Microsoft abandonne le SMS MFA : votre PME doit passer aux passkeys
28.09.2026 Security

Microsoft abandons SMS MFA: your SMB must move to passkeys

Microsoft is removing SMS and voice authentication from Entra ID. Learn why switching to passkeys better protects your M365 accounts.

Microsoft is preparing to remove SMS and voice call authentication methods from its Entra ID service (formerly Azure Active Directory), the identity manager at the heart of Microsoft 365. This change will directly affect all SMBs that still use these methods to secure access to their cloud applications. Good news: migrating to passkeys is easier than it seems.

Why is Microsoft pulling the plug on SMS?

SMS as an MFA factor has become like a sieve. Attackers now have well-honed techniques to bypass it: SIM swapping (taking control of your phone number with the carrier), message interception via telecom infrastructure weaknesses, or social-engineering attacks that trick your staff into giving their SMS code to a fraudster.

Microsoft has therefore decided to go beyond mere recommendations. The company will gradually disable its native SMS and voice authentication services in Entra ID. The objective: to generalise phishing-resistant methods — and passkeys are the spearhead.

Microsoft abandonne le SMS MFA : votre PME doit passer aux passkeys

Passkeys: a secure and simple technology to adopt

A passkey is a unique cryptographic key, generated and stored directly on the user’s device (PC, smartphone, physical security key such as a YubiKey). Unlike a password or an SMS code, a passkey never traverses the network: it therefore cannot be intercepted or copied by an attacker.

For users, the experience is often faster than an SMS: a fingerprint scan, facial recognition via Windows Hello, or a simple press on a secure USB key. Microsoft Authenticator and Windows Hello for Business already support passkeys natively, with no additional tool installation required for your Microsoft 365 users.

What roadmap for your SMB?

Microsoft has not yet provided a firm date for the definitive deactivation of SMS. But the signal is unambiguous: organisations that have not migrated will be forced to do so in a hurry, with the operational risks that entails.

For an SMB of 10 to 100 users, here are the key steps:

  1. Enable passkeys in the Microsoft Entra admin center (Entra admin centre).
  2. Train your users to configure Microsoft Authenticator or Windows Hello on their work devices.
  3. Identify accounts still protected only by SMS and migrate them as a priority, starting with high-privilege accounts (administrators, management, HR, finance).

What this means for your SMB

  • Audit your MFA methods now: sign in to the Entra admin centre and identify who is still using SMS — the list is accessible in a few clicks in the authentication activity report.
  • Migrate your privileged accounts first: IT admins, management and finance are prime targets for attackers. Securing them with a passkey drastically reduces the risk of compromise.
  • Combine passkeys with conditional access: use this migration to strengthen your conditional access rules in Entra ID — requiring a passkey to reach sensitive data is now possible without excessive complexity.

Want to discuss this? Get in touch with our Axentys experts.

Axentys helps you navigate digital transformation and integrate cloud services at the heart of your business.

Our experts shorten the time needed to adopt new digital and cloud solutions by leveraging their proven skills, tools, processes, and methods – all fully dedicated to your needs.

Thank you for your message. One of our team members will contact you as soon as possible.