Comserv Connect
← Back to Blog
Cybersecurity

Microsoft Is Retiring Texted Login Codes. What Small Businesses Should Do Now.

By Comserv Connect TeamReviewed by Chris Ferrera

If your team signs in to Microsoft 365 and gets a verification code by text message, that method now has an expiration date. Microsoft has confirmed the change and published the dates in plain sight, so there is no rumor to chase and no reason to panic. You have real runway, and the businesses that move early will barely notice the switch.

Here is the calm, no-lockout way to get ahead of it.

What Is Actually Changing

Two dates matter. Starting September 1, 2026, passkeys become the default sign-in prompt in Entra, the identity system behind Microsoft 365. Then on February 1, 2027, Microsoft retires its own text-message and phone-call verification codes. After that, texted and called codes only keep working if a business plugs in its own separate telecom provider.

A passkey is a sign-in tied to your device or a physical key. There is no code to read aloud, intercept, or be talked into sharing, because there is no code at all. An authenticator app with number matching sits in the same family: something an attacker cannot phish out of a distracted employee over the phone.

One thing to be clear about, because it causes real confusion: multi-factor authentication is not going away. It is getting stronger. Only the text-and-call method is being retired. If anyone tells you "Microsoft is turning off MFA," they have it backwards.

Why Microsoft Is Doing This

Texted codes were never great security, and the reason is simple. Until fairly recently it was easy for a criminal to spoof or steal someone's SIM card, take over their phone number, and receive the very code that was supposed to protect the account. That attack has a name (SIM swapping) and it has cost people real money. A passkey removes the code from the equation entirely, so there is nothing to steal in transit.

Who This Affects

Anyone on Microsoft 365 whose staff receive a login code by text message or automated phone call. If your people already use the Microsoft Authenticator app or a passkey, this change will pass you by quietly. If some of them still get a code by text, those are the accounts to move first.

What To Do, In Order

You have months, not days, so use them deliberately instead of scrambling at the deadline.

  1. Inventory who still receives a code by text or call. This is the whole job in one step: you cannot move people you have not counted.
  2. Move those staff to the Microsoft Authenticator app or a passkey.
  3. Decide whether any device or line-of-business system truly needs a backup telecom provider, or whether you can retire the texted-code path completely.
  4. Do it before February 2027, not on it. The organizations that wait until the deadline are the ones that risk locking staff out.

How Comserv Handles This for Clients

We already have every one of our clients on an authenticator app rather than texted codes, so for them this is a non-event. When we move a business off texted codes, the part that takes care is timing: making sure the switch happens cleanly and nobody loses access for an extended stretch in the middle of a workday. That is a planning problem, not a hard technical one, and it is exactly the kind of thing worth handing to someone who does it for a living.

If you are an owner reading this and worrying it will lock your staff out, here is the honest answer: give us a call and we will make sure it goes flawlessly. One account at a time, no scramble, no lockouts.

Want to know where your business stands before the deadline? Book a free strategy call or call (347) 273-1200, and we will walk through your sign-in setup with you.

Sources

  1. Microsoft Entra: SMS and voice call authentication retirement
  2. Microsoft 365 Message Center notice MC1426371

Ready to Strengthen Your Security?

Get a free strategy call with our team to assess your current IT and cybersecurity posture.