Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop
Microsoft says AI-driven phishing is increasing and that SMS and voice-based authentication are more vulnerable, including via SIM swapping. According to Microsoft, Entra ID users using SMS or voice must set up passkeys starting Sept. 1, 2026, and SMS and voice authentication will be retired Feb. 1, 2027. Personal Microsoft accounts are also being phased away from SMS.
How this was made

The 30-second read
Why it matters
The deadlines (Sep 1 passkey setup for SMS/voice users, Feb 1, 2027 retirement of SMS/voice with no opt-out) create a concrete migration schedule for enterprise identity teams and may increase demand for passkey enablement and related security configuration.
Market read
This is a security roadmap update with specific enforcement dates that can drive enterprise IT migration planning and identity security spend.
What to watch
Customer migration friction could create short-term support and implementation costs, and the article does not quantify adoption rates or any pricing changes for Entra.
Background
Microsoft is directing Entra ID tenants to replace SMS and voice-based authentication with passkeys due to AI-enabled phishing and SIM-swapping risks.
Ticker impact
Microsoft warns Entra ID admins to stop SMS and voice authentication, citing rising AI-driven phishing and setting passkey deadlines.
Near-term impact likely limited, but could support incremental demand for Entra security features and services as customers migrate to passkeys.
The article is a product/security roadmap communication with specific dates (Sep 1, 2027) rather than financial guidance or a contract; MSFT is the direct subject and the change can affect customer implementation timelines.
Market effects
Could accelerate broader enterprise shift away from SMS/voice MFA toward passkeys, benefiting identity and security tooling demand.
No clear regional specificity; enterprise IT security migration is global.
Likely relevant across major markets where Microsoft Entra is deployed, but no jurisdictional regulatory action is cited.
Counterpoint
The move may be more of a security best-practice enforcement than a revenue catalyst, with limited incremental monetization for Microsoft.
Key entities
- productMicrosoft Entra ID
Microsoft identity service where SMS/voice authentication is being phased out in favor of passkeys.
- authentication_methodPasskeys
Phishing-resistant sign-in method Microsoft is making mandatory for Entra ID.



