Tag: microsoft 365 mfa

  • Microsoft is retiring voice and SMS verification in favor of passkeys for Entra users starting February 2027, we tell you how to set this up NOW before you lose access

    Microsoft is retiring voice and SMS verification in favor of passkeys for Entra users starting February 2027, we tell you how to set this up NOW before you lose access

    If your business still has Microsoft 365 users receiving text messages or phone calls to verify their identities, Microsoft has officially put an expiration date on that workflow. Beginning February 1, 2027, Microsoft will retire the SMS and voice authentication services it currently provides through Microsoft Entra ID, and organizations that have not prepared could see users run directly into sign-in disruptions.

    This is not another security recommendation that businesses can indefinitely postpone because the old method still works. Microsoft is actively moving Entra customers toward phishing-resistant authentication such as passkeys, Windows Hello for Business, and FIDO2 security keys, and the transition starts well before February 2027.

    So, what exactly is Microsoft changing? Starting September 1, 2026, Microsoft will make passkeys the default authentication experience for users who are currently enabled for SMS or voice authentication. Those users will automatically become eligible for passkeys and Microsoft can begin prompting them to register one when they complete MFA.

    Then the bigger change arrives on February 1, 2027. Microsoft-provided SMS messages and voice calls will no longer be available as native Entra ID authentication services, and there is no permanent opt-out from that change.

    For businesses, the important dates and consequences are:

    • September 1, 2026: Microsoft begins automatically enabling passkeys for users who are enabled for SMS or voice authentication and can prompt those users to register. Organizations can prepare before this process starts rather than introducing a new authentication workflow to employees without planning or communication.
    • February 1, 2027: Microsoft-provided SMS and voice authentication are retired. Users whose only MFA option is SMS or voice can encounter a blocking registration experience and will have to establish a passkey before they can continue signing in normally.
    • After February 1, 2027: Organizations that genuinely need SMS or voice authentication will need to use a supported customer-managed telecommunications provider instead of Microsoft’s native delivery service. Microsoft recommends moving users to phishing-resistant authentication wherever possible rather than treating third-party telephony as the default replacement.

    That last point matters because this is not simply Microsoft swapping one MFA delivery vendor for another. The strategic direction is clear: Microsoft wants organizations to stop relying on codes that can be intercepted, relayed, socially engineered, or stolen through phishing.

    Why are they making this change now? SMS MFA was a major improvement over passwords alone, and businesses were right to adopt it when stronger MFA options were less accessible. The problem is that cybercriminals have become very good at attacking authentication workflows instead of trying to break the underlying cryptography. A six-digit verification code is still a secret that a human can be convinced to type into the wrong website. Attackers can build convincing Microsoft 365 login pages, proxy authentication sessions in real time, steal credentials, collect the MFA code the victim enters, and potentially capture authenticated sessions.

    Telephone-based authentication introduces additional risks such as SIM swapping and telecommunications account compromise. Microsoft specifically describes passwords, SMS codes, and email one-time codes as phishable credentials and is positioning passkeys as a replacement built around phishing-resistant public-key cryptography. A passkey works differently because there is no reusable verification code for an employee to accidentally hand to an attacker. The credential is cryptographically tied to the legitimate service, which makes the familiar fake-login-page attack substantially harder to execute successfully.

    You may be wondering what a passkey is, passkey is a FIDO2-based authentication credential that uses public-key cryptography rather than a shared password or temporary code. The private portion of the credential remains with the user’s device or credential provider, while Microsoft Entra receives what it needs to verify that the legitimate credential is present.

    Microsoft Entra currently supports both synced and device-bound passkeys. Synced passkeys can live in supported credential managers and follow a user across compatible devices, while device-bound passkeys can be stored in Microsoft Authenticator, Windows, or a physical FIDO2 security key. Businesses therefore do not have to choose one universal piece of hardware for every employee. The appropriate approach can vary by role, device ownership, administrative privilege, regulatory requirements, and how the organization manages endpoints.

    The good news is you can start now, there is no reason to wait until January 2027 to deal with this. Microsoft already supports passkeys in Entra ID, including Entra ID Free, and organizations can begin enabling them, registering users, testing applications, and building recovery procedures today.

    Starting early also gives your IT provider a chance to find the exceptions before they become emergencies. An employee with an unusual mobile device, an executive traveling internationally, an administrator with elevated privileges, or a legacy business process that depends on telephone authentication is much easier to deal with months before a mandatory cutoff.

    Step 1: Find out who is still using SMS or voice

    Before changing authentication policies, determine which Entra users are actually dependent on SMS or voice. Microsoft recommends identifying these users first so that organizations can target their migration rather than blindly changing authentication settings tenant-wide.

    This assessment should also distinguish between users who merely have a phone number registered and users who genuinely depend on phone authentication. Someone who already uses Windows Hello or a FIDO2 credential may require little intervention, while an employee whose only usable second factor is a text message needs attention.

    Step 2: Enable passkeys in Microsoft Entra

    Administrators can configure passkeys under the Authentication Methods policies in the Microsoft Entra admin center. Microsoft’s current deployment model uses passkey profiles, which allow administrators to define permitted passkey types, restrictions, attestation requirements, and the groups that should receive the policy.

    A controlled pilot is usually preferable to immediately targeting every employee. Start with IT personnel and a small group of cooperative users, confirm the registration and sign-in experience on the devices your organization actually uses, and then expand the deployment.

    Step 3: Have users register their passkeys

    Users can register passkeys through Microsoft’s Security Info experience once their organization has enabled the appropriate authentication method. Depending on the organization’s configuration, that passkey can be stored in Microsoft Authenticator, on a Windows device, in a supported synced credential provider, or on a physical FIDO2 security key.

    For Microsoft Authenticator, Microsoft supports passkey registration on current iOS and Android versions and recommends registering directly through the Authenticator application when that deployment model is being used. Organizations should test the exact workflow they intend to give employees before distributing instructions company-wide.

    Step 4: Plan for account recovery before you enforce anything

    Stronger authentication does not eliminate the need for recovery procedures. Employees replace phones, laptops fail, security keys disappear, and administrators eventually have to help someone who no longer possesses the credential they normally use.

    Microsoft Entra supports Temporary Access Pass, or TAP, specifically to help users bootstrap passwordless authentication methods or recover when a strong authentication method is unavailable. A TAP can be time limited and configured for controlled onboarding or recovery scenarios.

    Your IT team should understand this process before passkeys become mandatory. Locking down authentication without establishing a recovery workflow is an excellent way to turn a security improvement into an avoidable Monday-morning support emergency.

    Step 5: Protect administrators more aggressively than ordinary users

    Administrative accounts deserve stronger requirements because compromise of an administrator can affect the entire Microsoft 365 environment. Global Administrators and other privileged roles should ideally have more than one phishing-resistant credential available so that the loss of a single phone, laptop, or security key does not create an administrative lockout. For privileged users, physical FIDO2 security keys are still worth serious consideration. Microsoft specifically identifies them as a strong option for elevated users and regulated environments because the private credential remains on the physical authenticator.

    So, what should your business be doing now? February 2027 may sound comfortably far away, but authentication changes are much easier to deploy gradually than during a deadline-driven migration. Businesses should use the remaining time to turn passkeys into an ordinary part of their Microsoft 365 environment rather than something employees first encounter when their old MFA method stops working.

    A sensible preparation plan includes:

    • Audit your current authentication methods now. Identify employees who still depend on SMS or voice and pay particular attention to executives, administrators, remote employees, and users with unusual device requirements.
    • Enable passkeys and run a pilot deployment. Test Microsoft Authenticator, Windows-based passkeys, synced passkeys, and FIDO2 security keys where appropriate rather than assuming one method is ideal for every employee.
    • Establish a recovery process. Document how your IT team will use methods such as Temporary Access Pass when an employee loses a registered device or needs to enroll a replacement credential.
    • Communicate with employees before changing their sign-in experience. A short explanation of why passkeys are being introduced can prevent confusion and reduce help desk calls when registration prompts begin appearing.
    • Review Conditional Access at the same time. Moving to phishing-resistant credentials creates an opportunity to strengthen access requirements for administrators, remote access, sensitive applications, and other higher-risk scenarios.
    • Do not wait until January 2027. You want February 1 to be an uneventful date on the calendar because your employees migrated months earlier, not the day your organization discovers which users were still relying entirely on text messages.

    Can you keep using SMS? Technically, yes, but Microsoft will no longer provide the underlying SMS or voice delivery service after February 1, 2027. Organizations with a documented business, regulatory, or operational requirement will be able to select a supported telecommunications provider through Microsoft’s Security Store and route authentication through that provider.

    Microsoft says provider information will become available beginning September 18, 2026, with customer configuration scheduled to become available beginning October 30, 2026. For most small and midsize businesses, however, moving users to passkeys is likely to be both simpler and more aligned with Microsoft’s long-term authentication strategy. You should not wait until February 2027 to move on this. Microsoft’s retirement of native SMS and voice authentication is another signal that traditional MFA is evolving. Having MFA enabled is no longer the finish line because organizations now have to consider whether the authentication method itself can withstand modern phishing, session theft, social engineering, and identity attacks.

    The businesses that start preparing now have plenty of time to audit their users, deploy passkeys, test recovery procedures, and address exceptions without disrupting employees. The businesses that ignore the change until early 2027 may instead discover their authentication dependencies when Microsoft starts blocking the workflow they have relied on for years.

    Valley Techlogic can help your organization review its Microsoft 365 and Entra authentication environment, identify users who still depend on SMS or voice verification, deploy passkeys, strengthen Conditional Access policies, and create a practical recovery process before the February 2027 deadline. The goal is not simply to satisfy another Microsoft platform change, but to leave your organization with an authentication system that is substantially harder for attackers to defeat. Learn more today with a consultation.

    This article was powered by Valley Techlogic, leading provider of trouble free IT services for businesses in California including Merced, Fresno, Stockton & More. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on X at https://x.com/valleytechlogic

  • Our how to guide on setting up MFA for your organization’s Microsoft 365

    Our how to guide on setting up MFA for your organization’s Microsoft 365

    In addition to major updates released for Microsoft Windows this month, Microsoft also released their Digital Defense Report for 2023. You can find it here.

    One page in the report caught our eye and that’s the five items you can enable that will block 99% of attacks. At the top of the list is enabling multi-factor (MFA). The other four items are: apply Zero Trust principles, use extended detection response (XDR) and anti-virus/malware, keep your systems up to date and protect your data.

    We’re zeroing in on enabling MFA today as it’s simple to implement (can be done today) and will increase the security of your account tenfold.

    The reason we say this is because the report also outlined that password-based attacks are also up tenfold, from 3 billion attempts per month in 2022 to 30 million per month in 2023. Microsoft says they have blocked an average of 4,000 password attacks per second over the last year. Attacks know many Microsoft users have not enabled MFA and are targeting those users specifically.

    It’s not a manual process either, many of these brute force attempts are being enacted by bots. Cyber criminals set these bots up and let them run, reaping the rewards from the stolen accounts they’re able to access. In addition to that, many credentials are still available on the web for a very low cost.

    We know many people have “breach fatigue”, news of yet another massive breach is not the major news topic it once was. It can feel much different though when it happens to you directly. If you currently re-use passwords for your accounts, it’s highly likely that password has been offered for sale on the web.

    Enabling MFA is strong protection against these methods and more. See our chart on how to set up MFA for your own Microsoft account.

    As you can see, it’s pretty easy to enable MFA for your own account but did you know you can also set it up from an organizational level to enable it for your employees?

    The steps doing that are as follows:

    1. Navigate to the Microsoft 365 admin center at https://admin.microsoft.com.
    2. Select Show All, then choose the Azure Active Directory Admin Center.
    3. Select Azure Active Directory, Properties, Manage Security defaults.
    4. Under Enable Security defaults, select Yes and then Save.

    Just to note, you must turn off legacy per-user MFA first before enabling global MFA in your organization. You can find that by navigating to Users > Active Users and you should see a tab on this page for multi-factor authentication. On this page should be a list of your users and you want to set each user to MFA disabled. Then you can loop back to our previous instructions and turn on the global MFA instead.

    There are also other global security settings in this section but before testing out different settings we suggest reaching out to your IT provider. MFA is a pretty non-intrusive security setting, but other settings may have unexpected consequences when it comes to you or your employee’s workflow. It’s best to evaluate your security options with a pro.

    Don’t have access to an IT pro? Valley Techlogic can assist. We are experts both in the field of cyber of security AND all things Microsoft. See our advertising flyer on our approach to enabling Microsoft 365 MFA for our customers.

    You can schedule a consultation with us today to learn more.

    Looking for more to read? We suggest these other articles from our site.

    This article was powered by Valley Techlogic, an IT service provider in Atwater, CA. You can find more information at https://www.valleytechlogic.com/ or on Facebook at https://www.facebook.com/valleytechlogic/ . Follow us on Twitter at https://x.com/valleytechlogic.