Learn

Microsoft Is Turning Off Text-Message Sign-In Codes. Here Are the Two Dates That Matter.

Most people reading this have the same login routine. You type your password, Microsoft texts you a six-digit code, you type that in, you're working.

Microsoft is removing that method entirely.

The announcement went to every Microsoft 365 tenant earlier this month, and like most tenant notifications it went to whoever holds the admin account, which is usually not the person who will have to explain the change to twenty employees. So here is the version for the person who runs the business.

The two dates

September 1, 2026. Anyone currently set up to receive codes by text or phone call gets switched on for passkeys automatically, and Microsoft starts prompting them to create one after they log in. Nobody is blocked. The prompt can be dismissed, indefinitely for now. But your staff will start seeing an unfamiliar screen asking them to set up something they have never heard of, and some of them will call someone about it.

February 1, 2027. Microsoft stops delivering codes by text and voice entirely. From that point, anyone whose only login method is a texted code hits a screen they cannot dismiss: set up a passkey, or you don't get in.

Microsoft's own wording on that second date is unusually blunt. There is no opt out, and it will be enforced for every tenant.

Worth one footnote, because it shows how fresh this is. Microsoft's documentation says February 1st, while the script Microsoft published for admins to check their own exposure prints January 28th. Four days apart, in first-party material released the same week. We are planning to the earlier date. If it turns out to be wrong, being early costs nothing.

Nobody gets locked out, and that is less reassuring than it sounds

Microsoft is careful to say users won't lose their accounts, and that is true. The February behaviour is a registration prompt, not a lockout.

In practice the distinction matters less than it reads. An employee who sits down at 8:05 on a Monday and gets a mandatory security-setup screen between them and their email is not going to work through it calmly. They are going to call. And if that is the first they have heard of it, they will assume something is broken or that they have been hacked.

The technical change here is small. The change-management problem is the whole thing.

Why Microsoft is doing it

Texted codes were a genuine improvement over passwords alone, and for a decade they did real work. What changed is that attackers adapted specifically to them.

Three ways a texted code fails:

SIM swapping. Someone convinces your mobile carrier to move your number to a phone they control. The code arrives on their device. Your phone quietly stops having service.

Relay phishing. You land on a convincing Microsoft login page that is, in fact, relaying your session to the real Microsoft in real time. You enter your password. You enter your texted code. Everything works, because everything really did happen. Meanwhile the attacker captures the session token issued afterwards, which is the part that actually keeps you signed in. The code did its job perfectly and protected nothing.

Plain interception. Text messaging was never designed as a secure channel and does not behave like one.

A passkey closes these because it is cryptographically bound to the site that issued it. It cannot be read aloud, forwarded, typed into the wrong page, or handed to a convincing stranger on the phone. There is no code to intercept, because there is no code.

What a passkey actually is, in plain terms

The word is new; the experience is not. A passkey is your device proving it is you, using the fingerprint, face, or PIN you already use to unlock your phone or laptop. Signing in becomes the same gesture you make fifty times a day to open your own phone.

For most staff, the change makes logging in faster. The friction is entirely in the switchover, not in the destination.

What to do, in order

Find out whether this affects you at all. Some organizations have already moved to an authenticator app and have nothing to do. Others have most of their staff on texted codes and do not know it. This is a question with a definite answer, and it is worth getting before September rather than after.

One caution for anyone checking themselves. The script Microsoft provides for this reports on your policy, meaning whether text codes are switched on as an option. It does not report who is actually using them. A tenant can report "no action required" while a good portion of staff still log in by text, if those users are covered by older settings the script does not examine. The report you want is the per-user registration detail, not the policy summary.

Move people deliberately, before Microsoft moves them. Acting before September 1st means your staff hear about this from you, on a schedule you pick, with a heads-up. Acting after means they meet it as a surprise prompt mid-task. Same technical outcome, very different day.

Tell people first, then change the setting. The single biggest predictor of a smooth rollout is that people knew it was coming. This is not a technical claim; it is the consistent pattern in how these transitions go well or badly.

Do not forget password resets. The retirement covers self-service password reset too, not only login. If your staff currently recover a forgotten password by texted code, that path is closing on the same schedule, and it is the one people discover at the worst possible moment.

If you genuinely need text codes, there is a paid path. Organizations with a real regulatory requirement can contract a telecom provider directly through Microsoft to keep text messaging working. Options are published in late September and configurable from the end of October. It costs per message. For nearly every small business, passkeys are both free and stronger, though the option exists if a regulator requires it.

The part worth sitting with

This is the second major authentication change Microsoft has pushed through in two years, and it will not be the last. The pattern is consistent. The security floor keeps rising, the deadlines are firm, and the notifications go to an admin mailbox rather than to the people whose Monday morning is affected.

The organizations that handle these well are not the ones with better technology. They are the ones where somebody was reading the tenant notifications in August instead of finding out in February.

Sources: Microsoft Entra documentation on the retirement of Microsoft-provided SMS and voice authentication, its accompanying FAQ, and Microsoft's authentication methods activity reporting guidance.


We manage Microsoft 365 for businesses and nonprofits across the Kansas City metro, which includes reading the notifications nobody else opens and getting ahead of dates like these. If you are not certain whether your staff are affected, we can find out for you.

September 1st is about two weeks away. Do you know which of your people still sign in with a texted code?