← All Posts

Text Message Login Codes Are Going Away: Here's What Microsoft 365 Users Need to Know

Person signing in on a laptop with two-factor authentication prompts

If you use Microsoft 365 and receive a text message with a login code when signing in, there's an important change coming.

Microsoft has announced that it will stop supporting its built-in SMS (text message) and voice call authentication methods beginning February 1, 2027. Instead, the company is encouraging businesses to switch to more secure sign-in methods called passkeys.

Before you panic, this isn't something that needs immediate action tomorrow. However, it's something businesses should start planning for now.

Why Is Microsoft Making This Change?

Cybersecurity threats are getting smarter.

Years ago, receiving a text message with a login code was considered a major security improvement over using only a password. Today, criminals have found ways to trick people into revealing those codes, intercept them, or even hijack phone numbers through scams known as SIM-swapping attacks.

Microsoft believes that text messages and phone calls simply aren't secure enough anymore, especially as AI-powered phishing scams become more convincing and harder to spot. That's why they're moving users toward phishing-resistant sign-in methods such as passkeys.

What's a Passkey?

Despite the futuristic name, you've probably already used something similar.

A passkey lets you sign in using something like:

  • Your fingerprint
  • Face recognition
  • A PIN on your phone or computer
  • A security key

Instead of waiting for a text message and typing in a code, your trusted device confirms that it's really you.

For most users, it's actually faster and easier than receiving a text message every time they sign in.

What's Changing?

Microsoft is introducing the change in stages.

September 1, 2026

Users who currently rely on text messages or voice calls for multifactor authentication (MFA) will automatically be eligible to use passkeys. The next time they complete MFA, Microsoft may encourage them to set one up.

February 1, 2027

Microsoft's built-in SMS and voice authentication services will officially be retired.

After February 1, 2027

If a user's only security method is a text message or phone call, they'll be required to register a passkey before they can continue signing in. Microsoft has stated that there will be no opt-out for this requirement.

Does This Affect My Business?

Maybe.

If your employees currently:

  • Approve sign-ins using Microsoft Authenticator
  • Use Windows Hello
  • Use security keys
  • Already use passkeys

You may already be in good shape.

If employees still receive text messages with security codes when signing in, you'll likely need to make some changes before 2027.

The Good News

This isn't just about security. It's also about convenience.

Most people can relate to waiting for a text message that never arrives, entering a code incorrectly, or having poor cell service while travelling.

Passkeys eliminate many of those frustrations while also making accounts much harder for criminals to compromise.

In other words, this is one of those rare technology changes that's both more secure and easier to use.

What Should You Do Now?

The best approach is to start planning early.

Businesses should:

  • Identify which users still rely on text message authentication
  • Begin exploring passkeys and other phishing-resistant sign-in methods
  • Let employees know that changes are coming
  • Avoid waiting until the last minute when Microsoft begins enforcing the transition

The good news is that there's still plenty of time to prepare. Starting now simply means you'll be able to make the change on your schedule instead of Microsoft's.

Need Help?

If you're not sure how your Microsoft 365 accounts are currently set up, Reality Bytes can help.

We can review your Microsoft environment, identify users who may be affected, and help create a smooth transition plan before Microsoft's deadlines arrive.

A little planning today can prevent a lot of headaches later.

Want to Learn More?

Microsoft has published detailed guidance on the upcoming changes to authentication in Microsoft 365:

Have a question? Let's talk.