Microsoft MFA Changes: What Office 365 Users Need to Know
Microsoft is continuing its move towards more secure, phishing-resistant methods of authentication, with significant changes coming to how users access their Microsoft 365 accounts.
The changes are designed to improve security and reduce reliance on older verification methods that are more vulnerable to cyber threats such as phishing attacks, SIM-swapping and social engineering.
If your organisation uses Microsoft 365, it’s important to understand what is changing and how it may affect your users over the coming months.
Why is Microsoft Making these Changes?
Traditional authentication methods such as SMS text messages and voice calls have long been used as part of Multi-Factor Authentication (MFA). While these methods provide an extra layer of security compared to passwords alone, they are increasingly being targeted by cybercriminals.
Microsoft is therefore encouraging users to adopt stronger authentication methods that offer improved protection against modern cyber threats.
These include:
Passkeys
A passkey allows users to sign in using the security features already built into their device, such as:
- Fingerprint recognition
- Face ID or facial recognition
- Device PIN
Instead of entering a password and then approving a text message, users simply verify their identity using their device’s built-in security.
Passkeys can also be stored in authenticator applications such as Microsoft Authenticator.
Microsoft Authenticator
Many users already use Microsoft Authenticator to approve sign-in requests or enter six-digit verification codes.
It’s important to understand that using Microsoft Authenticator does not automatically mean you are using a passkey. A passkey stored within Microsoft Authenticator is a separate authentication method from standard push notifications or verification codes.
FIDO2 Security Keys
FIDO2 security keys are physical authentication devices, such as a YubiKey, that are plugged into or tapped against a device during sign-in.
These are considered one of the most secure authentication methods currently available.
Key Dates to Be Aware Of:
1 September 2026: Passkey Registration Begins
From September 2026, Microsoft will begin prompting users who currently rely on SMS or voice authentication to register a passkey.
Users may see a registration prompt the next time they successfully sign in and complete MFA.
Initially, the prompt can be postponed, but Microsoft is encouraging users to complete the registration process as soon as possible to take advantage of the increased security
1 February 2027: SMS and Voice Authentication Retired
From February 2027, Microsoft will retire its own SMS and voice-based authentication services within Microsoft 365.
Users who only have SMS or voice authentication configured will be required to register a passkey before they can continue accessing their Microsoft 365 account.
At this stage, registration will become mandatory and users will not be able to bypass or opt out of the requirement.
Who Will Be Affected?
These changes primarily affect users who currently use:
- SMS verification codes
- Voice call verification
Users who already use phishing-resistant authentication methods such as:
- Passkeys
- Windows Hello for Business
- FIDO2 security keys
can continue using those methods without interruption.
Users who currently use Microsoft Authenticator for push notifications or number matching will still be able to use the app. However, if SMS or voice authentication is also enabled on their account, they may still receive Microsoft’s passkey registration prompts.
How to Prepare
For most organisations, the best approach is to begin familiarising users with passkeys and modern authentication methods before Microsoft’s February 2027 deadline.
Registering a passkey provides several benefits:
- Improved protection against phishing attacks
- Faster sign-in experience
- Reduced reliance on passwords
- Better overall account security
To help users get started, Calder IT has created step-by-step setup guides for both Android and Apple devices:
- Setting up Microsoft Authenticator on Android
- Setting up Microsoft Authenticator on iPhone/iPad (iOS)
These guides walk users through installing and configuring Microsoft Authenticator as part of their Microsoft 365 security setup.
Need Help?
If you’re unsure how these changes will affect your organisation, or would like assistance setting up Microsoft Authenticator, passkeys, or other secure authentication methods, the Calder IT team is here to help.
Please contact our Support Desk for advice and support.


Leave a Reply
You must be logged in to post a comment.