Microsoft to retire SMS login as AI phishing surges
Passkeys become default for Entra ID this September, with SMS and voice gone by 2027
Microsoft has told IT administrators to move off SMS and voice-based authentication, warning that AI has made phishing attacks against these methods far more effective.
The company is replacing them with passkeys as the default sign-in method for Microsoft Entra ID, its identity and access management platform.
In a message spotted by Windows Latest, Microsoft said generative AI has lowered the skill bar for attackers targeting SMS and voice channels and made SIM swapping easier to pull off, letting bad actors redirect a victim's phone number to a device they control.
On another note, Microsoft's security blog has independently announced that there has been a dramatic increase in AI-powered password and multifactor code thefts, which have shown significantly higher success rates compared to previous phishing attempts that used non-AI technology.
Passkeys should be able to counter this trend, as the private key is stored on the user’s device; hence, it cannot be stolen by fraudulent login pages.
The transition process occurs in several phases. On September 1, 2026, all users of Entra ID with enabled SMS or voice authentication will be enrolled in passkeys automatically and will be required to register their passkeys during the next multifactor authentication session.
Those administrators who want some more time may defer this transition temporarily using the opt-out feature, which will be provided through Microsoft Graph starting from August 1, 2026.
Microsoft also plans to publish supported third-party telecom provider options on September 18, 2026, for organisations that still require phone-based verification, with configuration required by October 30, 2026.
Microsoft-provided SMS and voice authentication will be retired outright on February 1, 2027, with no exemptions available at that point.
Tenants that haven't configured a customer-managed telecom provider through the Microsoft Security Store by then will find affected users locked out of SMS or voice sign-in entirely, facing a blocking prompt to register a passkey before they can continue.
The changes apply directly to Entra ID, Microsoft's enterprise identity system, but personal Microsoft accounts tied to Outlook, Xbox, and Windows 11 are also being nudged away from SMS-based verification and recovery.
-
OpenAI faces senate probe after Rogue AI agents breach Hugging Face
-
Google launches Gemini app for windows: Everything you need to know
-
OpenAI meets power companies in urgent push to protect grid from AI cyber threats
-
Snapchat plans let you invite up to 200 friends
-
153 million driver's licences stolen in IDScan breach
-
OpenAI calls for binding national AI safety framework to counter autonomous agent risks
-
Apple iPhone 16, 17, Air got $100 more expensive
-
Why AI's own builders are suddenly begging you to slow down