Microsoft is killing off SMS login codes, citing AI-powered hacking
Microsoft says it will phase out SMS-based 2FA login codes for Microsoft Entra ID. IT admins will lose SMS code login on Feb 1, and Microsoft cites increased AI-enabled hacking and phishing risks. The company is pushing passkeys and other methods, and notes Entra will prompt passkey setup starting Sept 1.
How this was made

The 30-second read
Why it matters
The disclosed deadlines (Feb 1 for Entra admin SMS login removal, Sept 1 for passkey establishment prompts) create a concrete migration timeline for IT teams and may increase scrutiny of authentication security practices.
Market read
Traders get a specific, time-bound security policy change from MSFT that can affect enterprise IT migration planning and perceived security leadership.
What to watch
Enterprises may delay passkey adoption due to device, browser, or workflow constraints, creating short-term support and migration costs rather than immediate security gains.
Background
SMS-based 2FA is widely viewed as weak because codes can be intercepted or abused via SIM-swapping; Microsoft is moving toward passkeys for Entra ID and Windows sign-in flows.
Ticker impact
Microsoft says Entra ID admins will lose SMS-based 2FA login starting Feb 1, accelerating a passkeys-only direction.
Limited direct impact on MSFT earnings, but could modestly support security narrative and enterprise trust.
The article is a security product policy change with clear timelines (Feb 1 for admin SMS, Sept 1 for user passkey prompts) but no financial guidance or quantified revenue impact.
Market effects
Reinforces a broader enterprise security shift from SMS 2FA toward passkeys, potentially increasing demand for identity and authentication tooling.
No clear regional read-through; enterprise IT security practices are global.
Could influence multinational IT administrators’ authentication standards and compliance expectations.
Counterpoint
The change may be more of a security hygiene update than a material business driver, with limited measurable impact on MSFT revenue.
Key entities
- companyMicrosoft
Announces a timeline to discontinue SMS-based 2FA codes for Entra ID admins and eventually for Windows users, citing AI-enabled hacking risks.
- productMicrosoft Entra ID
Identity service where SMS-based 2FA login for admins ends Feb 1 and passkey prompts begin Sept 1.



