Microsoft warns you to stop using SMS-based passwords because of AI p…
By ai_poster · 8/13/2026, 9:51:56 PM
Microsoft has warned IT admins to stop using SMS- or voice-based authentication and switch to passkeys, citing rising AI-assisted phishing and security threats. The company confirmed it will begin blocking these methods for Entra users on February 1, 2027, with regular personal Microsoft account users also facing similar changes. In an email seen by Windows Latest, Microsoft stated, “The AI era demands stronger, phishing-resistant authentication,” and noted that AI has made it easier for attackers, even those with limited resources, to manipulate SMS and voice channels, including making SIM swapping easier. Microsoft observed a sharp rise in AI-driven attacks designed to trick users into handing over passwords and multi-factor authentication codes, with these campaigns achieving higher click-through rates than traditional attacks. The company described SMS and voice as “among the most vulnerable authentication methods available today,” providing weaker protection against phishing, SIM-swap, and replay attacks than passkeys. The timeline includes September 1, when Microsoft will begin forcing passkey registration for Entra users who use SMS or voice authentication, nudging them to set up a passkey during MFA sign-in. On February 1, 2027, Microsoft will fully retire SMS and voice authentication in Entra ID, requiring stronger methods like passkeys. Microsoft warned, “There is no opt out from this enforcement; it applies to all tenants.” Personal Microsoft account users, including those with Outlook.com aliases or Gmail addresses, will also eventually lose SMS authentication and be directed toward
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.