Microsoft Is Retiring Text Message Sign-In Codes, and Your Business Is Probably Using Them

A humanoid robot standing guard at night outside a glass-walled data center hall lined with server racks

If your team signs in to Microsoft 365 with a code texted to a phone, that method is being retired. Microsoft made passkeys the default sign-in experience on September 1, and Microsoft-provided text and voice codes go away on February 1, 2027, with global administrators and outside guests following on July 1, 2027.

This is not a nudge. After those dates, anyone whose only sign-in method is a text message gets a blocking prompt: register a passkey or you don’t get in. Microsoft has said plainly there is no opt out from the enforcement.

None of it is bad news. Text codes have been the weak link for years, and attackers have long since worked out how to get around them. But these changes get announced to tenant administrators, and at a small business the tenant administrator is often the owner, or the bookkeeper, or whoever set it up originally and hasn’t signed into the admin center since.

What Is Actually Changing

Since September 1, passkeys are the default. Anyone in your tenant who was set up for text or voice codes has been automatically enabled for passkeys and gets prompted to register one after signing in. If your staff have started seeing unfamiliar prompts about passkeys or face and fingerprint sign-in, that’s this.

February 1, 2027: text and voice codes stop working for most users. Anyone whose only method is a text code has to register a passkey before they can continue.

July 1, 2027: the same applies to global administrators and external guest accounts. The people with the most access get the longest runway and the biggest problem if it’s ignored.

If you genuinely need text codes, for a regulated process or a situation where nothing else works, Microsoft is allowing a separate telecom provider to be connected through its Security Store later this year. That’s a purchase and a configuration, not something that keeps working by default.

It follows the same direction as the rest of Microsoft’s recent changes: multi-factor authentication is already required to administer anything, and older email sign-in methods were switched off earlier this year. Passwords alone, and shared secrets sent over the phone network, are being taken off the table.

Who This Actually Hurts

Large companies have an identity team tracking these announcements. Small businesses have the person who happens to know the password.

Four situations cause real pain, and all of them are common:

Everyone is on text codes. If MFA was turned on a few years ago, it’s almost certainly all text messages. That is the entire company in scope for this change, not a handful of people.

One administrator, no backup. If a single account administers your tenant and that person loses their phone, changes numbers, or leaves, you can be locked out of your own Microsoft environment at the worst possible moment. Every tenant needs a second administrator account kept separate and tested.

Shared and frontline accounts. The front desk login, the warehouse tablet, the account three people use on one shift. Passkeys are tied to a device or a person, which is a better answer than a shared password, but it takes planning rather than discovery at the deadline.

Automation signing in with a stored password. A backup job, a scanner that emails PDFs, an accounting integration, a script somebody wrote in 2019. As the old sign-in methods get switched off, these stop working, usually silently, and usually on a weekend.

What to Check This Month

None of this requires a project. It needs an hour and somebody who knows where to look:

  • Who in your tenant still relies on text or voice codes? Microsoft publishes a way to pull that list. It’s usually more people than the owner expects.
  • Does every administrator account have a phishing-resistant method set up, not just a text code?
  • Is there a second administrator account that isn’t tied to one person’s phone, stored somewhere safe, and tested?
  • Do your people have devices that can hold a passkey? Modern phones and laptops handle this easily. An old personal phone may not, and that’s worth knowing before February.
  • What is still signing in with a stored password? Scanners, backup jobs, line-of-business apps, anything with email credentials saved in it.
  • Has anyone told your staff? People who get an unexplained prompt about passkeys either ignore it or assume it’s a phishing attempt. Both cost you later.

The Part Most Businesses Don’t Realize

Here is what comes up nearly every time somebody looks at a small business Microsoft tenant: the security features are already paid for and not turned on.

Microsoft 365 Business Premium and the E3 and E5 plans include serious security capability. Conditional rules about who can sign in from where, protection on laptops and phones, controls on company data, tools for handling a lost device. Businesses pay for those licenses every month and use a fraction of what they include. Some are also paying a second vendor for a product that duplicates something already sitting unused in the license they own.

So the honest first question isn’t what you should buy. It’s what you already have, and what state it’s in.

A No Cost Security Check

There is a straightforward way to find out, and it costs nothing.

The providers I work with will do a short review with one of their Microsoft security engineers, usually 30 minutes. They look at identity security, the rules governing who can sign in and from where, how MFA is configured, and how your devices are managed. You get back a written report of what they found and what to do about it, ranked so you know what matters first.

There’s no cost and no obligation to buy anything afterward. Some businesses take the report and hand it to whoever already supports them. That is a perfectly good outcome, and it’s a better position than not knowing.

And if you already have someone maintaining your security, that is a reason to do this, not a reason to skip it. A second set of eyes on somebody else’s work is how problems get caught, which is why every other serious profession does it. These reviews almost always turn up something worth improving, even at well-run businesses with good people looking after them. Wouldn’t you want to know what that something is at your company?

What I’d want from it, in your shoes, is an answer to three questions. Are the administrator accounts protected properly. Is anything still signing in the old way that’s about to break. And what am I already paying for that isn’t switched on.

Where I Come In

I don’t perform the assessment. I match you with the provider whose engineers do this work daily, sit in on the review, and go through the report with you afterward so the recommendations turn into a short list rather than a document nobody opens.

What I push on is priority. A good report tells you what to fix first based on what a failure would actually cost your business, not a list of forty findings in alphabetical order.

If your Microsoft environment hasn’t been looked at since it was set up, book the no cost check. Thirty minutes now beats a room full of people who can’t sign in on a Monday morning in February.

← Back to Blog