Microsoft is retiring text message (SMS) and phone call (voice) options for multi-factor authentication (MFA) on Microsoft 365 on February 1, 2027. These methods are being replaced by passkeys and authenticator apps, which offer far better protection against phishing, SIM-swapping, and stolen verification codes.
Do I need to do anything?
If you use Microsoft Authenticator or another authentication app: No. You can keep using those apps exactly as you do now and enter the verification codes.
If you verify by SMS text message or phone call: Yes. Please add a new verification option that uses an authenticator app or passkey. Learn more about adding a new verification option.
Key dates
- September 1, 2026 — If you use SMS or voice, you’ll start seeing a prompt to set up a passkey when you sign in.
- February 1, 2027 — SMS and voice verification are retired. If they are your only verification method, you will be required to set up a passkey before you can sign in. There is no opt-out.
How to add a new verification option
- Go to https://aka.ms/mysecurityinfo and sign in with your college email address.
- Select Add sign-in method.
- Choose Passkey or Microsoft Authenticator, then follow the on-screen steps.
- Once your new method is added, you can remove the phone number listed under your sign-in methods.
Learn more about adding a new verification option.
Questions?
Contact the ITS Help Desk for assistance.
For background on why Microsoft is making this change, see their security blog announcement.