# Entra ID stops delivering SMS and voice codes on February 1, and global admins go last

Source: https://startwithidentity.com/blog/2026-09-21-entra-id-stops-delivering-sms-and-voice-codes-february-1-and-global-admins-go-last/
Last updated: 2026-09-21
License: content by Start with Identity. Cite the source URL.

---

Microsoft reminded administrators this week that [Microsoft Entra ID](https://startwithidentity.com/vendors/iam/microsoft-entra/) is retiring the SMS and voice authentication it delivers itself. Passkeys became the default on September 1, when users enabled for SMS or voice were automatically enabled for passkeys and nudged to register one. From February 1, 2027, Microsoft-provided SMS and voice delivery ends for all users except Global Administrators and external users, whose date is July 1, 2027. After the cutoff, anyone whose only MFA method is SMS or voice must register a passkey during sign-in; the prompt blocks sign-in and has no opt-out. Organizations that still need SMS or voice must contract a telephony provider through Microsoft Security Store, with Soprano and Telesign first, configurable from October 30, 2026, and pay the telecom costs themselves. Microsoft's [retirement guide](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement) links a PowerShell analyzer for finding affected users.

## Why it matters

Read the dates in the opposite order to how Microsoft wrote them. Global Administrators get five more months on SMS than everyone else, which gives the most privileged accounts in the tenant the longest runway on the weakest factor. There are sensible operational reasons for that, since nobody wants the break-glass path to fail first, but the right move is to migrate administrators first and on purpose, with hardware keys, rather than last by default. External users on the July date are the other group to watch, because they are the ones you have least influence over.

The cost change is the quieter shift. SMS is now a line item you buy from a third party, which makes the business case for dropping it easier to write; the [UK government put its SMS saving at close to 600 pounds a day](https://startwithidentity.com/blog/2026-09-14-gov-uk-one-login-opens-passkeys-to-23-million-users/) after its passkey rollout. And a blocking passkey prompt at sign-in is exactly the moment a vishing caller wants: attackers were already [phoning staff about passkey enrollment](https://startwithidentity.com/blog/2026-07-09-entra-passkey-enrollment-vishing-targets-microsoft-365-users/). Tell users now how IT will and will not contact them. Background in our [July coverage of the passkey default](https://startwithidentity.com/blog/2026-07-14-microsoft-entra-id-gets-passkeys-default-authentication-starting-septe/) and [phishing-resistant MFA](https://startwithidentity.com/glossary/phishing-resistant-mfa/).

Source: [BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys/)
