Picture this: one of your employees gets a text message that looks exactly like the login code they get every time they sign into Outlook or Teams. They type it into what they think is the Microsoft login screen. Except it isn't. It's a fake page an attacker set up an hour earlier, and the "code" just handed over access to your company's email.
This isn't a hypothetical. It's one of the most common ways businesses get broken into today, and it's a big part of why Microsoft is changing how sign-in security works for every organization that uses Microsoft 365 and Entra ID (the system behind your employee logins, previously called Azure Active Directory).
The bottom line: starting September 1, 2026, Microsoft begins automatically switching users away from text-message and phone-call login codes and toward a more secure option called a passkey. By February 1, 2027, Microsoft stops offering text and voice codes altogether. If your business relies on them today, you have a window to get ahead of this on your own terms, or Microsoft will make the change for you.
Today, when an employee logs into Microsoft 365, they typically enter their password and then a second step, called multi-factor authentication (MFA), to prove it's really them. For a lot of businesses, that second step is a text message or phone call with a one-time code.
The problem is that text and voice codes are the weakest form of MFA available. They can be intercepted, redirected through a hijacked phone number (called a SIM-swap), or, as in the scenario above, handed straight to an attacker through a fake login page. Microsoft has been recommending against them for years, and now it's retiring the free service that delivers them.
In their place, Microsoft is pushing passkeys as the default. A passkey is a login method tied to your device, unlocked with your fingerprint, face, or PIN, the same way you unlock your phone. There's no code to type in and nothing for an attacker to trick out of your employee, because there's no code to steal in the first place.
|
Date |
What Happens |
|
September 1, 2026 |
Any employee still using text or voice codes is automatically switched into a passkey setup and prompted to register one at their next login. This happens whether you plan for it or not, unless you act first. |
|
September 18, 2026 |
Microsoft publishes pricing for businesses that want to keep using text/voice codes through a separately contracted telecom provider. |
|
October 30, 2026 |
Businesses can set up that alternate provider, if they have a specific reason to keep text/voice as an option. |
|
February 1, 2027 |
Microsoft's free text and voice codes stop working entirely. Any employee with no other login method on file gets locked out of signing in until they set up a passkey. |
1. Find out who's still using text or voice codes. Most businesses have at least a handful of employees on the older setup, often the ones least likely to enjoy learning a new login process. Knowing who they are ahead of time turns this into a planned rollout instead of a surprise for them.
2. Get passkeys set up before Microsoft does it for you. You can move employees over on your own schedule, with a heads-up and a little hand-holding, well before the September 1 deadline. That beats having it happen automatically with no warning.
3. Give your team a short explanation, not just an instruction. People adopt new logins faster when they understand why it's changing. A two-line email ("Microsoft is retiring text-message codes because they're the easiest login method for scammers to fake, here's how to set up your new one") goes a long way.
4. If you have a genuine reason to keep text or voice codes (a regulatory requirement or an unusual line-of-business need), you can contract with a separate telecom provider through Microsoft's Security Store starting October 30, 2026. This comes at your own cost and doesn't carry the same security benefit as a passkey, so it's worth treating as a fallback rather than a first choice.
Do we have to do anything if none of our employees use text or voice codes? No. If everyone's already using an authenticator app, a hardware key, or another modern method, this change won't affect you.
Will this cost us anything? Moving employees to passkeys has no additional cost from Microsoft. The only cost involved is if you choose to keep text/voice codes through a separately contracted provider after February 1, 2027.
What happens to an employee who ignores the prompts? Between September 2026 and February 2027, they'll get repeated reminders but can still sign in normally. After February 1, 2027, anyone whose only method on file is text or voice will be blocked from signing in until they register a passkey.
Is a passkey harder for employees to use than a text code? Generally the opposite. Most people already unlock their phone or laptop with a fingerprint or face scan, a passkey uses that same motion instead of asking them to copy a code from a text message.
Can we control the timing instead of letting Microsoft switch everyone automatically? Yes. There's a setting IT can put in place that delays the automatic September 1 switch-over so you can roll passkeys out on your own schedule instead. This is exactly the kind of setting a managed IT provider handles for you before it becomes a scramble.
Manage your IT, don't let your business be managed by it. That's the whole idea behind what we do, and a change like this is a good example of why it matters. Left alone, this becomes a scramble in early 2027 when employees start getting locked out mid-workday. Handled ahead of time, it's a quiet, well-communicated rollout that actually leaves your business more secure than it was before.
If you're not sure whether your team is still using text or voice codes, or you'd rather have someone else handle the rollout, that's exactly what we're here for.
Book a Free Consultation and we'll take a look at your current setup and map out what, if anything, needs to change before the deadlines hit.
Comments