06 Aug Microsoft pulls the plug: why SMS MFA is now finally obsolete
Inhaltsverzeichnis
- 1 The message that many IT departments underestimate
- 2 Why Microsoft is suddenly taking such decisive action
- 3 The uncomfortable reality check: how many of your users still use text messages?
- 4 Why passkeys are actually a security improvement
- 5 The dispute between Microsoft and security researchers highlights the real problem
- 6 TEAL Assessment: The real message behind Microsoft’s announcement
Passkeys are becoming the standard in Entra ID. SMS and phone calls are on their way out. Anyone still relying on traditional MFA is in for a problem—and sooner than many realize.
The message that many IT departments underestimate
You know how it is: For years, the motto was “Just make sure MFA is enabled.” Whether it was Microsoft Authenticator, an SMS code, or a call to your cell phone… anything was better than just a username and password.
Now Microsoft is changing the rules of the game.
Starting September 1, 2026, passkeys will gradually become the default authentication method in Microsoft Entra ID. At the same time, Microsoft has announced that it will discontinue native support for SMS and voice MFA. Starting February 1, 2027, Microsoft will discontinue its own SMS and voice services for Entra ID. Organizations should switch to passkeys or other phishing-resistant methods instead.
This is no minor product change. It is a strategic decision that will have long-term implications for nearly every Microsoft 365 environment.
Why Microsoft is suddenly taking such decisive action
Microsoft cites the drastic change in the threat landscape as the reason for this move. While many companies now secure their passwords quite well, SMS codes and phone calls remain a popular target for attacks:
-
- SIM-Swapping
-
- Social Engineering
-
- Phishing of One-time codes
-
- MFA-Fatigue attacs
-
- Man-in-the-Middle attacs
-
- AI-powered phishing campaigns
Microsoft explicitly points out the increasing sophistication of modern attacks and the fact that traditional MFA methods continue to rely on shared secrets. Passkeys, on the other hand, use public-key cryptography and are considered phishing-resistant.
In other words: Passwords are yesterday’s problem. Phishable MFA is today’s problem.
The uncomfortable reality check: how many of your users still use text messages?
This is exactly where things get interesting. While MFA has been implemented in many companies, it has never been consistently developed further.
Typische Situationen:
-
- Administrators still use SMS as a backup
- External users rely exclusively on phone-based MFA
- Outdated service processes rely on SMS verification
- Legacy applications require special solutions
- The identity strategy has not been reviewed in years
The result:
Microsoft is making passkeys the standard, and many companies are realizing that their own authentication strategies aren’t prepared for this at all.
Why passkeys are actually a security improvement
Passkeys are not just a new marketing term for MFA. The key difference is:
With a passkey, the private key never leaves the user’s device. A fake login page therefore cannot intercept or reuse the code. That is exactly why passkeys are considered phishing-resistant.
Put simply, this means:
| SMS MFA | Passkeys |
| Code can be intercepted | No transferable code |
| Vulnerable to phishing | Phishing-resistant |
| SIM swapping possible | Not relevant |
| Poor user experience | Quick login via fingerprint, Face ID, or PIN <
The security gains are real. But as is so often the case, the real challenge lies not in the technology. |
The dispute between Microsoft and security researchers highlights the real problem
The current discussion between Microsoft and parts of the security community is particularly intriguing. In recent months, several security researchers have pointed out that it is not the passkeys themselves that pose the greatest risk, but rather their implementation in companies.
Attackers are already using fake help desk calls, social engineering, and purported “passkey registrations” to trick users into registering new credentials for the attackers. These attacks target people, not the technology itself.
Microsoft, on the other hand, rightly emphasizes that passkeys themselves remain one of the most secure authentication methods and that the actual vulnerability often lies in the registration or rollout process. The technology isn’t broken; the implementation might be.
And that, in our view, is the most important takeaway:
Passkeys solve technical problems. They do not solve organizational problems.
If you fail to engage users, prepare help desks, define governance, or secure the registration process, you create new vulnerabilities—even with the most advanced technology.
TEAL Assessment: The real message behind Microsoft’s announcement
Most headlines these days are focused on passkeys. From our perspective, however, the much more important message lies between the lines:
Microsoft is effectively declaring SMS-based MFA obsolete.
In doing so, one of the world’s largest identity providers is sending a clear message: Authentication methods that can be compromised through phishing, social engineering, or SIM swapping are no longer suitable for today’s threat landscape.
“The news isn’t really that Microsoft is introducing passkeys. The news is that Microsoft officially no longer considers SMS-based MFA to be viable for the future. Companies should view this announcement as a wake-up call and reevaluate their entire authentication strategy. Anyone still relying on methods that can be bypassed through phishing, social engineering, or SIM swapping is playing catch-up with today’s threats,” says Fabian Böhm, Managing Director & Security Architect at TEAL
In our experience, passkeys aren’t the biggest challenge here. The real challenge lies in implementation:
-
- Which user groups will be migrated first?
- How will administrators be protected?
- What is the recovery process for lost devices?
- Which fallback mechanisms will remain in place?
- How can misuse be prevented during registration?
- Which conditional access policies need to be adjusted?
For those who want to dive into the details briefly, here’s a mini-FAQ on passkeys and SMS MFA:
Why is Microsoft replacing SMS MFA?
SMS and phone-based MFA are considered vulnerable to phishing, social engineering, and SIM swapping. Microsoft is therefore switching to phishing-resistant methods such as passkeys.
What are passkeys?
Passkeys are modern authentication credentials based on cryptography instead of passwords or SMS codes. Sign-in is completed using methods like fingerprint, Face ID, or a device PIN.
When will passkeys become the default?
Starting in September 2026, Microsoft will begin rolling out passkeys as the default authentication method in Entra ID.
Are passkeys really more secure?
Yes. Unlike SMS codes or passwords, passkeys cannot be intercepted on phishing websites, making them significantly more resilient against modern attacks.
What should organizations do now?
Organizations should assess which users are still relying on SMS MFA, plan a passkey rollout, and align their Entra ID strategy with phishing-resistant authentication in a timely manner.
LATEST POSTS
-
Microsoft pulls the plug: why SMS MFA is now finally obsolete
Starting September 1, 2026, passkeys will gradually become the default authentication method in Microsoft Entra ID. At the same time, Microsoft has announced that it will discontinue native support for SMS and voice MFA....
06 August, 2026 -
One-Click Disaster in Microsoft 365 Copilot: When AI becomes a hacker’s best friend
AI agents like Microsoft 365 Copilot are revolutionizing our daily work and promise unprecedented productivity. But what happens if this very smart assistant system quietly turns into the ultimate spy? ...
01 July, 2026 -
Microsoft’s Mega Patch Day: 200 Vulnerabilities, Zero-Days, and an Open War
You know the drill: It’s the second Tuesday of the month, the administrators are sighing quietly, and the usual routine updates are due. But what Microsoft rolled out in June 2026 goes far beyond the norm....
30 June, 2026


























