Ventrix IT

Microsoft Is Retiring SMS & Voice Authentication. Here’s What Kent Businesses Need to Know

If your business uses Microsoft 365, there’s an important security change on the horizon.

Microsoft has announced that it’s retiring its native SMS and voice authentication services for Microsoft Entra ID. Instead, it’s encouraging organisations to move to passkeys and other phishing-resistant authentication methods that offer much stronger protection against modern cyber attacks.

The deadlines are still some way off, but this isn’t something businesses should leave until the last minute. Changing the way people sign in affects every user in your organisation, so the earlier you start planning, the smoother the transition will be.

For businesses across Kent, this is a good opportunity to review your Microsoft 365 security and make sure your authentication methods are fit for the future.

Why is Microsoft making this change?

When multi-factor authentication first became common, receiving a code by text message or phone call was a huge improvement over relying on a password alone. The problem is that attackers have caught up.

Cyber criminals now regularly use phishing websites, SIM swapping and social engineering to intercept SMS verification codes or trick users into giving them away. While SMS authentication is still better than having no MFA at all, it no longer offers the level of protection organisations need.

Microsoft has spent the last few years investing in passwordless authentication, and passkeys are becoming a central part of that strategy. They make signing in quicker for users while making it much harder for attackers to gain access to accounts.

It’s a win for both security and usability.

What actually changes?

Microsoft’s rollout will happen in stages rather than all at once.

From 1 September 2026, passkeys will become the default sign-in option within Microsoft Entra ID. Users who still rely on SMS or voice authentication will begin seeing prompts encouraging them to register a passkey.

Then, on 1 February 2027, Microsoft’s native SMS and voice authentication services will be retired. Organisations that haven’t moved to supported authentication methods, or an approved external provider where appropriate, could run into problems when users try to sign in.

Although 2027 sounds a long way off, projects involving user authentication often take months to plan and roll out successfully. If you have dozens or hundreds of users, it’s worth starting that conversation now rather than rushing it later.

So, what are passkeys?

If you already unlock your phone with Face ID or your fingerprint, you’ve got a good idea of how passkeys work.

Instead of typing a password and then entering a code sent by text, users verify their identity using something they already have, such as Windows Hello, Face ID, Touch ID, a fingerprint reader or a device PIN.

Behind the scenes, passkeys use cryptography rather than shared secrets like passwords or one-time codes. That means there’s nothing for an attacker to steal through a phishing email or fake login page.

From a user’s perspective, signing in is often quicker. From an IT perspective, it’s a much more secure way to protect business accounts.

What should businesses be doing now?

There’s no need to panic, but there is a good reason to start preparing.

A sensible first step is understanding how your users currently authenticate. Many organisations assume everyone is using Microsoft Authenticator when, in reality, a significant number of employees still rely on SMS codes.

Once you know where you stand, you can begin introducing passkeys, test the rollout with a small group of users and communicate the changes before they affect the whole business.

Taking a gradual approach usually leads to fewer support requests and a much smoother experience for everyone involved.

How Ventrix IT can help

At Ventrix IT, we work with businesses across Kent to get the most from Microsoft 365 while keeping their systems secure.

If you’re unsure how these changes affect your organisation, we can review your Microsoft Entra ID setup, identify users still relying on SMS authentication and help you plan a straightforward migration to passkeys. We can also review your wider Microsoft 365 security, including Conditional Access policies, identity protection and other best practices that reduce the risk of cyber attacks.

Authentication is one of the most important parts of your security strategy, and Microsoft’s latest announcement is a good reminder that it shouldn’t be left to chance.

If you’d like to make sure your business is ready before the deadlines arrive, get in touch with Ventrix IT. We’ll help you put a plan in place that keeps your users secure without disrupting the way they work.

 

Scroll to Top