Skip to main content

MC1426371: Microsoft Retiring SMS and Voice MFA in Entra

by Ella-Louise Jain
26 August 2026

If any of your users still sign in using an SMS one-time passcode or an automated voice call, put a date in the diary: 1 February 2027.

That's when Microsoft stops providing SMS and voice as MFA methods in Microsoft Entra altogether. Microsoft announced the change in Message Center post MC1426371, and it isn't a single cut-off. It's a four-date rollout that starts far sooner than most admins expect, on 1 September 2026.

Summary

  • MC1426371: Microsoft is retiring Microsoft-provided SMS and voice as MFA methods in Microsoft Entra

  • Passkeys Default: Passkeys become the default authentication experience from 1 September 2026 -  auto-enabled for anyone currently on SMS or voice MFA

  • Hard Retirement: Microsoft-provided SMS and voice are fully retired on 1 February 2027. After that date, only a customer-configured telecom provider keeps telephony MFA working.

  • Opt-Out Window: A temporary opt-out can delay passkey enablement between September 2026 and February 2027 — but it does not extend past the February deadline.

  • Action Required: Audit who still relies on SMS or voice MFA, decide between passkeys-only or a telecom provider, and configure any telephony provider at least four weeks before the deadline.

  • Impact Rating: Admin + User Impact: High

 

What Is MC1426371 and What's Actually Changing in Entra?

Message Center post MC1426371 announces the retirement of Microsoft-provided SMS and voice MFA in Microsoft Entra, automatically enabling passkeys as the default sign-in method starting 1 September 2026.

Today, when a user in Microsoft Entra registers for MFA using SMS or a voice call, Microsoft provides that telephony service itself. It sends the text or places the call on your tenant's behalf, with no extra configuration needed. MC1426371 switches that model off.  

From September 2026, Entra treats passkeys as the default sign-in method, and it starts nudging the users who are still on SMS or voice to move off it. By February 2027, Microsoft will no longer provide the underlying SMS or voice service for MFA under any circumstance. If you still need telephony-based MFA after that date, you have to bring your own telecom provider, configured through the Microsoft Security Store.

This change impacts every user still registered for SMS or voice MFA, it changes what they see at sign-in from September, and it removes a fallback option most tenants have relied on for years.

 

When Does Microsoft Retire SMS and Voice MFA in Entra?

The Microsoft Entra SMS and voice MFA retirement follows a strict four-stage rollout schedule beginning 1 September 2026 and ending with full retirement on 1 February 2027.

Mark all four dates - the gap between the first and the last is five months, and each step narrows your options:

Date Category Milestone Action Required
1 September 2026 Enforcement Passkey Auto-Enablement & Nudge Begins: Passkeys are auto-enabled for SMS/voice users, and skippable registration and prompts appear upon sign-in. Notify end users of upcoming prompts. Use temporary opt-out via API if more runway is needed.
18 September 2026 Admin Milestone Telecom Options Published: Provider list, terms, and pricing go live in the Microsoft Security Store. Review providers if legal, regional, or device constraints require keeping SMS/voice.
30 October 2026 Admin Milestone Telecom Provider Setup Opens: Admins can select and integrate third-party telecom providers into Entra. Configure and test your chosen telephony provider. Setup should be done at least 4 weeks before February.
1 February 2027 Enforcement Microsoft Telephony Fully Retired: Native SMS and voice delivery ends completely. Migrate all remaining users to passkeys/FIDO2 or ensure your custom telecom provider is active.
After 1 February 2027 Enforcement Mandatory Block Prompts (No Opt-Out): Users on SMS/voice without a custom provider are forced to register a passkey to access their account. Helpdesk teams must assist unmigrated users facing mandatory enrollment.

 

 

Why is Microsoft Retiring SMS and Voice MFA?

Microsoft is retiring telephony-based MFA because SMS and voice rely on unencrypted telecom channels vulnerable to SIM-swapping, interception, and AI-driven Adversary-in-the-Middle (AiTM) phishing.

SMS and voice depend on shared secrets sent over public telecom networks, which makes them vulnerable to SIM-swapping, message interception, number reassignment, and social-engineering attacks. Passkeys use public-key cryptography instead, which resists all of those attack paths.

The scale of the exposure is why Microsoft is moving now rather than leaving this as an opt-in upgrade. Microsoft laid out the reasoning in its official Entra Identity Security blog post announcing the change, framing passkeys as the new default authentication experience "to help customers securely adopt AI at scale", tying the retirement to its broader AI security push, not just identity hygiene.

One practical point worth knowing: passkeys are included in every Entra plan at no extra cost, unlike Conditional Access policies to enforce MFA, which still require Entra ID P1 or P2.

 

Why Does MC1426371 Matter for Admins?

MC1426371 poses a critical administrative risk because it alters end-user sign-in behavior automatically without requiring admin opt-in.

Most Entra changes are opt-in, or they land quietly in the background with no user-facing impact. This one is different for three key reasons:

  1. It changes the sign-in experience automatically
    From September, affected users see a new passkey registration prompt without any admin action. If nobody has told them what it is, expect helpdesk tickets.

  2. The clock starts five months before the actual retirement
    Admins who wait until the new year to think about this will already be past the point where telecom providers were reviewable (18 September) and close to the point where they need to be configured (at least four weeks before 1 February, so by early January at the latest).

  3. There's no default fallback
    Unlike some Microsoft retirements where a legacy option quietly keeps working for a grace period, Microsoft-provided SMS and voice stop working outright on 1 February 2027.

Two tenants can experience MC1426371 completely differently.

A tenant that has already standardised on the Microsoft Authenticator app or FIDO2 security keys sees almost nothing change as there's no legacy SMS/voice population to migrate. A tenant where SMS or voice is still the default MFA method sees the passkey prompt hit almost everyone from 1 September, carrying real helpdesk and change-management load through to February.

 

What Should IT Admins Do Before February 2027?

To prepare for MC1426371, IT administrators must audit legacy MFA users, choose between passkeys or custom telecom providers, and update user communication before 1 September 2026.

Step 1: Audit who still relies on SMS or voice MFA

In the Microsoft Entra admin center, navigate to Identity → Users → Authentication methods → Activity to pull an authentication methods report of exactly how many users are registered for SMS or voice MFA today. Or run Microsoft's entra-sms-voice-usage-analyzer script.

 

Step 2: Decide whether to use passkeys only or move to a telecom provider

For most organisations, moving to passkeys is the stronger long-term position as they're phishing-resistant, they don't depend on a mobile signal, and Microsoft is investing in them as the default. If you have a genuine reason to keep telephony MFA, plan to configure a customer-managed telecom provider instead via Microsoft Entra admin center → Identity → Authentication methods → Policies.

Feature / Consideration Passkeys (Default) Telecom Provider (SMS/Voice)
Cost Included in every Entra plan Paid third-party service via Microsoft Security Store
Security Phishing-resistant (public-key cryptography) Vulnerable to SIM-swapping, interception, social engineering
Availability Date 1 September 2026 30 October 2026
Best For Most organisations, long term Regulatory, device, or regional constraints

 

Step 3: If keeping telephony, configure the provider early
Telecom providers become available on 30 October 2026 through the Microsoft Security Store. Microsoft recommends having it in place at least four weeks before 1 February 2027. See the Entra ID SMS & Voice MFA Retirement Migration Playbook for technical setup steps.

Step 4: Communicate before the September prompts land
Tell affected users what the passkey registration prompt is, why it's appearing, and what to do with it, before it shows up at their next sign-in on 1 September.

Step 5: Brief the helpdesk
Make sure helpdesk teams know the rollout dates and can talk users through passkey registration.

Step 6: Use the opt-out only as a bridge, not a plan
If you need more runway, the temporary opt-out delays passkey enablement, but it stops working on 1 February 2027 regardless.

 

How does MC1426371 Fit Microsoft's Broader Identity Security Push?

MC1426371 is part of Microsoft's systemic shift toward passwordless, phishing-resistant identity security, following the deprecation of Basic Authentication and legacy protocols.

Microsoft has been steadily narrowing the gap between "legacy" and "unsupported" across identity: Basic Authentication is gone, legacy protocols keep getting switched off, and now telephony MFA is being retired as a Microsoft-provided service entirely.

Organisations that treat 1 September 2026 as the actual deadline, not 1 February 2027, are the ones that get through this without disruption. We tracked this broader trend recently in our breakdown of 5 Microsoft 365 Security and Governance Changes IT Teams Need to Know.

If you want a system that catches changes like MC1426371 the moment they land in Message Center, instead of finding out when users start losing access, ChangePilot is built for exactly that.



Frequently Asked Questions

What does MC1426371 say?
MC1426371 is the Microsoft Message Center post announcing that Microsoft Entra will make passkeys the default authentication method and retire Microsoft-provided SMS and voice MFA. The Admin and User Impact is rated High.

When does Microsoft stop providing SMS and voice MFA?
The retirement completes on 1 February 2027. The rollout starts on 1 September 2026, when passkeys are automatically enabled for anyone currently on SMS or voice MFA.

Will my users lose MFA access on 1 February 2027?
Only if you haven't configured an alternative, users who have registered a passkey will be unaffected. Users who still need telephony-based MFA will lose access unless you've configured a customer-managed telecom provider through the Microsoft Security Store before the deadline.

Do we have to move to passkeys?
No. If you have a valid reason to keep telephony-based MFA, you can configure a customer-managed telecom provider from 30 October 2026 onward.

What should admins do right now?
Audit which users are currently registered for SMS or voice MFA, decide whether you're moving to passkeys only or keeping telephony via a third-party provider, and communicate the change to users and helpdesk before 1 September 2026.

Closing

MC1426371 is one of the Message Center changes that decides for you automatically, starting 1 September 2026, whether you've reviewed it or not. The organisations that come through it cleanly are the ones auditing their usage now, deciding on passkeys or a telecom provider before the September prompts land, and treating the four-month gap to February as testing and communication time, not slack.

ChangePilot surfaces every M365 change that matters, tailored specifically to your tenant profile. Sign up to the ChangePilot Bulletin here.

 

Comments