Phishing-resistant authentication
17.8.2026, 4 minutes read time
TL; DR: Microsoft is retiring Microsoft-provided telecom delivery for SMS and voice authentication from February 1, 2027. The deeper story is about phishing-resistant authentication.
Microsoft-provided telecom delivery for SMS and voice authentication retires
Microsoft is retiring Microsoft-provided telecom delivery for SMS and voice authentication from February 1, 2027.
At first glance, this looks like a straightforward deprecation story: organizations still relying on SMS or voice need to identify those users, plan the migration, and move them to another authentication method.
A broader move towards phishing-resistant authentication
However, there is a more interesting question behind the announcement: Why is Microsoft focusing on SMS and voice, while Microsoft Authenticator push notifications are not really part of the discussion?
The reality behind the question is that this retirement is about a broader move toward phishing-resistant authentication, not only replacing old MFA methods. SMS and voice are the obvious places to start this move; they are among the oldest authentication methods still widely used in Microsoft Entra ID environments.
Well-known weaknesses, including SIM swapping, social engineering, interception, and phishing attacks where users can simply be tricked into providing a verification code, make them vulnerable, and retiring Microsoft-provided SMS and voice delivery therefore makes sense as a first step.
Does the move from SMS to Microsoft Authenticator push make authentication phishing-resistant?
The answer is a clear no. Moving from SMS to Microsoft Authenticator push does not automatically make authentication phishing-resistant. Authenticator push notifications, including number matching, are significantly better than SMS and voice in many scenarios, but they are still not classified as phishing-resistant authentication.
Verified ID
Fortytwo is a Microsoft Verified ID partner and helps organizations design, implement, and operationalize verifiable credentials in the Microsoft ecosystem.
So where does Microsoft Authenticator fit?
This is where the story becomes interesting. Microsoft Authenticator is not just a push-notification application anymore. It can also store and use passkeys. That means the same application can support two very different authentication models: Traditional Authenticator push-based MFA, and phishing-resistant passkey authentication.
Because of this, Microsoft does not need to retire or replace the Authenticator application itself. Instead, the authentication method used inside Authenticator is evolving.
A user who today approves a push notification could eventually authenticate using a passkey stored in the same application.
Passkeys change the security model
Passkeys are based on FIDO2 authentication and are cryptographically bound to the legitimate service the user is signing into. This is important because a user can no longer simply enter their passkey into a fake Microsoft login page in the same way they could enter a password, SMS code, or other traditional MFA code.
That makes passkeys resistant to many of the phishing and adversary-in-the-middle techniques that continue to work against traditional authentication methods. The important distinction is becoming less about SMS vs Microsoft Authenticator, and more about phishable authentication vs phishing-resistant authentication.
What should you do now?
The immediate priority is clear: identify users who still depend on SMS or voice authentication and understand where those methods are being used.
Microsoft has also released a PowerShell-based analyzer helps organizations understand their SMS and voice authentication usage. You should avoid treating this purely as a forced migration from SMS → Authenticator push. If the authentication experience already needs to be changed, this is a good opportunity to consider whether the better target is SMS → Passkey.
Authenticator push can still be a useful and practical authentication method, particularly during migration, but this does not represent the same security level as phishing-resistant authentication.
The bigger shift
For years, the industry goal was simply enable MFA. That was the right message when large numbers of accounts were still protected only by passwords.
The next stage is more specific: Use authentication methods that cannot easily be phished.
SMS and voice are the first obvious legacy methods to address, but you should look beyond the retirement deadline and think about where you want your authentication architecture to end up.
The better question to ask is: How much of our authentication is actually phishing-resistant?
Authenticator push can still be a useful and practical authentication method, particularly during migration, but this does not represent the same security level as phishing-resistant authentication.
Talk to us
Call us if you want to discuss your challenges or if you have questions about identity and access management.
