Microsoft Is Moving Past SMS and Voice Authentication: What You Should Know

Microsoft Is Moving Past SMS and Voice Authentication: What You Should Know

/ / /

Microsoft is changing how users sign in to Microsoft 365.

Many organizations have used text messages or phone calls for Multifactor Authentication (MFA) for years. You may use this method as well. After entering your password, Microsoft sends a code by text or phone call to confirm your identity.

While this is safer than just using a password, it is no longer the most secure option. Cybercriminals have become better at attacking text messages and phone-based authentication.

For this reason, Microsoft is urging organizations to switch to more secure sign-in options like Microsoft Authenticator, Windows Hello, and passkeys. Microsoft will gradually retire its built-in SMS and voice authentication service, giving organizations time to plan and adjust. If your business still uses text message or phone-based authentication, you have other options to consider.

Passkeys are a newer way to sign in. They can use your phone, computer, fingerprint, or facial recognition instead of a code sent by text. Often, passkeys make signing in easier for employees and improve security.

Will This Change Affect Your Business?

It could.

If your employees get a text message or phone call when signing in to Microsoft 365, Outlook, Teams, SharePoint, or other Microsoft cloud services, now is a good time to review how they sign in and start planning other methods.

For many organizations, switching will be simple. Others may need more planning, user training, or changes to security policies.

Why This Is Important

Cybercriminals target user accounts because they can provide access to email, files, and other business data.

Switching to more secure sign-in methods can help you:

  • Better protect business data.
  • Reduce the risk of compromised accounts.
  • Simplify the sign-in experience for employees.
  • Strengthen protection against phishing attacks.

What Steps Should Organizations Take?

Start by understanding how people sign in today.

Consider:

  • Reviewing how employees currently complete MFA
  • Identifying users who rely on text messages or phone calls
  • Evaluating alternatives such as Microsoft Authenticator, passkeys, or security keys
  • Planning communication and training before making changes

Each organization has its own security needs, user requirements, and compliance rules. Taking time to understand your setup will help you choose the best way forward.

How TechHouse Can Support You

Whether you are just starting to look at these Microsoft changes or are ready to switch, TechHouse can help.

We can help you find affected users, choose the best authentication methods for your business, set up Microsoft 365 security, and guide your employees through the change. We can also review your overall Microsoft 365 security and help you defend against new cyber threats.

TechHouse is a Tier 1 Direct Microsoft Solutions Partner with Security and Support badges. We have the experience to help organizations boost security and keep employees productive.

Find Out More

You can read Microsoft’s announcement and timeline in the Microsoft Learn article:

Passkeys by Default and Retirement of Microsoft-Provided SMS and Voice Authentication