In an email, Microsoft just warned IT admins against using SMS- or voice-based authentication and urged them to switch to passkeys due to rising AI-assisted phishing and other security threats.
Microsoft confirmed that it’ll begin blocking these authentication methods for Entra users on February 1, 2027, and regular users with a personal Microsoft account will also see similar changes.

“We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication,” Microsoft noted in an email seen by Windows Latest.
Starting February 1, 2027, Microsoft says it won’t let you access your accounts using SMS or voice authentication.

But you might wonder, how does AI even read your SMS to access your one-time passwords? According to Microsoft, AI has made it easier for attackers, even those with limited resources, to manipulate SMS and voice communication channels.
With AI, SIM swapping is easier, the company argues, and it could allow an attacker to transfer your mobile number to a SIM card they control.
Microsoft has observed a sharp rise in AI-driven attacks designed to trick you into handing over passwords and multi-factor authentication codes. Moreover, these campaigns have higher click-through rates than traditional, pre-AI-era attacks, which means users are actually falling into the hands of attackers.
All of that means AI isn’t giving attackers superpowers to access your mobile device or SIM, but it has made it much easier to deceive people and convince them to hand over credentials.
“SMS and voice are among the most vulnerable authentication methods available today and provide significantly weaker protection against phishing, SIM-swap, and replay attacks than passkeys,” Microsoft noted in the email. “Moving to phishing-resistant methods gives your organization stronger security by default.”
Microsoft has set a timeline:
- On September 1, Microsoft will begin forcing passkey registration if you use SMS or voice authentication with your Entra account. That means you’ll be nudged to set up a passkey when you try to sign in using MFA. If you don’t want to use passkeys on September 1, or you’re not ready, you’ll need to stop relying on SMS or voice authentication before the rollout.
- On February 1, 2027, Microsoft will fully retire SMS and voice authentication in Entra ID, and you’ll need to use a stronger authentication method such as passkeys.
“There is no opt out from this enforcement; it applies to all tenants,” the company warns, so it’s clear Microsoft isn’t playing around with the change.
What about personal Microsoft account/Outlook account users?
What if you use a personal Microsoft account, whether through an Outlook.com alias, Gmail address, or anything else? Will you be affected? According to Microsoft, regular consumers will also eventually lose SMS authentication and be nudged toward passkeys instead.

In a support document spotted by Windows Latest, Microsoft has already confirmed that it views SMS-based authentication as a leading source of fraud and has begun phasing out SMS for authentication and account recovery on personal accounts.
“Microsoft is committed to advancing security standards, and as such, we will start phasing out SMS as a method of authentication and account recovery for personal Microsoft accounts,” Microsoft noted in a document.
“Microsoft believes that the future of authentication is passwordless, secure, and user-friendly.”
While enterprises have a February 1 deadline to keep in mind, Microsoft has not given regular Microsoft account users a similar cutoff date yet. These accounts are used to sign in to Windows 11, Xbox, Outlook, and dozens of other services, so the change will eventually affect a much broader group of users.
I recommend not waiting for Microsoft to block SMS authentication on your account. You can set up a passkey now or use Microsoft Authenticator if that’s what you prefer.
If you’re not comfortable with either option, passwords will still exist in some scenarios, but they’re also vulnerable to phishing, including AI-assisted attacks. That’s exactly why Microsoft is pushing users toward phishing-resistant authentication in the first place.
The post Microsoft warns you to stop using SMS-based passwords because of AI phishing, and it’ll block you starting with Entra ID appeared first on Windows Latest
