date, Entra users who still have SMS or voice authentication enabled will see prompts asking them to set up a passkey during sign-in. This is not a hard failure, but it is a strong nudge. Microsoft is encouraging tenants to proactively remove SMS and voice authentication from their conditional access policies and authentication methods.

After that, February 1, 2027 is the definitive deadline. Microsoft will retire SMS and voice authentication for Entra ID entirely. Any user who has not enrolled a passkey or another phishing-resistant method will need to do so. The company has emphasized that this will apply to every tenant, with no exceptions. Enterprise administrators should begin planning now, including inventorying users who currently rely on SMS codes or voice calls for MFA.

Why the timeline spans several years

Migrating an entire identity platform is not something that happens overnight. Microsoft has provided years of lead time so organizations can update their security posture, train users, and deploy new hardware or software. The two-step timeline allows for a gentle transition: first prompting users to create passkeys, then eventually removing the old methods.

This approach is similar to earlier passwordless initiatives. Microsoft has gradually expanded passwordless sign-in options for years, allowing users to remove passwords entirely. The company has also introduced passkey support in Windows, Edge, and mobile apps, making it easier for users to adopt the new system. The multi-year timeline gives enterprises a clear path while still maintaining pressure to move quickly.

Personal Microsoft accounts are affected too

The shift is not limited to enterprise customers. Microsoft has already begun phasing out SMS for authentication and account recovery on personal accounts used for Outlook, Xbox, and Windows 11. The company has not confirmed a specific deadline for regular consumers, but the direction is unmistakable. Anyone using a personal Microsoft account should expect SMS codes to become less common over time.

For consumers, the transition to passkeys can be as simple as using Windows Hello, a phone's built-in biometrics, or Microsoft Authenticator. Those methods are not only more secure but also faster than typing in a six-digit code. Users who still rely on SMS as a recovery method should consider switching to an alternative before they are forced to.

AI-powered phishing is the real threat

AI has changed the phishing landscape. Attackers can now create highly convincing emails, text messages, and voice simulations that are hard for ordinary people to distinguish from legitimate communications. AI can also automate the process of gathering personal details from social media and data breaches, allowing attackers to target individuals with personalized messages.

Microsoft has observed a sharp increase in AI-driven attacks that target passwords and MFA codes. These attacks are more likely to succeed because they are harder to spot and can be delivered at scale. A user might receive an email that appears to be from their IT department, asking them to verify their account by replying with a code. That code might be captured and used within minutes by an attacker.

The phrase "AI isn't hacking your SIM card directly" is an important nuance. The technology does not need to break into the telecom infrastructure. It only needs to trick a human into revealing a code or approving a login request. Passkeys close that gap by making authentication impossible to intercept or replay.

What administrators should do now

Administrators should begin by reviewing their authentication methods in Entra ID. Identify which users are still using SMS or voice codes and understand why. Check conditional access policies and legacy authentication settings to ensure there are no hidden dependencies. Then start piloting passkey enrollment with a small group of users, especially those in high-risk roles.

Communication is also important. Users need to understand why SMS codes are being removed and how to set up passkeys or Microsoft Authenticator. Providing clear guidance before the September 1 prompt appears can reduce confusion and support tickets. After deployment, monitor sign-in logs to ensure that passkeys are working correctly and that no users are being locked out.

The broader move toward passwordless

This announcement should be seen as part of a broader industry movement. Passwords are increasingly seen as the weakest link in security. They can be stolen, reused, phished, and cracked. Passwordless authentication eliminates the shared secret entirely. Instead of transmitting a password or code, the user's device proves identity through cryptography.

Yubikeys, Windows Hello, Apple Face ID, and Google's passkey system are examples of this approach. Microsoft's push to retire SMS and voice authentication is a sign that passwordless technology has matured enough to be adopted as a default. The integration of passkeys into browsers and operating systems has removed many of the friction points that slowed earlier adoption.

For administrators, the move to passkeys is not a punishment. It can reduce the cost of helpdesk calls for password resets and account recovery. It can also improve the user experience by letting people sign in with a fingerprint or face scan instead of remembering multiple codes.

What happens next

Between now and September 1, Microsoft is likely to release additional guidance and tools to help tenants make the transition. The company has already built passkey management into Microsoft Authenticator and Windows, so most users will have a straightforward path forward. IT teams should test their critical applications with passkey authentication to ensure compatibility, especially line-of-business apps that may have older sign-in flows.

At home, users should also take advantage of passkeys for their personal Microsoft accounts. Windows 11 users can set up Windows Hello with a PIN, fingerprint, or face recognition. Outlook and Xbox accounts can be protected using Microsoft Authenticator. These changes are not difficult, and they provide immediate protection against phishing attempts that would previously trick users into handing over passwords and codes.

The retirement of SMS and voice authentication for Entra ID is a decisive step in the fight against AI-driven phishing. With the September 1 prompt and the February 1, 2027 deadline, Microsoft has given every organization a clear timetable and ample warning. The time to act is now, before the era of phone-based codes officially ends.


Source: Digital Trends News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy