- SMS codes can be intercepted, phished, or redirected.
- Voice calls can be socially engineered.
- SIM swaps can move your phone number to an attacker.
- Stolen session tokens can bypass the protection a code was supposed to provide.
- Microsoft is already moving affected users toward passkeys.
- Microsoft-provided SMS and voice MFA delivery retires for most users on February 1, 2027.
If your law firm, medical office, accounting firm, or financial practice still depends on text messages or phone calls for Microsoft 365 MFA, this is not a distant technology story.
It is an access-management project with a deadline.
Microsoft began automatically enabling passkeys for users enabled for SMS or voice authentication on September 1, 2026. After February 1, 2027, users in scope who rely only on SMS or voice may receive a blocking prompt requiring them to register a passkey before they can continue signing in.
Your firm should not wait for that prompt to appear during tax season, a trial deadline, patient-care disruption, or a critical client meeting.
What Microsoft Is Actually Changing
Microsoft Entra ID, the identity platform behind Microsoft 365 sign-in, is making passkeys the default phishing-resistant authentication experience.
The timeline is straightforward:
- September 1, 2026: Users enabled for SMS or voice authentication are automatically enabled for passkeys and prompted to register one after completing MFA.
- February 1, 2027: Microsoft-provided SMS and voice delivery retires for most users, including internal guest users.
- July 1, 2027: The later retirement date applies to Global Administrators and external users.
- After the applicable deadline: Users whose only available MFA method is SMS or voice must register a passkey before continuing to sign in.
Microsoft recommends passkeys, Windows Hello, Microsoft Authenticator passkeys, and FIDO2 security keys. Organizations with a legitimate regulatory, technical, or operational need may be able to configure a third-party telephony provider through the Microsoft Security Store.
That should be treated as an exception, not your primary security strategy.
Microsoft’s official retirement guidance explains the timeline, affected users, reporting tools, and migration options.
Why SMS and Voice MFA Are No Longer Enough
SMS was a major improvement over password-only access. Voice verification helped bring MFA to users who could not use an authenticator app.
But the threat environment has changed.
1. Phishing and session-token theft
An attacker may create a convincing Microsoft 365 login page that captures a password and relays the MFA challenge in real time. If the attacker steals the resulting session token, they may access email or cloud services without needing to request another code immediately.
A text message does not protect the session after the user has been tricked into authenticating through an attacker-controlled site.
Passkeys use public-key cryptography and verify the legitimate website or service as part of the authentication process. That makes them substantially more resistant to phishing and credential replay.
2. Social engineering and MFA fatigue
MFA fatigue is most closely associated with repeated push notifications, but the broader problem applies to every workflow that trains users to approve an unexpected authentication request.
“Hey Margaret, I’m locked out. Can you read me the code that just came through?”
That request may come from a criminal pretending to be a managing partner, physician, controller, or IT helpdesk technician.
A code is not a security decision. It is only a credential. Your people still need to recognize when a sign-in request is suspicious.
3. SIM-swap attacks
In a SIM-swap attack, a criminal convinces a mobile carrier to transfer a victim’s phone number to a device controlled by the attacker. Once that happens, SMS and voice codes may go to the criminal instead of your employee.
This is especially dangerous for privileged users, financial staff, executives, and anyone with access to client, patient, payroll, or tax information.
Passkeys in Plain English
A passkey replaces a shared secret with a cryptographic credential stored on a trusted device or credential manager.
Your employee may authenticate with:
- Windows Hello
- A device-based passkey
- A synced passkey stored through a supported password or platform credential manager
- Microsoft Authenticator
- A FIDO2 hardware security key
The employee does not type a code that an attacker can copy. Instead, the device proves that it holds the correct cryptographic key.
For everyday users, a platform passkey may be the simplest option. For high-risk roles, a FIDO2 hardware key provides a strong, dedicated possession factor that is not dependent on a phone number.

A Practical Five-Step Passkey Rollout for Firms of 10–150 People
A passkey rollout does not need to become a six-month transformation project. It does need ownership, communication, and testing.
1. Audit authentication methods
Start with facts.
Identify:
- Users enabled for SMS or voice MFA
- Users actively completing MFA with SMS or voice
- Administrators and other privileged accounts
- Shared accounts and service accounts
- Internal guest users
- Users with no backup authentication method
- Applications or workflows dependent on SMS-based password reset
Microsoft provides an Entra SMS and Voice Usage Analyzer to help identify affected users.
Do not rely only on what employees remember using. Authentication reports and policy settings may reveal dormant or legacy configurations.
2. Pilot passkeys with partners and high-trust users
Do not begin with a firm-wide mandate and hope for the best.
Start with a small pilot group:
- Managing partners
- Practice leaders
- Physicians or office managers
- Controllers and finance staff
- IT administrators
- A few technically confident employees
Have them register passkeys on the devices they actually use: office desktops, laptops, and mobile devices.
Test the real workflows. Remote access. New-device setup. Password reset. Travel. Lost phones. Replacement laptops. Shared workstations.
Then gather feedback and refine your instructions before expanding the rollout.
3. Enforce Conditional Access
Registration alone is not enough.
Use Microsoft Entra Conditional Access to establish when and how users may access Microsoft 365. Your policies should consider:
- User and group
- Application
- Device compliance
- Sign-in risk
- Location
- Administrative role
- Authentication strength
For example, a law firm may require compliant, managed devices for access to confidential matter files. A medical practice may require stronger controls for systems containing protected health information. An accounting firm may apply additional restrictions to payroll, tax, and financial applications.
This is the operational side of zero trust MFA: do not simply ask whether a user completed MFA. Ask whether the person, device, application, and request are trustworthy right now.
4. Register hardware security keys for high-risk roles
Some users deserve more than a convenient default.
Consider FIDO2 security keys for:
- Global and privileged administrators
- Managing partners
- Finance and payroll personnel
- Users who approve wire transfers
- Executives targeted by business email compromise
- Staff handling highly sensitive legal or medical data
- Employees who frequently travel or work from unmanaged locations
Register two keys where possible: one primary and one securely stored backup.
Your IT helpdesk or managed IT provider should document ownership, enrollment, replacement, and recovery procedures. A security key that disappears without a recovery plan can create its own operational problem.
5. Retire legacy methods
Once users have successfully registered a phishing-resistant method, remove unnecessary SMS and voice dependencies.
Review:
- Authentication Methods policies
- Legacy per-user MFA settings
- Self-service password reset
- Conditional Access authentication strengths
- Emergency access accounts
- Third-party applications
- Old phone numbers and inactive users
Do not remove every fallback method at once. Validate recovery first. Maintain carefully protected emergency access accounts and document how administrators regain control if a device is lost.
The goal is not merely to add passkeys. The goal is to reduce the attack surface.

How This Maps to FTC Safeguards and HIPAA Expectations
For financial and accounting firms, the FTC Safeguards Rule requires covered financial institutions to implement MFA for anyone accessing customer information, subject to a limited exception for equivalent controls approved in writing by the qualified individual.
The Rule also expects a broader written information security program, including risk assessment, access controls, monitoring, workforce training, service-provider oversight, and incident response.
Moving away from phishable SMS and voice methods supports that risk-based approach. It does not, by itself, make your firm compliant.
For medical offices, HIPAA requires reasonable and appropriate safeguards addressing access control, authentication, audit controls, and transmission security. The HIPAA Security Rule is risk-based; it is not simply a checklist that says every organization must use one specific MFA technology.
However, HHS guidance consistently treats MFA as an important safeguard, particularly for remote and privileged access. Passkeys and FIDO2 keys can help medical practices strengthen authentication while reducing exposure to phishing, SIM swaps, and credential theft.
For law firms, the central concern is client confidentiality and competent technology management. A firm handling privileged communications, discovery materials, settlement information, and financial records should be able to explain how identity, devices, email, and cloud services are protected.
An IT audit can help document where your authentication program stands before a client, insurer, regulator, or incident forces the question.
Should You Handle the Rollout Internally?
There are legitimate advantages to managing the transition with internal staff:
- Your employees understand existing workflows.
- Communication may feel more personal.
- You retain direct control over scheduling.
- The project may appear less expensive initially.
But there are also risks:
- Registration instructions may be inconsistent.
- Busy staff may postpone enrollment indefinitely.
- Recovery procedures may be overlooked.
- Conditional Access changes may cause unexpected lockouts.
- Departing employees may leave behind undocumented methods.
- One internal IT generalist may not have time for ongoing identity governance.
“I got a guy” may be enough to replace a laptop. It is not a complete authentication strategy for a regulated organization.
Passkey deployment is closer to medical care than a one-time repair: assess the environment, create a treatment plan, monitor results, and adjust when conditions change.
Final Word
SMS and voice MFA are not disappearing because MFA is unimportant. They are being retired because phishable authentication methods no longer provide enough protection for modern cloud environments.
For your firm, the practical path is clear:
- Audit who still uses SMS or voice.
- Pilot passkeys with trusted partners and administrators.
- Configure Conditional Access around risk and device trust.
- Issue FIDO2 hardware keys to high-risk roles.
- Retire legacy methods after recovery is tested.
Start now. Your February 2027 deadline is closer than it appears.
A PC of Mind helps law firms, medical practices, accounting firms, and other regulated professional-services organizations manage Microsoft 365, email security, endpoint security, cloud services, compliance planning, and ongoing IT support. Explore our managed IT services, cybersecurity services, or contact A PC of Mind to plan your transition.
This article is provided for general informational purposes and does not constitute legal, regulatory, or compliance advice. Consult qualified legal and compliance professionals regarding your specific obligations.
Further reading:
- Microsoft: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Microsoft: Frequently asked questions about SMS and voice retirement
- Microsoft Security: Passkeys are the default authentication method in Entra ID
- FTC Safeguards Rule guidance
- HHS HIPAA Security Rule guidance