Microsoft is retiring the text-message code. Your countdown has started.
Starting September 1, 2026, Microsoft 365 will prompt your team to replace SMS sign-in codes with passkeys — and on February 1, 2027, Microsoft's SMS codes stop entirely. What's changing, why the SMS code became the weakest link, and how a Quebec SMB can make the switch calmly and at no cost.

On this page
Some morning after September 1, 2026, someone on your team will sign in to Microsoft 365 and, instead of the usual six-digit code by text message — the SMS code — they'll be asked to set up something called a passkey. That prompt isn't a bug and it isn't optional forever. Microsoft has put an end date on the text-message code — and it's closer than it sounds.
What's actually changing
If your business runs on Microsoft 365, your team already uses Microsoft Entra ID every day without knowing its name. It's the sign-in system that checks who you are before Outlook, Teams or SharePoint opens — the front desk of your digital office.
Most businesses already add a second confirmation on top of the password — a code that arrives by SMS, an automated phone call, an approval in an app. That second step has a name: multifactor authentication, or MFA. It exists so that a stolen password alone isn't enough to get in.
Microsoft has announced that passkeys will become the default way to do that second step in Entra ID. The rollout starts September 1, 2026: employees who currently confirm their sign-in with an SMS code or a phone call will be prompted to register a passkey the next time they sign in. Then, on February 1, 2027, Microsoft stops delivering those SMS and voice codes altogether. After that date, an employee whose only second step was those codes will be required to register a passkey before they can sign in at all. There is no opt-out.
That's the whole story in two dates. Everything else is preparation — and preparation is easier when you understand why the code had to go.
Why the SMS code is being retired
The SMS code was a real improvement over a password alone, and it brought a second layer of protection to millions of businesses that would never have had one. But it has a flaw that no update can fix: it's a code a person can read aloud. And anything your employees can read aloud, they can be talked into reading aloud. That goes double for its cousin, the automated phone call, which reads the code aloud for you — and which is being retired on the same schedule.
That's how most of these attacks work. Nobody breaks the code — they ask for it. The technique is called phishing, and with an SMS code it plays out like this: a convincing email leads to a convincing fake sign-in page; the employee types their password, the page asks for "the code we just sent you," and the employee — believing they're talking to Microsoft — hands it over. The attacker signs in as them, from anywhere.
What's changed recently is who's writing the script. In its Digital Defense Report 2025, Microsoft's threat researchers observed AI-enabled phishing campaigns reaching click-through rates as high as 54%, against roughly 12% for traditional ones — the spelling mistakes and clumsy phrasing your team was trained to spot are gone. Meanwhile, techniques like SIM swapping, where an attacker convinces a phone carrier to move your number to their device, have become routine enough that the texted code can be stolen without you ever seeing it. The code didn't get weaker. The people asking for it got better.
What a passkey is, in plain terms
A passkey is a key that never leaves your device. When you set one up, your phone or computer creates a matched pair: a lock that gets stored with your Microsoft account, and a key that stays sealed inside your device and is unlocked by your face, your fingerprint or your device PIN. When you sign in, the device proves it holds the key — without the key ever being displayed, typed or sent.
That design closes the read-it-aloud problem completely. There's no code on the screen for an employee to hand over, and no code travelling through the phone network for anyone to intercept. Even the fake sign-in page trick stops working: a passkey is bound to the real site it was created for, so on an impostor's page the key simply doesn't turn. Your employee can't be talked into giving away something they never see.
In practice, it barely feels like security at all: signing in to Microsoft 365 becomes the same gesture as unlocking your phone. Passkeys can live on the phones your team already owns, on their Windows PCs, or — for shared computers and front-desk stations — on a small physical security key that plugs into a USB port.
The dates on your calendar
Microsoft has laid out the transition in stages, and each one is a decision point for your business:
- September 1, 2026 — the prompts begin. Employees who use SMS or voice codes start getting asked to register a passkey at sign-in. The prompt can be postponed at first, so nothing breaks overnight — but if you've prepared your team, it's a ten-second task; if you haven't, it's a wave of confused calls to whoever handles your IT.
- October 30, 2026 — the exception path opens. Businesses with a genuine regulatory or technical need to keep SMS or voice codes can contract a third-party telecom provider through Microsoft's partner marketplace — at their own cost. Microsoft publishes the provider list and pricing a few weeks earlier, on September 18.
- February 1, 2027 — Microsoft's SMS and voice codes end. From this date, SMS and voice codes only work for businesses that set up a third-party provider in advance. For everyone else, that door is closed.
- After February 1, 2027 — the prompt stops being polite. An employee whose only sign-in confirmation was SMS or voice codes will be required to register a passkey before they can get into their account. No more postponing, and Microsoft is explicit that there's no opt-out from this one.
These dates apply to the standard Microsoft cloud — where virtually every Quebec SMB lives. Specialized government cloud environments follow their own, later schedule.
What to do before the prompts arrive
For a typical SMB, this transition costs nothing and fits calmly into a few weeks. Most of the work is a handful of decisions and one good memo.
- Find out who still signs in with SMS or voice codes. Your IT provider can pull this list from your Microsoft 365 admin settings in minutes. You may be surprised — it's often the owners and the longest-tenured employees.
- Choose where your passkeys will live. For most teams, the phones people already carry are the answer. For shared workstations, a cash desk or a shop floor, plan a physical security key instead.
- Tell your team before Microsoft does. An unexpected prompt asking you to change how you sign in is exactly what your employees have been trained to distrust — you've spent years teaching them that. A two-paragraph memo — this is coming, it's legitimate, here's what to do — turns a suspicious moment into a routine one.
- Treat the SMS exception as an exception. If a specific system or regulation truly requires SMS, document who and why, and budget for the third-party provider. Don't let "we've always done it this way" become a paid subscription to the weakest link in your security.
The six-digit code had a good run. It deserves a respectful retirement. But a code that can be read aloud will always, eventually, find someone to read it to — and the attackers now asking are more fluent and more patient than the ones your team learned to spot. If you'd rather your switch to passkeys happen on your schedule instead of Microsoft's, talk to us before September — we'll find out who on your team is still on SMS codes and plan the move with you, without the confused calls.


