Yes, it is. Microsoft is retiring the text message and voice call codes built into Microsoft Entra ID, the sign in system behind Microsoft 365. Passkeys become the default sign in experience on September 1, 2026, and Microsoft provided SMS and voice authentication retires on February 1, 2027. If your team still approves logins with a six digit text code in 2026, this change affects you directly, and owners searching for IT support New Braunfels businesses can rely on are asking exactly the right question at the right time.
Quick Answer: Microsoft is retiring text message and voice call MFA in Microsoft Entra ID. Passkeys become the default on September 1, 2026, and Microsoft provided SMS and voice sign in goes away on February 1, 2027, so the time to plan your move to passkeys is now.
Key Takeaways
- Starting September 1, 2026, Microsoft automatically enables passkeys for users who currently sign in with text or voice codes.
- On February 1, 2027, Microsoft provided SMS and voice authentication retires. Keeping text codes after that requires configuring and paying for a third party telecom provider.
- Text message codes are the weakest form of multi factor authentication still in wide use, because attackers can phish and proxy them in real time.
- Passkeys replace codes with a fingerprint, face scan, or device PIN, and they are phishing resistant by design.
- A planned rollout that starts with administrators prevents the lockouts and help desk scramble that come from waiting until the deadline.
What's at Stake
If your people still depend on text codes when Microsoft stops delivering them, they will not be able to sign in. That is the continuity risk in one sentence, and it lands on email, files, Teams, and every application tied to your Microsoft account at the same time.
The security risk is already here. Modern phishing kits sit between your employee and the real login page and relay the six digit code the moment it is typed, which means a text code no longer proves the person signing in is your employee. Business email compromise, fraudulent wire instructions, and payroll redirection schemes all start with a stolen login. Your business deserves technology that helps it thrive, not technology that leaves the front door propped open while everyone assumes it is locked.
Why Central Texas Businesses Face This Challenge
Most small businesses chose text codes because they were easy, and easy is exactly what attackers count on. From New Braunfels and San Marcos up the corridor to Austin and Round Rock, growing companies turned on SMS verification years ago because it required no hardware and no training, and most have never revisited that decision since.
Without a dedicated IT team, nobody owns the authentication settings in the Microsoft tenant, so the September 1 change will simply arrive. Employees will start seeing prompts to register passkeys whether or not anyone has explained what a passkey is.
There is also a money angle: cyber insurance carriers across Texas are asking pointed questions about phishing resistant MFA on renewal applications, and healthcare practices, construction firms, and professional services offices handle exactly the kind of data attackers target. Preparation is the difference between a smooth week and a confused one.
How CTTS Delivers the IT Support New Braunfels Businesses Count On
You do not need to become an identity expert. You need a guide who has already made this move many times. CTTS has walked Central Texas organizations through Microsoft transitions since 2002, and this one follows a proven path.
We review your Entra ID tenant and authentication policies to see exactly who still relies on text or voice codes. We design a passkey rollout that matches how your team actually works: Windows Hello for desk staff, phone based passkeys for field and remote workers, and hardware security keys where workstations are shared. We pilot with a small group first, set conditional access so high risk accounts require phishing resistant sign in, and train your staff in plain language before anything changes.
For clients on our Complete Care Coverage plan, this transition is already on the technology roadmap, and when someone does get stuck at a sign in screen on a Monday morning, our local helpdesk answers in 3 rings. This is how we serve organizations with 10 to 250 employees across Central Texas.
How to Move From Text Codes to Passkeys Before the Deadline
The businesses that plan this move in the fall will barely notice the change, and the ones that wait will feel it. Here is what the path looks like.
What Should We Do Before September 1, 2026?
Take inventory now, because Microsoft begins enabling passkeys automatically for anyone still using text or voice codes on that date. A simple sequence keeps the project manageable:
- Pull a report of every user still signing in with SMS or voice codes.
- Decide which passkey types fit each role: Windows Hello for office staff, phone based passkeys for remote and field workers, hardware keys for shared stations.
- Pilot with leadership and your IT partner first, then one friendly department.
- Communicate the change in plain language before the Microsoft registration prompt appears on employee screens.
- Set a completion date well ahead of February 1, 2027, so nothing depends on the deadline.
Can We Keep Text Message Codes After February 1, 2027?
Only by configuring a customer managed telecom provider through the Microsoft Security Store, and only if you have a genuine business, regulatory, or technical need. That route adds a new vendor and a new cost just to keep the weakest sign in method alive. For nearly every business between Buda and Georgetown, the better answer is to treat this as the nudge to move on.
Start With Administrators and High Risk Accounts
Your administrator accounts should move to phishing resistant sign in first, because they hold the keys to everything else. Owners, finance staff who approve payments, and anyone with access to payroll or banking should follow immediately after. Attackers do not target job titles, they target permissions.
Train Your Team Before the Nudge Arrives
Most sign in problems after a change like this are communication problems, not technology problems. A ten minute explanation of what a passkey is, why the company is moving, and what the new sign in feels like will prevent the majority of support calls. Most employees discover passkeys are faster than waiting on a text, and they work even where cell coverage is thin.
Take the Next Step
If you are not sure who in your company still signs in with text message codes, that is the first thing to find out, and you should not have to figure it out alone. Our Executive IT Risk Assessment reviews your Microsoft tenant, your sign in methods, and the rest of your security posture, then gives you a clear picture of where you stand before these deadlines arrive.
Schedule a free strategy session with CTTS and we will map out your move to passkeys on your schedule, not Microsoft's.
Have Questions? We've Got Answers
When exactly does Microsoft retire text message MFA?
Two dates matter. On September 1, 2026, passkeys become the default sign in experience in Microsoft Entra ID and users still on text or voice codes are automatically enabled for passkeys. On February 1, 2027, Microsoft provided SMS and voice authentication retires entirely.
Are passkeys hard for employees to use?
No. Most people find them easier than codes because there is nothing to wait for and nothing to type. A fingerprint, face scan, or device PIN signs them in, and it works even when cell coverage is spotty.
What happens if we do nothing?
Starting September 1, 2026, your team will see prompts to register passkeys with no context, and after February 1, 2027, the text and voice codes simply stop arriving unless you have configured and paid for a third party telecom provider. The safest and least expensive path is a planned migration on your own timeline.
Contact CTTS today for IT support and managed services in Austin, TX. Let us handle your IT so you can focus on growing your business. Visit CTTSonline.com or call us at (512) 388-5559 to get started!
