According to a recent report from Digital Trends Computing, Microsoft is advising IT administrators worldwide to stop using SMS and voice-based multi-factor authentication due to the increasing effectiveness of AI-powered phishing attacks. The company highlights how AI tools have lowered the barrier for attackers to exploit these traditional authentication methods, prompting a mandatory transition to passkeys by early 2027.
- AI-powered phishing raises success rates of SMS/voice exploits
- Mandatory passkey rollout set for Entra ID by February 2027
- Personal Microsoft accounts will also phase out SMS authentication
Product angle
The source review reports that Microsoft identifies artificial intelligence as a catalyst increasing the vulnerability of SMS and voice-based authentication methods. Attackers are employing AI to craft more convincing phishing attempts and execute easier SIM swapping. As a result, these traditionally popular secondary authentication channels are increasingly compromised, undermining account security on a global scale. Microsoft therefore advocates transitioning to passkeys, which provide stronger resistance to phishing and automated manipulation.
Microsoft’s timeline mandates that by early 2027, SMS and voice authentication will no longer be supported for Entra ID tenants, forcing organizations to adopt passkeys or alternatives such as Microsoft Authenticator. This strategic move reflects a broader shift toward authentication mechanisms designed to withstand evolving AI threats, and the company recommends proactive preparation ahead of the enforceable deadline.
Best for / avoid if
This authentication update is best for enterprises and IT administrators managing Microsoft Entra ID environments who need to future-proof their security architecture against sophisticated AI-driven phishing attacks. Organizations currently relying on SMS or voice authentication must plan an orderly migration to passkeys or secure authenticator apps before the September 2026 prompt and the mandatory cutoff in February 2027.
Conversely, individuals or smaller teams heavily dependent on SMS or voice-based multi-factor authentication without the capacity to implement alternative methods quickly may find this transition challenging initially. Those still using personal Microsoft accounts for services like Outlook or Xbox should remain aware of similarly imminent changes and avoid relying solely on SMS for account protection, although Microsoft has not yet established a final deadline for these users.
Pricing and alternatives to check
While the source does not specify pricing details related to Microsoft’s passkey implementation or alternative authentication methods, organizations should consider the possible operational costs of migrating authentication infrastructure and training relevant personnel. Using Microsoft Authenticator or passkeys typically involves no direct user fee but may require integration and management overhead, which should be factored into planning.
Alternatives to watch include biometric authentication, hardware security keys supporting FIDO2 standards, and third-party authenticator applications that provide enhanced phishing resistance. Comparing these options with Microsoft’s native passkey solution can help organizations find an approach best aligned with their security needs and budget constraints amidst the evolving threat landscape driven by AI.