What Microsoft is changing, and when

Microsoft 365 business accounts sign in through Microsoft Entra ID. On September 1, 2026, passkeys became the default sign-in method there, and people who use texted codes are now being prompted to set one up. On February 1, 2027, Microsoft stops sending SMS and voice codes for most users. Global administrators and outside guests follow on July 1, 2027. Businesses that truly need text codes can keep them, but only by setting up a separate phone provider and paying for it themselves. Administrators can delay the switch until February 1, but not past it. If nobody in your office is watching this, staff who rely on texted codes could find themselves locked out next winter.

Why texted codes lost the argument

A texted code is only as safe as your phone number, and phone numbers can be stolen. In a SIM swap, a criminal talks your carrier into moving your number to their phone, and your codes go with it. Fake login pages are the bigger problem. A convincing copy of the Microsoft sign-in screen asks for your password and then your code, and passes both to the real site within seconds. Microsoft says AI has made these attacks faster, cheaper, and more convincing. A passkey cannot be handed over that way. It only works on the genuine site, so a fake page gets nothing. I covered how they work in passkeys and passwordless login.

What to do this fall

  • Find out who still uses text codes. Whoever administers your Microsoft 365 account can see each person’s sign-in methods.
  • Register a passkey for everyone, on a phone, in the Microsoft Authenticator app, or with a hardware security key. Set up a second method as a backup.
  • Start with administrator accounts. They are the most valuable target.
  • Check your other services. Banks, domain registrars, and hosting accounts that still offer only text codes deserve a closer look. Switch to an authenticator app wherever one is offered.
  • Do not forget your website. A WordPress admin login protected only by a password is the same weak point. Two-factor authentication for WordPress walks through the options.

Microsoft is the first big platform to set a hard date, but it will not be the last. On the WordPress sites I manage at Design Menu, moving logins to app-based codes or passkeys is now the default. It is an afternoon of work that removes one of the most common ways small businesses get breached.