Start with Identity
Analysis

The SMS off-ramp has a date now: what Entra, GOV.UK and America.gov mean for your MFA plan

Microsoft stops delivering SMS and voice codes in Entra ID on February 1, 2027. The UK has put passkeys in front of 23 million citizens, and the new federal front door runs on Login.gov. Here is how to plan the move off SMS without creating a new weak point in recovery.

By SWI Community TeamSep 29, 2026

SMS codes have been the default second factor for a decade because they were free, familiar and everywhere. September 2026 is the month that stopped being true in all three respects. Microsoft Entra ID set a hard date to stop delivering SMS and voice codes itself, the UK government showed what dropping SMS saves at population scale, and the new U.S. federal front door launched on top of Login.gov. If you run a workforce or customer identity program, the question is no longer whether to move off SMS but how to do it without opening a worse hole in account recovery.

What changed in September

Entra ID has a cutoff. Passkeys became the Entra ID default on September 1. From February 1, 2027, Microsoft stops providing SMS and voice authentication for everyone except Global Administrators and external users, who follow on July 1, 2027. After each date, users whose only MFA method is SMS or voice hit a blocking prompt to register a passkey, with no opt-out. Tenants that still need SMS must contract a telephony provider through Microsoft Security Store and pay the telecom costs themselves.

GOV.UK showed the economics. GOV.UK One Login opened passkeys to more than 23 million people, reported that passkeys are up to eight times faster than password plus 2FA, and put its saving on SMS at close to 600 pounds a day. Passwords remain optional there, which matters and is covered below.

America.gov launched on Login.gov. The executive order behind the new federal portal names Login.gov as its authentication service. As we argue in our America.gov analysis, a single front door to federal services will be the most impersonated login page in the country, which makes phishing-resistant sign-in a requirement rather than a preference.

Why SMS is leaving

The cost argument is new; the security argument is old. SMS codes can be intercepted through a SIM swap, relayed in real time by a phishing proxy, or simply read out by a user to a caller posing as IT, the pattern behind OTP relay social engineering. NIST's guidelines have treated codes sent over the phone network as a restricted authenticator since 2017. Phishing-resistant MFA such as passkeys closes the relay path because the credential is bound to the real site and never leaves the device as a typeable code.

What has changed is that SMS now has an invoice attached. Once a platform stops absorbing the per-message cost, the business case for leaving writes itself, and the finance team becomes an ally of the security team.

A migration plan that holds up

1. Find who actually depends on SMS. Microsoft's retirement guide links a PowerShell analyzer that lists users enabled for SMS or voice. The number that matters is users for whom SMS is the only method, because those are the ones the February prompt will block.

2. Move administrators first, on purpose. Microsoft gives Global Administrators until July 1, five months after everyone else. Do the opposite: move every privileged account to hardware security keys or device-bound passkeys before the general deadline, and verify break-glass accounts separately so the emergency path is not the last thing tested. The most privileged accounts should not keep the weakest factor the longest.

3. Remove SMS, do not just add passkeys. A passkey sitting next to a live SMS or password option is a faster login, not a phishing-resistant account. Kits such as BigBear already disable WebAuthn in the browser to force a downgrade to whatever method remains. Enforce authentication strength through Conditional Access for the accounts that matter, so the weaker method is rejected rather than merely de-prioritized.

4. Fix recovery before you remove the fallback. Account recovery is where passkey programs quietly reintroduce SMS. If a lost phone is recovered by texting a code to the same number, the attacker's easiest path is unchanged. Use a second registered passkey or hardware key, a verified in-person or video check for high-value accounts, and a help-desk procedure that cannot be satisfied by a convincing phone call. See account recovery.

5. Buy SMS only where a regulation requires it. Microsoft's guidance is to use a Security Store telephony provider only for documented user segments with a genuine regulatory or operational need. Treat each such segment as an exception with an owner and a review date, not as the new default.

6. Warn users before the attackers do. A blocking "register a passkey" prompt is the perfect pretext for a vishing call, and attackers have been phoning staff about passkey enrollment since July. Tell people now how IT will and will not contact them, and that nobody legitimate will ever ask them to read out a code or approve a sign-in they did not start. See vishing.

7. Plan for external and guest users. External users are on the July date in Entra and are the population you control least. Decide whether partners must bring their own phishing-resistant method through federation, or whether they get a passkey in your tenant, before July forces the choice.

What passkeys do not solve

Passkeys stop credential phishing. They do not stop session theft after sign-in, social engineering of the help desk, or malware on an unmanaged device. August's research showed attacks on the plumbing around passkeys, such as sync custody and in-session key reuse, rather than on the cryptography. Pair the migration with short session lifetimes for sensitive apps, device-bound session protections where available, and monitoring for token replay.

The deadline is a gift. It gives identity teams a date, a cost argument and a vendor-driven reason to do work that has been postponed for years. Use it to remove SMS rather than to renew it.

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.