Microsoft Is Retiring Text-Message Sign-In Codes. Here Is What Your Business Needs to Know
- Asheville Computer Company
- 6 hours ago
- 4 min read
If your team signs into Microsoft 365 by typing in a code from a text message or a phone call, that routine has an expiration date. Microsoft has announced it is retiring its own SMS and voice sign-in codes across Microsoft 365 and Entra ID, and this time there are hard dates attached, including one with no opt-out.
Here is what is changing, when, and what a well-prepared small business should do about it. Nothing here requires panic. It does require a plan, and the window for an easy transition is open right now.

The dates that matter
Microsoft's timeline has two milestones every business owner should know:
September 1, 2026. Users who currently sign in with texted or voice codes will automatically have passkeys enabled, and Microsoft will start nudging them to register one when they sign in. The nudge can be snoozed, so nothing breaks on this date. It is the on-ramp.
February 1, 2027. Microsoft-provided text and voice codes stop working entirely. Anyone whose only sign-in verification is a texted code will hit a blocking prompt: register a passkey before you can continue signing in. Microsoft is explicit that there is no opt-out from this enforcement, for any organization.
In other words, this is not one of those Microsoft changes that quietly slips a year. Between those two dates, every user still on texted codes will be moved, nudged, and eventually required to change.
Why Microsoft is doing this
The honest answer is that text-message codes were never a great lock. They protect against the laziest attacks, but they are among the weakest forms of multi-factor authentication: codes can be phished by a convincing fake login page, intercepted through SIM-swap tricks where an attacker takes over your phone number, or simply read out to a scammer by a helpful employee on a phone call.
We have written before about how attackers phish credentials and talk employees into approving sign-ins. Texted codes are the exact layer those attacks are built to beat. Microsoft's answer is to make phishing-resistant sign-in the default for everyone.
What is a passkey, in plain language
A passkey replaces the typed-in code with your device itself. When you sign in, your computer or phone proves it is really you using the same unlock you already use, your fingerprint, your face, or a PIN, backed by cryptography under the hood.
The practical differences from texted codes:
There is no code to phish. A fake login page has nothing to steal, because the passkey only works with the real site.
There is nothing to intercept. SIM-swapping your phone number gets an attacker nothing.
It is usually faster. A touch or a glance beats waiting for a text and typing six digits.
Passkeys can live in Microsoft Authenticator on a phone, in Windows Hello on a PC, in iCloud Keychain or Google Password Manager, or on a physical security key for special cases. For most office workers, the experience is "tap yes and look at the camera," which is an easier sell to staff than most security changes.
One more point worth knowing: moving to passkeys costs nothing. Microsoft does offer a paid escape hatch for organizations that genuinely must keep SMS codes, through third-party telecom providers in its new Security Store, but that route carries per-message costs and is intended for regulated edge cases, not as the default for a typical small business.
What your business should actually do
For most of the businesses we work with in Asheville, Arden, Fletcher, Hendersonville, and across Western North Carolina, the plan looks like this:
1. Find out who still uses texted codes
Most organizations have a mix: some people already approve sign-ins in an app, others still get texts. Microsoft provides tools for administrators to list exactly who is still on SMS or voice codes. That list is your to-do list.
2. Move people before Microsoft moves them
The difference between a smooth transition and a chaotic one is whether registration happens on your schedule or during a Monday morning rush in February when a blocking prompt appears. Registering a passkey takes a couple of minutes per person when it is planned: a short announcement, a simple how-to for each device type, and a nudge campaign that runs while there is no deadline pressure.
3. Do not forget the odd corners
Shared mailboxes, front-desk computers that multiple people use, employees without smartphones, and any system that sends codes for password resets all deserve a look before February. There are good answers for each of these, including security keys for shared or phone-free situations, but they are much easier to sort out in advance.
4. Treat it as an upgrade, not a chore
This change genuinely improves your security posture. The attacks that hurt small businesses most, phished passwords and stolen codes, get dramatically harder against passkeys. If you have been meaning to tighten up sign-in security anyway, Microsoft just handed you the occasion and the deadline.
How we can help
If Asheville Computer Company manages your Microsoft 365, we will be reaching out about this well before the deadlines, identifying who in your organization is still on texted codes and planning the transition around your schedule. If you handle your own IT and want a second set of eyes on it, or you are not sure whether your setup is affected, we are glad to take a look and map out the steps with you.
Sign-in security is one of those areas where a small amount of planning prevents a very annoying morning. September is the on-ramp. February is the wall. The businesses that plan for the first date will never notice the second one. Managed IT clients get this kind of change handled before it becomes a deadline.
Source and further reading: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication (Microsoft Learn)


