Microsoft has officially started notifying customers about the upcoming retirement of voice and SMS-based authentication within Entra ID, marking another step in the company’s push toward more secure identity verification methods. While the announcement confirms the deprecation timeline, early reports indicate that the warning email leaves out a critical piece of information that administrators will need to manage the transition smoothly.
The Warning Goes Out
According to recent reports, Microsoft has begun distributing warning communications to tenants currently utilizing voice calls or SMS one-time passwords (OTP) for multi-factor authentication. These legacy methods have long served as fallback options for users who prefer not to use the Microsoft Authenticator app or who lack smartphone access. However, as part of a broader security initiative, Microsoft is now moving to sunset these channels in favor of modern, phishing-resistant alternatives.
The notification serves as an official heads-up that these authentication methods will no longer be supported in the near future. Organizations relying on voice or SMS for compliance, accessibility, or user preference will need to evaluate their current policies and prepare for necessary changes. The move aligns with Microsoft’s long-standing guidance that SMS and voice OTPs are inherently less secure than app-based or hardware-based methods due to vulnerabilities like SIM swapping and interception.

Missing Critical Details
While the core message of the warning is clear, the communication appears to lack specific guidance on the exact deprecation date or a detailed migration roadmap. Administrators receiving the notice are left without a definitive timeline, making it difficult to prioritize updates across large fleets of users. In enterprise environments, authentication changes require careful coordination with helpdesk teams, compliance officers, and end-users to avoid lockouts or support spikes.
The absence of a concrete deadline or step-by-step migration guide has drawn attention from IT professionals who rely on precise documentation to plan rollouts. Without clear markers, organizations may struggle to allocate resources, test alternative methods, or communicate effectively with employees who depend on voice or SMS for account recovery. Microsoft typically provides these details in follow-up documentation or through the Microsoft 365 admin center, but the initial warning’s brevity suggests that more granular instructions may still be pending.
Security Context and Industry Trends
The push to retire voice and SMS authentication is part of a wider industry shift toward phishing-resistant multi-factor authentication. Security researchers and threat actors have long exploited the weaknesses of SMS-based verification, with SIM swapping attacks allowing attackers to hijack phone numbers and bypass security checks. Voice OTPs face similar risks, as automated robocall systems can sometimes be tricked into delivering codes to unauthorized parties.
Microsoft has consistently recommended the Microsoft Authenticator app, Windows Hello, and FIDO2 security keys as superior alternatives. These methods leverage device-bound credentials, biometric verification, or cryptographic keys that are significantly harder to compromise. The deprecation of legacy channels forces organizations to adopt these stronger controls, reducing the attack surface for credential theft and account takeover attempts.

What This Means for You
If your organization currently uses voice calls or SMS for multi-factor authentication, this warning signals that changes are imminent. The impact will be felt across several areas: user experience, helpdesk operations, and security posture. Employees who rely on SMS for account recovery or who work in environments without smartphone access will need alternative solutions. IT teams will need to update authentication policies, configure fallback methods, and potentially adjust compliance settings to ensure uninterrupted access.
For users, the transition may require installing the Authenticator app, registering biometric options, or obtaining a hardware security key. While these steps add a layer of friction, they also provide stronger protection against phishing and credential stuffing attacks. Organizations should view this as an opportunity to modernize their identity infrastructure rather than a mere compliance hurdle.
How to Prepare for the Change
Administrators should take immediate steps to assess their current authentication landscape. Begin by auditing which users and groups are configured for voice or SMS OTP. Next, prioritize migrating high-risk accounts and those with limited alternative verification options. Deploy the Authenticator app or enable push notifications as the primary method, and configure hardware keys for privileged accounts. Finally, establish a clear communication plan to inform users about the upcoming changes and provide support resources for those who need assistance.
Keep an eye on official Microsoft channels for follow-up documentation, as the initial warning likely precedes more detailed guidance. Until then, treat the notification as a strong indicator that legacy authentication methods are on their way out, and begin planning your migration strategy now to avoid last-minute disruptions.
Source: Neowin
Over to you: Are you still relying on SMS or voice calls for MFA, or have you fully switched to the Authenticator app?



