Microsoft stops sending text-message and phone-call sign-in codes to most Microsoft 365 accounts on February 1. Here's what to sort out before your team hits a prompt they can't skip.
Someone on your team signed in to their email this month and hit a screen they'd never seen before: Microsoft asking them to set up something called a passkey. No warning from you, nothing from your IT provider. To a cautious person it looks exactly like the phishing screens you've trained them to distrust.
It's genuine. And there's a deadline behind it.
Two dates
Microsoft is retiring the text-message and automated phone-call codes it sends out for Microsoft 365 sign-ins.
The first date has already passed. On September 1, everyone set up to receive a code by text or call was switched on for passkeys automatically, and Microsoft started prompting them to register one after they sign in. Microsoft's own documentation notes that the prompt can be snoozed an unlimited number of times — which is why most people clicked past it and forgot.
The second is February 1, 2027, when Microsoft stops sending those codes to nearly everyone; global administrator accounts and outside guests get until July 1, 2027. The documentation is unusually blunt about it: "There is no opt out from this February 1 behavior for users in scope of the February 1 retirement."
After that date, anyone whose only sign-in method is a texted code meets a prompt to register a passkey that they cannot skip. Microsoft's own word for it is "blocking." Nobody is locked out forever — they can complete the setup and get in. But they're doing it cold, first thing on a Monday, with no idea it was coming.
That's the real exposure here, and it isn't a breach. It's a morning where four people can't open their email and nobody in the building knows why.
No, the Authenticator app isn't going away
This affects two things only: codes sent by text message, and codes read out by an automated phone call. If your people tap Approve in the Microsoft Authenticator app, or type a number the app generated, February changes nothing for them.
Worth being precise about, because "Microsoft is changing MFA" is exactly the kind of half-heard news that sends an office chasing the wrong problem.
Why they're doing it
Texted codes were always the weakest rung on the ladder. Microsoft's FAQ on the retirement now says SMS and voice "are among the most vulnerable authentication methods available today."
Two reasons for that. A phone number can be taken — an attacker talks a mobile carrier into moving it to a SIM card they control, and the codes follow. Far more common in practice, though: the code can simply be asked for. A convincing fake login page collects the password, then asks for the six digits, and someone types them into the real Microsoft site inside the minute they stay valid. We've walked through how that attack works. A code a person can read out is a code a person can be talked into reading out.
A passkey can't be handed over. It lives on the phone or laptop, unlocks with a fingerprint or a face, and only works on the genuine Microsoft sign-in page. There is nothing for a user to repeat to a stranger on the phone.
What to do between now and February
Tell your team the prompt is real. One message to everyone. Otherwise you're asking people to tell a legitimate unexpected login prompt apart from a fraudulent one — precisely the judgement call you want them failing safely. Two minutes, and it saves the support calls.
Find out who's still on text codes. Ask your IT provider by name: "Which of our users are still set up for SMS or voice sign-in, and what's the plan to move them before February 1?" Microsoft publishes a script that produces exactly that list, so whoever administers your Microsoft 365 can answer properly rather than guess. Individuals can also check their own methods under Security info in their Microsoft account settings.
Get passkeys registered while it's still optional. A couple of minutes per person, at a desk, with someone on hand to help — that beats the same task done under a blocking prompt in February with a customer waiting. The Microsoft Authenticator app most teams already have can hold one.
If your business genuinely needs text codes, some regulated industries among them, Microsoft is opening a route to contract your own telecom provider from October 30. It costs extra, with the price depending on the provider and how much you use it, and it takes setting up. For most small businesses, passkeys are the cheaper and the better answer.
Changes like this one land quietly in a settings page nobody opens. A read-only scan from Tenant Strike grades how your Microsoft 365 is set up, A to F, and shows the exact fix for each gap it finds — it reads your settings and never changes them.
AI-researched from public sources. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike finds the security gaps in your Microsoft 365 and Azure, shows how they chain into a real break-in, and hands you a plain-English fix for every one — read-only, and it never asks for permission to change anything. Start a 7-day Pro trial — no credit card.