Microsoft is telling IT admins to drop SMS and voice-based authentication. The company points to AI-powered phishing as the main driver. Attackers can now manipulate SMS and voice channels more easily, even those with limited skills. SIM swapping has also grown simpler with AI help, letting bad actors shift a phone number to a card they control with less effort than before.
Microsoft reports a sharp rise in AI-driven attacks aimed at stealing passwords and MFA codes. These newer attempts succeed more often than older phishing methods from before widespread AI tools. The AI does not directly hack the SIM card. It simply makes it far easier to trick people into giving up their credentials on their own.
Timeline for Entra ID Changes
Microsoft outlined a clear two-step schedule for Entra users. Starting September 1, anyone still relying on SMS or voice authentication will see a prompt to set up a passkey during sign-in. Those not prepared for the change need to shift away from SMS or voice methods before that date arrives.
On February 1, 2027, Microsoft will fully retire SMS and voice authentication for Entra ID. Passkeys become mandatory at that point. There is no opt-out option. Every tenant faces the same requirement with no exceptions.
Changes for Personal Microsoft Accounts
Personal Microsoft accounts used for Outlook, Xbox, or Windows 11 face a similar shift. Microsoft has already begun phasing out SMS for both authentication and account recovery on these accounts. No firm deadline exists yet for everyday users.
Steps Users Can Take Now
Waiting for Microsoft to enforce the change is not the best approach. Setting up a passkey ahead of time removes the pressure. Switching to Microsoft Authenticator offers another solid path for those who prefer that option. Passwords by themselves no longer provide enough protection, especially as AI continues to make phishing more effective.

