2 Sources
[1]
Microsoft is killing off SMS authentication codes as AI makes phishing attacks even more dangerous
Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. In brief: Sending codes to users via SMS has long been discredited as the least secure multi-factor authentication method, and Microsoft will soon discontinue support for this practice altogether. Citing the rising danger of hackers armed with AI tools, the company has now provided a timeline for phasing out SMS codes. IT admins will no longer be able to log into Microsoft Entra ID accounts using SMS-based 2FA codes starting February 1. The deadline is part of Microsoft's broader shift toward passkeys, widely considered one of the most secure login methods. Admins recently began receiving an email from the company, obtained by Windows Latest, which outlines the SMS phaseout. Earlier this year, a support document also warned that Microsoft will eventually cease sending SMS codes to ordinary Windows Home and Professional users, but when that will happen remains unclear. Security experts have advised against sending 2FA codes via text messages for years, primarily because they are easily intercepted. However, Microsoft's recent announcement also claims that AI has made phishing and other hacking methods more effective. Traditional phishing strategies are more likely to trick users into handing over passwords and other sensitive data when used in tandem with AI. The technology also makes it easier for attackers to carry out SIM-swapping attacks. A recent Windows 11 update also retired picture passwords. Initially introduced to promote Windows 8's touch capabilities, tracing gestures over pictures to log into Windows has not been considered truly secure for some time. Microsoft has instead promoted PINs, biometrics, and passkeys over other methods, especially passwords. The company already encourages users to delete their passwords and use passkeys as their first login method. Starting September 1, Entra will prompt users to establish a passkey. Easier to set up and use, passkeys lock authentication to specific devices without storing critical data on servers, leaving nothing for attackers to steal. However, researchers recently demonstrated that systems compromised with malware can leak passkey data stored in Google Chrome's memory. Meanwhile, Google recently began testing another sign-in method for users who forget their passwords and do not have access to passkeys. After providing the company with a selfie video, users can log in from any other device by uploading another one, which is compared to the original. It remains to be seen whether the method is more or less secure than other biometric options.
[2]
Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop
AI made phishing too easy, so Microsoft is closing the door on SMS logins. Microsoft just sent a warning to IT admins, and it's a big one. The company wants everyone to stop using SMS and voice-based authentication, and it's citing AI-powered phishing as the main reason. Why is Microsoft killing SMS authentication? In an email spotted by Windows Latest, Microsoft explained that the AI era calls for stronger, phishing-resistant authentication. Basically, AI has made it far easier for attackers, even the less skilled ones, to manipulate SMS and voice channels. SIM swapping has also become easier with AI, allowing bad actors to move your number to a SIM card they control without much effort. Microsoft says it's seeing a sharp rise in AI-driven attacks to steal passwords and MFA codes, and these attacks have a noticeably higher success rate than older, pre-AI phishing attempts. So no, AI isn't hacking your SIM card directly, but it is making it a lot easier to trick people into handing over their credentials willingly. When is this happening? Microsoft has laid out a two-step timeline. Starting September 1, Entra users using SMS or voice authentication will be asked to set up a passkey during sign-in. If you're not ready for that switch, you'll need to move away from SMS or voice authentication before the rollout begins. Then, on February 1, 2027, Microsoft will fully retire SMS and voice authentication for Entra ID, and passkeys will become mandatory. There's no opt-out either, so every single tenant will be affected, no exceptions. What about personal accounts? If you use a personal Microsoft account for Outlook, Xbox, or Windows 11, you're not off the hook either. Microsoft has already started phasing out SMS for authentication and account recovery on personal accounts too, though there's no confirmed deadline yet for regular users. Recommended Videos We should suggest not waiting around for Microsoft to flip the switch on you. Set up a passkey now, or switch to Microsoft Authenticator if that's more your style. Passwords alone just aren't cutting it anymore, especially with AI making phishing scarier by the day.
Share
Copy Link
Microsoft is phasing out SMS and voice-based authentication for all users, citing the surge in AI-powered phishing attacks that make text-based codes dangerously vulnerable. IT admins face a February 2027 deadline to switch to passkeys, while personal account users should prepare for similar changes as the company mandates stronger authentication security.
Microsoft announced it will discontinue support for SMS-based multi-factor authentication, marking a decisive shift in how enterprise users and personal accounts secure their logins
1
. The company cited AI-powered phishing as the primary driver behind this decision, warning that artificial intelligence has made traditional text-based authentication codes increasingly vulnerable to interception and manipulation2
. IT admins received emails from Microsoft outlining a firm timeline: starting February 1, 2027, they will no longer be able to log into Microsoft Entra ID accounts using SMS or voice-based authentication1
.
Source: Digital Trends
The threat landscape has fundamentally changed as AI tools enable even less skilled attackers to execute sophisticated phishing campaigns with higher success rates than pre-AI attempts
2
. Microsoft emphasized that AI has made SIM swapping attacks significantly easier, allowing bad actors to transfer phone numbers to SIM cards they control without requiring advanced technical skills2
. Security experts have long advised against sending authentication codes via text messages because they are easily intercepted, but the company now warns that AI has amplified these risks substantially1
. Traditional phishing strategies become far more dangerous when combined with AI capabilities that help attackers trick users into surrendering passwords and sensitive data1
.Microsoft has established a clear roadmap for the transition away from SMS authentication. Starting September 1, users accessing Microsoft Entra ID with SMS or voice authentication will be prompted to set up a passkey during sign-in
2
. This initial phase gives IT admins time to prepare their organizations for the mandatory switch. Then, on February 1, 2027, Microsoft will fully retire SMS and voice authentication for Microsoft Entra ID, making passkeys mandatory across every single tenant with no exceptions2
. Organizations must move away from SMS or voice-based authentication before the September rollout begins if they want to avoid disruption2
.Related Stories
While enterprise users have a confirmed deadline, Microsoft has already begun phasing out SMS for authentication and password recovery on personal accounts used for services like Outlook, Xbox, and Windows 11
2
. A support document warned that the company will eventually cease sending SMS codes to ordinary Windows Home and Professional users, though the exact timeline for personal account users remains unclear1
. Microsoft recommends that users set up passkeys now or switch to Microsoft Authenticator rather than waiting for the company to force the transition2
.Microsoft has promoted passkeys, biometrics, and PINs over traditional passwords and SMS codes as part of its broader authentication security strategy
1
. Passkeys are easier to set up and use while locking authentication to specific devices without storing critical data on servers, leaving nothing for attackers to steal1
. The company already encourages users to delete their passwords and use passkeys as their first login method1
. However, researchers recently demonstrated that systems compromised with malware can leak passkey data stored in Google Chrome's memory, highlighting that no authentication method is entirely bulletproof1
. Meanwhile, Google recently began testing another sign-in method for users who forget their passwords and lack access to passkeys, allowing authentication through selfie video comparison1
. The retirement of SMS authentication reflects Microsoft's recognition that passwords alone cannot protect users in an era where AI phishing attacks have become significantly more dangerous and effective2
.Source: TechSpot
Summarized by
Navi
[1]
16 Apr 2025•Technology

19 Mar 2025•Technology

12 May 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
