What Microsoft is changing.
Microsoft is retiring SMS text message and voice call codes as a way of verifying your identity. These methods are increasingly targeted by attackers (through SIM-swapping and interception), so Microsoft is replacing them with a more secure, phishing-resistant method called a passkey, set up through the Microsoft Authenticator app.
The key dates you NEED to know.
From 1 September 2026
Microsoft has begun rolling out passkeys as the default sign-in experience. If you currently receive codes by text or call, you’ll automatically be prompted to register a passkey the next time you sign in. For now, these prompts can be snoozed.
From 1 February 2027
Microsoft will fully retire text message and voice call codes. After this date, anyone still relying only on SMS or voice will be blocked at sign-in until they set up a passkey. There is no option to skip or opt out of this.
What you need to do.
Setting up a passkey takes just a few minutes. We’ve attached a step-by-step guide that walks you through registering a passkey in the Microsoft Authenticator app on your device. We’d recommend completing this as soon as possible to avoid any disruption to your access.
Speak with us.
Need a hand?
If you have any questions or would like help setting up your passkey, our team is here to support you.
