Two dates are now fixed in Microsoft's calendar, and they concern every business that signs into . From September 2026, become the default sign-in prompt in . On 1 February 2027, SMS and voice codes stop working as authentication methods altogether.
Neither change is a surprise to anyone who has watched where account attacks have gone over the past few years. But a published retirement date turns a good intention into a deadline, and most Australian businesses we talk to have at least a handful of staff still receiving codes by text.
What Microsoft actually announced
These are two separate changes, and they are worth keeping apart.
The first is a default. From September 2026, new sign-in setups in Microsoft Entra will prompt for a first rather than offering the older menu of methods. Nobody is locked out by this one. It simply moves the strongest method to the front of the queue for anyone enrolling fresh.
The second is a removal. On 1 February 2027, SMS and voice call verification retire as sign-in methods. A staff member whose only registered method is a text message will not be able to authenticate. That is the date that matters for planning, because it is the one with a failure mode attached.
Microsoft Authenticator is not going anywhere. Push notifications and app-based passkeys remain. The retirement is specific to codes delivered over the phone network.
Why the SMS code had to go
The text message code was a reasonable answer in 2012. The problem it developed is not that the cryptography failed, it is that a person can be talked into typing a code into the wrong window. kits now proxy the real login page in real time, collect the code the moment it is entered, and use it before it expires. The code did exactly what it was designed to do. It just proved possession of a phone to the wrong party.
SIM swapping adds a second route. Convince a telco to move a number to a new SIM and the codes follow. Neither attack requires much sophistication anymore, which is why the methods that depend on a human reading and retyping a secret are being retired across the industry, not just at Microsoft.
What counts as a proper replacement
The replacement standard is phishing resistance, and the property that delivers it is domain binding. A passkey created for your Microsoft tenancy will not respond to a lookalike domain, no matter how convincing the page looks. There is no code to read and nothing to retype, so there is nothing for a proxy site to capture.
Passkeys come in two forms, and the difference matters once compliance enters the picture. A synced passkey lives in a platform account and follows you between devices. A device-bound passkey lives in one piece of hardware, such as a security key, and cannot be copied off it. Both resist phishing. Frameworks that call for , including the Essential Eight at its higher maturity levels, generally have the device-bound kind in mind for the accounts that matter most.
For most staff, a passkey in Microsoft Authenticator is a genuine upgrade and costs nothing. The store guide on Authenticator passkeys versus hardware keys works through where each one fits.
Why we put YubiKeys on the shelf
We have deployed hardware security keys for clients for years, usually for admin accounts and for workforces where a personal phone cannot be part of the sign-in story. A clinic front desk, or a finance team with elevated access. Somewhere in every rollout, the same task appeared: helping the client buy the keys, because doing it well means knowing which of sixteen nearly identical black rectangles fits which port, and which of them a phone can tap.
So we became the shop we kept wishing existed. Our store stocks the YubiKey range in Australia with GST-inclusive pricing, a tax invoice on every order, and product pages that say plainly who each key suits and who it does not. We chose Yubico because it is the hardware we have put in front of clients through every rollout we have run, and it has never been the part of the project that failed.
The honest caveat belongs here too. Plenty of businesses will not need hardware at all. If every staff member has a company-managed phone and none of them holds privileged access, Authenticator passkeys may be the whole answer. Our product pages and guides say so, because a key that comes back in a drawer clean-up helped nobody.
A sensible order of operations
The gap between now and February 2027 is generous if you use it, and uncomfortable if you spend it deciding to decide.
Start by finding out who still uses codes. The authentication methods report in Entra shows every user's registered methods, and the sign-in logs show what they actually use. The list is usually shorter than feared and more senior than expected.
Then choose the replacement per group rather than per company. Office staff with managed phones go to Authenticator passkeys. Admins and finance go to hardware keys. Shared-device workers get keys because a personal phone was never available to them anyway.
Pilot with your IT team and one ordinary team before the wide rollout, and have every person register a second method at enrolment. The backup method is not an optional extra. Account recovery without one is the worst afternoon in this whole subject.
Finally, turn off the legacy methods yourself rather than waiting for Microsoft's date to do it for you. A Conditional Access policy can require phishing-resistant methods for privileged accounts first, which is where the risk concentrates, and the rest of the business can follow on a schedule you control.
Do we have to buy hardware keys?
No. Passkeys in Microsoft Authenticator satisfy the new default for most users. Hardware keys earn their place for privileged accounts, and for settings where a personal phone is unavailable or inappropriate to ask for.
What happens if we do nothing before 1 February 2027?
Any user whose only registered methods are SMS or voice will be unable to sign in once the methods retire. In practice that surfaces as a helpdesk queue on the first morning, so the fix is a planned enrolment now rather than an unplanned one then.
Is Microsoft Authenticator being retired too?
No. The app, its push notifications and its passkeys all remain. The retirement covers codes delivered by text message and voice call only.
Where to from here
If you want the enrolment, the policy and the backup-key discipline handled, that is work we do week in and week out. And if you just need the hardware with straight advice attached, the store is open.


