One Up Solutions Northwest Blog

One Up Solutions Northwest has been serving the Oregon area since 2003, providing IT Support such as technical helpdesk support, computer support and consulting to small and medium-sized businesses.

Your Employees' Text-Message Login Codes Are Going Away: What Oregon Businesses Need to Know

Your Employees' Text-Message Login Codes Are Going Away: What Oregon Businesses Need to Know

Picture this: one of your employees gets a text message that looks exactly like the login code they get every time they sign into Outlook or Teams. They type it into what they think is the Microsoft login screen. Except it isn't. It's a fake page an attacker set up an hour earlier, and the "code" just handed over access to your company's email.

This isn't a hypothetical. It's one of the most common ways businesses get broken into today, and it's a big part of why Microsoft is changing how sign-in security works for every organization that uses Microsoft 365 and Entra ID (the system behind your employee logins, previously called Azure Active Directory).

The bottom line: starting September 1, 2026, Microsoft begins automatically switching users away from text-message and phone-call login codes and toward a more secure option called a passkey. By February 1, 2027, Microsoft stops offering text and voice codes altogether. If your business relies on them today, you have a window to get ahead of this on your own terms, or Microsoft will make the change for you.

What's Actually Changing

Today, when an employee logs into Microsoft 365, they typically enter their password and then a second step, called multi-factor authentication (MFA), to prove it's really them. For a lot of businesses, that second step is a text message or phone call with a one-time code.

The problem is that text and voice codes are the weakest form of MFA available. They can be intercepted, redirected through a hijacked phone number (called a SIM-swap), or, as in the scenario above, handed straight to an attacker through a fake login page. Microsoft has been recommending against them for years, and now it's retiring the free service that delivers them.

In their place, Microsoft is pushing passkeys as the default. A passkey is a login method tied to your device, unlocked with your fingerprint, face, or PIN, the same way you unlock your phone. There's no code to type in and nothing for an attacker to trick out of your employee, because there's no code to steal in the first place.

Key Dates for Oregon Businesses

Date

What Happens

September 1, 2026

Any employee still using text or voice codes is automatically switched into a passkey setup and prompted to register one at their next login. This happens whether you plan for it or not, unless you act first.

September 18, 2026

Microsoft publishes pricing for businesses that want to keep using text/voice codes through a separately contracted telecom provider.

October 30, 2026

Businesses can set up that alternate provider, if they have a specific reason to keep text/voice as an option.

February 1, 2027

Microsoft's free text and voice codes stop working entirely. Any employee with no other login method on file gets locked out of signing in until they set up a passkey.

What You Need to Do Now

1. Find out who's still using text or voice codes. Most businesses have at least a handful of employees on the older setup, often the ones least likely to enjoy learning a new login process. Knowing who they are ahead of time turns this into a planned rollout instead of a surprise for them.

2. Get passkeys set up before Microsoft does it for you. You can move employees over on your own schedule, with a heads-up and a little hand-holding, well before the September 1 deadline. That beats having it happen automatically with no warning.

3. Give your team a short explanation, not just an instruction. People adopt new logins faster when they understand why it's changing. A two-line email ("Microsoft is retiring text-message codes because they're the easiest login method for scammers to fake, here's how to set up your new one") goes a long way.

4. If you have a genuine reason to keep text or voice codes (a regulatory requirement or an unusual line-of-business need), you can contract with a separate telecom provider through Microsoft's Security Store starting October 30, 2026. This comes at your own cost and doesn't carry the same security benefit as a passkey, so it's worth treating as a fallback rather than a first choice.

Frequently Asked Questions

Do we have to do anything if none of our employees use text or voice codes? No. If everyone's already using an authenticator app, a hardware key, or another modern method, this change won't affect you.

Will this cost us anything? Moving employees to passkeys has no additional cost from Microsoft. The only cost involved is if you choose to keep text/voice codes through a separately contracted provider after February 1, 2027.

What happens to an employee who ignores the prompts? Between September 2026 and February 2027, they'll get repeated reminders but can still sign in normally. After February 1, 2027, anyone whose only method on file is text or voice will be blocked from signing in until they register a passkey.

Is a passkey harder for employees to use than a text code? Generally the opposite. Most people already unlock their phone or laptop with a fingerprint or face scan, a passkey uses that same motion instead of asking them to copy a code from a text message.

Can we control the timing instead of letting Microsoft switch everyone automatically? Yes. There's a setting IT can put in place that delays the automatic September 1 switch-over so you can roll passkeys out on your own schedule instead. This is exactly the kind of setting a managed IT provider handles for you before it becomes a scramble.

We Can Handle This For You

Manage your IT, don't let your business be managed by it. That's the whole idea behind what we do, and a change like this is a good example of why it matters. Left alone, this becomes a scramble in early 2027 when employees start getting locked out mid-workday. Handled ahead of time, it's a quiet, well-communicated rollout that actually leaves your business more secure than it was before.

If you're not sure whether your team is still using text or voice codes, or you'd rather have someone else handle the rollout, that's exactly what we're here for.

Book a Free Consultation and we'll take a look at your current setup and map out what, if anything, needs to change before the deadlines hit.

The Greed Trap in Business Automation
Why Relying on One IT Employee is a Trap
Comment for this post has been locked by admin.
 

Comments

No comments made yet. Be the first to submit a comment
Guest
Already Registered? Login Here
Guest
Sunday, 06 September 2026

Captcha Image

Customer Login

News & Updates

One Up Solutions Northwest is proud to announce the launch of our new website at www.1upnw.com. The goal of the new website is to make it easier for our existing clients to submit and manage support requests, and provide more information about our services for ...

Contact us

Learn more about what One Up Solutions Northwest can do for your business.

One Up Solutions Northwest
8060 SW Pfaffle street Suite 108
Tigard, Oregon 97223