Microsoft SMS MFA retirement: Cambridge life sciences guide
If your team still gets a text code every time they sign into Microsoft 365, the clock just got louder.
From 1 September 2026, Microsoft Entra ID began treating passkeys as the default authentication experience for tenants where SMS or voice MFA is still enabled. Users who rely on text or phone-call codes are being nudged to register a passkey. From 1 February 2027, Microsoft-provided SMS and voice delivery is retired. After that date, anyone whose only MFA method is SMS or voice faces a blocking passkey registration prompt before they can carry on signing in. There is no opt-out from that February behaviour.
For Cambridge and Cambridgeshire SMEs — especially life-sciences, regulated and science-park firms already juggling audit trails, Cyber Essentials-style controls and hybrid work — this is not a “set a reminder for January” job. It is an autumn project: map who is still on SMS, pick phishing-resistant methods that fit your people, and roll them out before helpdesk chaos becomes a board problem.
What’s changing (and what isn’t)
Microsoft’s own guidance is blunt. Passkeys become the default. SMS and voice are no longer positioned as secure authentication methods, and Microsoft will stop providing those telecom channels natively in Entra ID from February 2027. Organisations that genuinely still need SMS or voice for a narrow operational or regulatory reason will need a customer-managed telecom provider through the Microsoft Security Store (selection opens later in 2026). For everyone else, the path is passkeys, Windows Hello for Business, or FIDO2 security keys.
If you already use passkeys, Windows Hello or another phishing-resistant method, keep going. Those users are largely unaffected. The risk sits with people still enabled for SMS or voice in the Authentication methods policy (or older MFA settings). From September, many of them will see registration nudges. From February, if SMS or voice is all they have, the prompt becomes blocking.
A temporary opt-out exists for the automatic September passkey enablement while you prepare. It does not stop the February 2027 enforcement. Leaving SMS as “good enough” until next winter is how quiet tenants become noisy Monday mornings.
Why SMS MFA was never enough
Text codes feel familiar. They also travel over a channel attackers already understand: SIM-swap, number recycling, phishing kits that relay live MFA prompts, and social-engineering calls that talk people into reading out a code. Traditional MFA — passwords plus SMS, voice, app OTP or push — still helps against casual password reuse. It remains phishable when someone is in the middle of a real login session.
That matters because phishing is still the attack UK businesses actually see. The government’s Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses identified a cyber security breach or attack in the previous 12 months, and phishing remained the most common type (38% of businesses). Among those that identified a breach or attack, phishing was also the most disruptive.
The NCSC now recommends passkeys wherever a service supports them, with traditional two-step verification as the fallback where it does not. In plain terms: if Microsoft is offering a stronger door lock for your Microsoft 365 tenant, keep using the text code only while you fit the new one.
What a passkey actually is
Skip the cryptography lecture. A passkey is a login credential tied to a device or a synced credential manager. Your phone or laptop proves it holds the private key; the service holds the matching public key. There is no shared secret for an attacker to steal from a fake login page and replay elsewhere.
Microsoft Entra ID supports two broad flavours:
Either way, the user experience is usually “approve with Face ID / fingerprint / PIN / tap the key”, not “wait for a text and type six digits under pressure”.
Practical options for a small Microsoft 365 tenant
You do not need an enterprise IAM programme. You need a short list that matches how your people work.
Passkeys in Microsoft Authenticator work well for hybrid staff who already have the Authenticator app. Pair that with clear recovery steps so a lost phone does not lock someone out of SharePoint on deadline day.
Windows Hello for Business suits desks and laptops that are Entra-joined or hybrid-joined. Face or PIN unlock becomes the daily habit; MFA stops feeling like a tax on every Teams call.
FIDO2 security keys earn their keep for privileged admins, shared workstations where phones are awkward, and regulated environments that prefer a physical factor you can inventory. They are also a solid second method beside a phone-based passkey.
For life-sciences and other regulated SMEs around Cambridge, treat authentication method quality as part of the same story as access reviews, privileged accounts and evidence for auditors. “We have MFA on” is no longer the whole answer. Auditors, insurers and larger customers increasingly ask which MFA — and whether it resists phishing.
Avoid a free-for-all. Decide which methods are allowed, who must use a hardware key (hint: Global Admins), and how you handle contractors on BYOD. Document it. Ten minutes of policy now beats a week of one-off exceptions later.
An autumn migration plan that doesn’t wreck the week
Aim to finish core registration well before Christmas if you can. February 2027 sounds distant until half the lab is stuck behind a blocking prompt on the morning of a regulatory submission.
What happens if you wait until February 2027
Users whose only MFA method is still Microsoft-provided SMS or voice will hit a blocking passkey registration prompt at sign-in. No opt-out. For a quiet professional-services firm that might mean a busy helpdesk afternoon. For a regulated or science-park tenant with shift patterns, shared lab PCs and external collaborators, it can look like an outage.
Waiting also wastes the September window, when nudges are still soft and you can coach people calmly. Leaving everything to a hard cutover is how “we meant to do MFA properly” turns into “why can’t finance open the ERP?”
For the wider hardening and phishing picture, see our cyber security page, or managed IT for Cambridgeshire firms that need day-to-day Microsoft 365 support alongside a calm passkey rollout.
How CAMBITION helps
CAMBITION works with Cambridgeshire SMEs every week on Microsoft 365 hardening that stands up to real audits and real phishing — not checkbox MFA. We can run a short authentication review: who is still on SMS or voice, which phishing-resistant methods fit your devices and compliance story, and a calm passkey rollout plan before February 2027.
If you want that review booked while autumn diaries still have gaps, call 01223 656 156 or use https://cambition.co.uk/contact/.
Frequently asked questions
When does Microsoft retire SMS and voice MFA?
Microsoft-provided SMS and voice authentication in Entra ID is retired from 1 February 2027. Passkeys became the default experience from 1 September 2026 for users enabled for SMS or voice.
What should UK SMEs use instead of SMS MFA?
Passkeys (synced or device-bound), Windows Hello for Business, or FIDO2 security keys — phishing-resistant methods Microsoft and the NCSC recommend where available.
Will sign-in break if we do nothing?
After 1 February 2027, users whose only MFA method is SMS or voice face a blocking passkey registration prompt before they can continue signing in.
© CAMBITION I.T. Services Ltd
Head Office
Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridgeshire, CB22 7RG
VAT# 136 186 313 · Registered in the UK # 808 4429
View Privacy / Data Protection / Cookie Statement
Microsoft SMS MFA retirement: Cambridge life sciences guide
If your team still gets a text code every time they sign into Microsoft 365, the clock just got louder.
From 1 September 2026, Microsoft Entra ID began treating passkeys as the default authentication experience for tenants where SMS or voice MFA is still enabled. Users who rely on text or phone-call codes are being nudged to register a passkey. From 1 February 2027, Microsoft-provided SMS and voice delivery is retired. After that date, anyone whose only MFA method is SMS or voice faces a blocking passkey registration prompt before they can carry on signing in. There is no opt-out from that February behaviour.
For Cambridge and Cambridgeshire SMEs — especially life-sciences, regulated and science-park firms already juggling audit trails, Cyber Essentials-style controls and hybrid work — this is not a “set a reminder for January” job. It is an autumn project: map who is still on SMS, pick phishing-resistant methods that fit your people, and roll them out before helpdesk chaos becomes a board problem.
What’s changing (and what isn’t)
Microsoft’s own guidance is blunt. Passkeys become the default. SMS and voice are no longer positioned as secure authentication methods, and Microsoft will stop providing those telecom channels natively in Entra ID from February 2027. Organisations that genuinely still need SMS or voice for a narrow operational or regulatory reason will need a customer-managed telecom provider through the Microsoft Security Store (selection opens later in 2026). For everyone else, the path is passkeys, Windows Hello for Business, or FIDO2 security keys.
If you already use passkeys, Windows Hello or another phishing-resistant method, keep going. Those users are largely unaffected. The risk sits with people still enabled for SMS or voice in the Authentication methods policy (or older MFA settings). From September, many of them will see registration nudges. From February, if SMS or voice is all they have, the prompt becomes blocking.
A temporary opt-out exists for the automatic September passkey enablement while you prepare. It does not stop the February 2027 enforcement. Leaving SMS as “good enough” until next winter is how quiet tenants become noisy Monday mornings.
Why SMS MFA was never enough
Text codes feel familiar. They also travel over a channel attackers already understand: SIM-swap, number recycling, phishing kits that relay live MFA prompts, and social-engineering calls that talk people into reading out a code. Traditional MFA — passwords plus SMS, voice, app OTP or push — still helps against casual password reuse. It remains phishable when someone is in the middle of a real login session.
That matters because phishing is still the attack UK businesses actually see. The government’s Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses identified a cyber security breach or attack in the previous 12 months, and phishing remained the most common type (38% of businesses). Among those that identified a breach or attack, phishing was also the most disruptive.
The NCSC now recommends passkeys wherever a service supports them, with traditional two-step verification as the fallback where it does not. In plain terms: if Microsoft is offering a stronger door lock for your Microsoft 365 tenant, keep using the text code only while you fit the new one.
What a passkey actually is
Skip the cryptography lecture. A passkey is a login credential tied to a device or a synced credential manager. Your phone or laptop proves it holds the private key; the service holds the matching public key. There is no shared secret for an attacker to steal from a fake login page and replay elsewhere.
Microsoft Entra ID supports two broad flavours:
Either way, the user experience is usually “approve with Face ID / fingerprint / PIN / tap the key”, not “wait for a text and type six digits under pressure”.
Practical options for a small Microsoft 365 tenant
You do not need an enterprise IAM programme. You need a short list that matches how your people work.
Passkeys in Microsoft Authenticator work well for hybrid staff who already have the Authenticator app. Pair that with clear recovery steps so a lost phone does not lock someone out of SharePoint on deadline day.
Windows Hello for Business suits desks and laptops that are Entra-joined or hybrid-joined. Face or PIN unlock becomes the daily habit; MFA stops feeling like a tax on every Teams call.
FIDO2 security keys earn their keep for privileged admins, shared workstations where phones are awkward, and regulated environments that prefer a physical factor you can inventory. They are also a solid second method beside a phone-based passkey.
For life-sciences and other regulated SMEs around Cambridge, treat authentication method quality as part of the same story as access reviews, privileged accounts and evidence for auditors. “We have MFA on” is no longer the whole answer. Auditors, insurers and larger customers increasingly ask which MFA — and whether it resists phishing.
Avoid a free-for-all. Decide which methods are allowed, who must use a hardware key (hint: Global Admins), and how you handle contractors on BYOD. Document it. Ten minutes of policy now beats a week of one-off exceptions later.
An autumn migration plan that doesn’t wreck the week
Aim to finish core registration well before Christmas if you can. February 2027 sounds distant until half the lab is stuck behind a blocking prompt on the morning of a regulatory submission.
What happens if you wait until February 2027
Users whose only MFA method is still Microsoft-provided SMS or voice will hit a blocking passkey registration prompt at sign-in. No opt-out. For a quiet professional-services firm that might mean a busy helpdesk afternoon. For a regulated or science-park tenant with shift patterns, shared lab PCs and external collaborators, it can look like an outage.
Waiting also wastes the September window, when nudges are still soft and you can coach people calmly. Leaving everything to a hard cutover is how “we meant to do MFA properly” turns into “why can’t finance open the ERP?”
For the wider hardening and phishing picture, see our cyber security page, or managed IT for Cambridgeshire firms that need day-to-day Microsoft 365 support alongside a calm passkey rollout.
How CAMBITION helps
CAMBITION works with Cambridgeshire SMEs every week on Microsoft 365 hardening that stands up to real audits and real phishing — not checkbox MFA. We can run a short authentication review: who is still on SMS or voice, which phishing-resistant methods fit your devices and compliance story, and a calm passkey rollout plan before February 2027.
If you want that review booked while autumn diaries still have gaps, call 01223 656 156 or use https://cambition.co.uk/contact/.
Frequently asked questions
When does Microsoft retire SMS and voice MFA?
Microsoft-provided SMS and voice authentication in Entra ID is retired from 1 February 2027. Passkeys became the default experience from 1 September 2026 for users enabled for SMS or voice.
What should UK SMEs use instead of SMS MFA?
Passkeys (synced or device-bound), Windows Hello for Business, or FIDO2 security keys — phishing-resistant methods Microsoft and the NCSC recommend where available.
Will sign-in break if we do nothing?
After 1 February 2027, users whose only MFA method is SMS or voice face a blocking passkey registration prompt before they can continue signing in.
© CAMBITION I.T. Services Ltd
Head Office
Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridgeshire, CB22 7RG
VAT# 136 186 313 · Registered in the UK # 808 4429
View Privacy / Data Protection / Cookie Statement
If your team still gets a text code every time they sign into Microsoft 365, the clock just got louder.
From 1 September 2026, Microsoft Entra ID began treating passkeys as the default authentication experience for tenants where SMS or voice MFA is still enabled. Users who rely on text or phone-call codes are being nudged to register a passkey. From 1 February 2027, Microsoft-provided SMS and voice delivery is retired. After that date, anyone whose only MFA method is SMS or voice faces a blocking passkey registration prompt before they can carry on signing in. There is no opt-out from that February behaviour.
For Cambridge and Cambridgeshire SMEs — especially life-sciences, regulated and science-park firms already juggling audit trails, Cyber Essentials-style controls and hybrid work — this is not a “set a reminder for January” job. It is an autumn project: map who is still on SMS, pick phishing-resistant methods that fit your people, and roll them out before helpdesk chaos becomes a board problem.
Microsoft’s own guidance is blunt. Passkeys become the default. SMS and voice are no longer positioned as secure authentication methods, and Microsoft will stop providing those telecom channels natively in Entra ID from February 2027. Organisations that genuinely still need SMS or voice for a narrow operational or regulatory reason will need a customer-managed telecom provider through the Microsoft Security Store (selection opens later in 2026). For everyone else, the path is passkeys, Windows Hello for Business, or FIDO2 security keys.
If you already use passkeys, Windows Hello or another phishing-resistant method, keep going. Those users are largely unaffected. The risk sits with people still enabled for SMS or voice in the Authentication methods policy (or older MFA settings). From September, many of them will see registration nudges. From February, if SMS or voice is all they have, the prompt becomes blocking.
A temporary opt-out exists for the automatic September passkey enablement while you prepare. It does not stop the February 2027 enforcement. Leaving SMS as “good enough” until next winter is how quiet tenants become noisy Monday mornings.
Text codes feel familiar. They also travel over a channel attackers already understand: SIM-swap, number recycling, phishing kits that relay live MFA prompts, and social-engineering calls that talk people into reading out a code. Traditional MFA — passwords plus SMS, voice, app OTP or push — still helps against casual password reuse. It remains phishable when someone is in the middle of a real login session.
That matters because phishing is still the attack UK businesses actually see. The government’s Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses identified a cyber security breach or attack in the previous 12 months, and phishing remained the most common type (38% of businesses). Among those that identified a breach or attack, phishing was also the most disruptive.
The NCSC now recommends passkeys wherever a service supports them, with traditional two-step verification as the fallback where it does not. In plain terms: if Microsoft is offering a stronger door lock for your Microsoft 365 tenant, keep using the text code only while you fit the new one.
Skip the cryptography lecture. A passkey is a login credential tied to a device or a synced credential manager. Your phone or laptop proves it holds the private key; the service holds the matching public key. There is no shared secret for an attacker to steal from a fake login page and replay elsewhere.
Microsoft Entra ID supports two broad flavours:
Either way, the user experience is usually “approve with Face ID / fingerprint / PIN / tap the key”, not “wait for a text and type six digits under pressure”.
You do not need an enterprise IAM programme. You need a short list that matches how your people work.
Passkeys in Microsoft Authenticator work well for hybrid staff who already have the Authenticator app. Pair that with clear recovery steps so a lost phone does not lock someone out of SharePoint on deadline day.
Windows Hello for Business suits desks and laptops that are Entra-joined or hybrid-joined. Face or PIN unlock becomes the daily habit; MFA stops feeling like a tax on every Teams call.
FIDO2 security keys earn their keep for privileged admins, shared workstations where phones are awkward, and regulated environments that prefer a physical factor you can inventory. They are also a solid second method beside a phone-based passkey.
For life-sciences and other regulated SMEs around Cambridge, treat authentication method quality as part of the same story as access reviews, privileged accounts and evidence for auditors. “We have MFA on” is no longer the whole answer. Auditors, insurers and larger customers increasingly ask which MFA — and whether it resists phishing.
Avoid a free-for-all. Decide which methods are allowed, who must use a hardware key (hint: Global Admins), and how you handle contractors on BYOD. Document it. Ten minutes of policy now beats a week of one-off exceptions later.
Aim to finish core registration well before Christmas if you can. February 2027 sounds distant until half the lab is stuck behind a blocking prompt on the morning of a regulatory submission.
Users whose only MFA method is still Microsoft-provided SMS or voice will hit a blocking passkey registration prompt at sign-in. No opt-out. For a quiet professional-services firm that might mean a busy helpdesk afternoon. For a regulated or science-park tenant with shift patterns, shared lab PCs and external collaborators, it can look like an outage.
Waiting also wastes the September window, when nudges are still soft and you can coach people calmly. Leaving everything to a hard cutover is how “we meant to do MFA properly” turns into “why can’t finance open the ERP?”
For the wider hardening and phishing picture, see our cyber security page, or managed IT for Cambridgeshire firms that need day-to-day Microsoft 365 support alongside a calm passkey rollout.
CAMBITION works with Cambridgeshire SMEs every week on Microsoft 365 hardening that stands up to real audits and real phishing — not checkbox MFA. We can run a short authentication review: who is still on SMS or voice, which phishing-resistant methods fit your devices and compliance story, and a calm passkey rollout plan before February 2027.
If you want that review booked while autumn diaries still have gaps, call 01223 656 156 or use https://cambition.co.uk/contact/.
Microsoft-provided SMS and voice authentication in Entra ID is retired from 1 February 2027. Passkeys became the default experience from 1 September 2026 for users enabled for SMS or voice.
Passkeys (synced or device-bound), Windows Hello for Business, or FIDO2 security keys — phishing-resistant methods Microsoft and the NCSC recommend where available.
After 1 February 2027, users whose only MFA method is SMS or voice face a blocking passkey registration prompt before they can continue signing in.
© CAMBITION I.T. Services Ltd
Head Office
Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridgeshire, CB22 7RG
VAT# 136 186 313 · Registered in the UK # 808 4429
View Privacy / Data Protection / Cookie Statement