Microsoft is changing sign-in methods in Microsoft Entra ID's public cloud. From 1 September 2026, users enabled for SMS or voice can be included in automatic passkey enablement and registration prompts. Microsoft-provided SMS and voice delivery is scheduled to retire on 1 February 2027.
Ask your IT team to check which methods your account and organisation permit. Being enabled for text or phone verification matters even if you normally verify another way, so this is worth checking rather than assuming it does not apply to you.
We are flagging this well ahead of time so you can plan it properly. The effort involved depends on your tenant's policies and how your accounts are currently set up. If a call or email claims to be part of this change, use your established support channel to check it rather than acting on the message itself.
What we suggest you do
Set up the Microsoft Authenticator app on your work account. Note that approving sign-ins through Authenticator is not the same thing as having registered a passkey, and it does not by itself establish that no policy change affects you — your team should confirm a supported method and test it before retiring the old one. As a bonus, the app also fixes the old travel problem: sign-in codes that never arrive when you are overseas.
- Install Microsoft Authenticator from the official App Store or Google Play. Check you have the right app before you install: it is called Microsoft Authenticator, published by Microsoft Corporation, with the blue padlock-and-person icon. Lookalike apps exist in both stores.
- Open the app, choose Add work or school account, then Sign in.
- Sign in with your Microsoft 365 work account.
- Follow the prompts to finish setting it up.
If you already use a different authenticator app for other services, we still suggest Microsoft Authenticator for your Microsoft 365 work account. It is the app we support, and it works with the newer sign-in methods Microsoft is introducing.
What you will see from 1 September
From 1 September 2026 Microsoft switches on its newer sign-in methods across Microsoft 365 and starts prompting people who still use text codes or phone calls, right at sign-in. You may be asked to set up a passkey, which lets you sign in with your fingerprint, face or device PIN instead of a code.
The prompt appears on screen while you are signing in, as part of the sign-in itself. It is genuine and safe to accept, and you can also choose to skip it and carry on signing in as normal. You may see it even if you already use Microsoft Authenticator.
Microsoft recommends phishing-resistant authentication. Where an organisation has a valid need to retain SMS or voice for MFA, Microsoft has described a customer-managed telephony option — its availability, supported providers, cost and suitability need checking before you rely on it, and it does not preserve SMS as a primary sign-in method. Microsoft's transition guidance and telephony-provider FAQ carry the current detail.
Watch out for copycats
Changes like this are a gift to scammers, because “Microsoft is retiring codes, click here” is an easy email to fake. Two simple checks:
- Genuine Microsoft prompts appear inside your sign-in, on the screen, while you are signing in. They do not arrive as an email demanding urgent action.
- If a call or email claims to be from Anvil or Microsoft and asks for codes, passwords or sign-in details, hang up and call us back on 09 579 5432 to check. We will never mind.
If this approach does not suit your situation some situations need a different answer, including:
- You share a login with colleagues, for example a reception, info or warehouse user account.
- You cannot, or prefer not to, use a personal phone for work sign-in.
- You do not have a smartphone.
There are workable options for all of these. Please contact us and we will help you plan the right one.
Thanks