Microsoft Ends SMS Authentication by 2027 as AI Phishing Attacks Make Text Codes Too Risky

2 Sources

Share

Microsoft is phasing out SMS and voice-based authentication for all users, citing the surge in AI-powered phishing attacks that make text-based codes dangerously vulnerable. IT admins face a February 2027 deadline to switch to passkeys, while personal account users should prepare for similar changes as the company mandates stronger authentication security.

Microsoft Ends SMS Authentication Amid Rising AI Phishing Threats

Microsoft announced it will discontinue support for SMS-based multi-factor authentication, marking a decisive shift in how enterprise users and personal accounts secure their logins

1

. The company cited AI-powered phishing as the primary driver behind this decision, warning that artificial intelligence has made traditional text-based authentication codes increasingly vulnerable to interception and manipulation

2

. IT admins received emails from Microsoft outlining a firm timeline: starting February 1, 2027, they will no longer be able to log into Microsoft Entra ID accounts using SMS or voice-based authentication

1

.

Source: Digital Trends

Source: Digital Trends

AI Makes SIM Swapping and Phishing More Effective

The threat landscape has fundamentally changed as AI tools enable even less skilled attackers to execute sophisticated phishing campaigns with higher success rates than pre-AI attempts

2

. Microsoft emphasized that AI has made SIM swapping attacks significantly easier, allowing bad actors to transfer phone numbers to SIM cards they control without requiring advanced technical skills

2

. Security experts have long advised against sending authentication codes via text messages because they are easily intercepted, but the company now warns that AI has amplified these risks substantially

1

. Traditional phishing strategies become far more dangerous when combined with AI capabilities that help attackers trick users into surrendering passwords and sensitive data

1

.

Two-Step Timeline for Enterprise Users

Microsoft has established a clear roadmap for the transition away from SMS authentication. Starting September 1, users accessing Microsoft Entra ID with SMS or voice authentication will be prompted to set up a passkey during sign-in

2

. This initial phase gives IT admins time to prepare their organizations for the mandatory switch. Then, on February 1, 2027, Microsoft will fully retire SMS and voice authentication for Microsoft Entra ID, making passkeys mandatory across every single tenant with no exceptions

2

. Organizations must move away from SMS or voice-based authentication before the September rollout begins if they want to avoid disruption

2

.

Personal Accounts Face Similar Changes

While enterprise users have a confirmed deadline, Microsoft has already begun phasing out SMS for authentication and password recovery on personal accounts used for services like Outlook, Xbox, and Windows 11

2

. A support document warned that the company will eventually cease sending SMS codes to ordinary Windows Home and Professional users, though the exact timeline for personal account users remains unclear

1

. Microsoft recommends that users set up passkeys now or switch to Microsoft Authenticator rather than waiting for the company to force the transition

2

.

Passkeys as a More Secure Alternative

Microsoft has promoted passkeys, biometrics, and PINs over traditional passwords and SMS codes as part of its broader authentication security strategy

1

. Passkeys are easier to set up and use while locking authentication to specific devices without storing critical data on servers, leaving nothing for attackers to steal

1

. The company already encourages users to delete their passwords and use passkeys as their first login method

1

. However, researchers recently demonstrated that systems compromised with malware can leak passkey data stored in Google Chrome's memory, highlighting that no authentication method is entirely bulletproof

1

. Meanwhile, Google recently began testing another sign-in method for users who forget their passwords and lack access to passkeys, allowing authentication through selfie video comparison

1

. The retirement of SMS authentication reflects Microsoft's recognition that passwords alone cannot protect users in an era where AI phishing attacks have become significantly more dangerous and effective

2

.

Source: TechSpot

Source: TechSpot

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved