News

Microsoft Is Phasing Out Phone Verification Codes for a New Passwordless Standard

4 min read Editorial

Microsoft is accelerating its push toward passwordless authentication, and the next major shift targets one of the most common backup sign-in methods still in use: phone verification codes. According to recent enterprise rollout communications and internal policy updates, Microsoft Entra ID is beginning to phase out SMS and voice-based one-time passwords for users who have not yet adopted passkeys or authenticator apps. The change is part of a broader identity strategy that has been in motion since the company rebranded Azure Active Directory to Microsoft Entra, but it is now reaching a point where it will directly affect everyday Windows and Microsoft 365 sign-ins.

What Exactly Is Changing?

For years, Microsoft allowed users to fall back on a six-digit code sent via text message or automated phone call when they could not access their primary authentication method. While convenient, the approach has grown increasingly vulnerable to SIM-swapping attacks, social engineering, and network interception. The new policy introduces what Microsoft is referring to as a “keypass” model for accounts that have not yet migrated. In practice, this means users who are still relying on phone codes will be prompted to register a more secure second factor, typically a FIDO2 security key, a built-in Windows Hello credential, or a push notification from the Microsoft Authenticator app, before their account remains fully active. The transition is not an immediate lockout, but it does establish a clear deadline for accounts that remain on legacy verification paths.

Why Microsoft Is Moving Away From Phone Codes

The decision aligns with industry-wide security standards that have long flagged SMS-based authentication as a weak link. The National Institute of Standards and Technology (NIST) updated its digital authentication guidelines years ago to explicitly discourage SMS as a primary or secondary factor, citing predictable vulnerabilities in cellular network routing. Microsoft has been quietly deprecating older authentication methods across Entra ID for enterprise tenants, and the consumer and business cloud side is now following the same trajectory. By shifting users toward cryptographic credentials, the company reduces the attack surface tied to phone number portability and SIM replacement fraud. It also simplifies the authentication flow for IT administrators who manage large fleets of devices, since passkeys and authenticator push notifications require less manual intervention than code-based recovery.

Advertisement
A clean, modern illustration of a smartphone displaying a biometric scan prompt, surrounded by subtle digital lock icons
Microsoft is steering users away from SMS verification codes toward cryptographic credentials like passkeys.

What This Means for You

If you currently use a text message or phone call to sign into your Microsoft account, Windows Hello, or Microsoft 365 work profile, you will likely see a setup prompt within the next few weeks. The change affects anyone who has not yet enabled two-factor authentication through a more secure channel. For most users, the migration is straightforward: you will register a compatible device, enable push notifications in the Authenticator app, or pair a security key with your account. The real-world friction often appears during the transition window, particularly for users who rely on secondary phones, shared devices, or older iOS versions that do not fully support the latest FIDO2 standards. Some users in the iPhone ecosystem have already reported synchronization delays and authenticator app pairing hiccups while Microsoft rolls out the new verification requirements. If you are managing accounts for a family or a small office, you will want to test the new flow on a spare device before relying on it as your primary sign-in method.

How to Get It

The update is being distributed through Microsoft Entra ID policy settings and Microsoft account security dashboards. If you use a personal Microsoft account, navigate to your account security settings and look for the “Advanced security options” or “Passwordless” section to register a new second factor. For enterprise and education tenants, administrators will see the new authentication policy templates in the Entra admin center, along with reporting dashboards that track migration progress. Microsoft has not published a hard cutoff date for phone code deprecation, but the rollout is proceeding in waves tied to tenant activity and compliance thresholds. Users who prefer to stay on the current verification path should monitor their account notifications closely, as Microsoft typically provides a grace period before enforcing stricter requirements.

A close-up photograph of a hand holding a modern smartphone with a Microsoft Authenticator push notification visible on
Authenticator push notifications are replacing SMS codes as Microsoft's preferred second factor.

The iPhone Ecosystem Hurdle

While Microsoft pushes passwordless authentication across all platforms, iOS remains one of the more complex environments for FIDO2 and authenticator app integration. Apple’s strict background process restrictions and varying levels of FIDO2 support across iOS versions can cause pairing delays, delayed push notifications, or failed biometric prompts. Users who rely on iPhones as their primary device for Microsoft account sign-ins should ensure their operating system is updated to the latest stable release before attempting the migration. If you encounter authentication timeouts or sync failures after the policy change, clearing the Authenticator app cache and re-pairing your device through the Microsoft account security portal typically resolves the issue. Microsoft has acknowledged the iOS friction in enterprise support documentation and is working with Apple on deeper integration in future updates.

Source: AskWoody

Over to you: Are you switching to a passkey or authenticator app, or sticking with SMS codes for now?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement