Raleigh News Today

collapse
Home / Daily News Analysis / Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop

Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop

Aug 14, 2026  Twila Rosenbaum  4 views
Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop

Microsoft is pushing enterprises and consumers alike toward a passwordless future. In a new warning to IT administrators, the company is making it clear that SMS and voice-based authentication are no longer acceptable defenses in an era where AI-powered phishing attacks are becoming more sophisticated and more successful. The message is straightforward: passkeys are the future, and organizations need to prepare now.

Why Microsoft is retiring SMS and voice authentication

The core reason behind this shift is the growing threat of AI-enhanced phishing. According to Microsoft, attackers are now using AI to craft more convincing messages, automate attacks at scale, and bypass traditional authentication measures. SMS and voice channels are particularly vulnerable because they rely on phone networks and human behavior, both of which can be manipulated with relative ease.

One of the biggest risks is SIM swapping. In a SIM swap attack, a bad actor convinces a mobile carrier to transfer a victim's phone number to a SIM card controlled by the attacker. Once that happens, any SMS-based verification codes or voice calls meant for the legitimate user go straight to the attacker. AI has made these social engineering attempts more believable and harder to detect, increasing the likelihood that mobile carriers and users will fall for them. Microsoft specifically pointed to this as a key factor in its decision to move away from phone-based authentication.

Another major concern is the rise of AI-driven phishing campaigns designed to steal passwords and multi-factor authentication (MFA) codes. These attacks use machine learning to analyze communication patterns, craft realistic emails and messages, and even clone voices in some cases. The result is a significantly higher success rate compared to older phishing attacks that were often riddled with grammatical errors and obvious red flags. Microsoft says it is observing a sharp increase in these AI-assisted attacks, and the data is concerning enough to warrant a hard deadline.

What this means for Entra ID users

Microsoft's new policy affects Entra ID, the cloud-based identity and access management service formerly known as Azure Active Directory. This is the backbone of authentication for millions of organizations that rely on Microsoft 365, Azure, and other enterprise applications. For these users, the transition away from SMS and voice authentication will happen in two distinct phases.

Starting September 1, Entra users who are still using SMS or voice authentication will be prompted to set up a passkey during sign-in. Passkeys are a passwordless authentication method that uses a digital key stored on a device, such as a laptop, smartphone, or security key. Instead of entering a password and then receiving a text message with a code, users simply verify their identity with a biometric scan, a PIN, or a physical security key.

This first step is not an immediate cutoff, but it is a clear signal that the clock is ticking. Users who are not ready to make the switch to passkeys will need to move away from SMS or voice authentication before the broader rollout begins. Microsoft is urging IT admins to start planning now to avoid a last-minute scramble.

The second phase is the hard deadline. On February 1, 2027, Microsoft will fully retire SMS and voice authentication for Entra ID. After that date, passkeys will be mandatory, and there is no opt-out option. Every tenant will be affected, regardless of size, industry, or geographic location. This applies to administrators and end users alike, so organizations must ensure that all accounts are migrated to passkeys well before the cutoff.

For IT teams, this means more than just changing a few settings. They need to audit their current authentication methods, identify any users who are still relying on SMS or voice, and provide training and support for the transition. They also need to consider hardware requirements, device enrollment policies, and contingency plans for users who may not have access to a compatible device.

What about personal Microsoft accounts?

Enterprise users are not the only ones affected. Microsoft is also phasing out SMS authentication for personal accounts, including those used for Outlook, Xbox, and Windows 11. The company has already started this process, though it has not yet announced a specific deadline for regular consumers. That uncertainty has led to growing pressure on users to adopt passkeys or other passwordless methods sooner rather than later.

For personal accounts, the transition is likely to be smoother because many users already have a Microsoft account linked to a smartphone. Passkeys can be created using Windows Hello, a fingerprint scanner, or a PIN, and they can be synced across devices using the Microsoft Authenticator app. The company has been pushing users toward Microsoft Authenticator for years, and it is now the primary alternative for those who do not want to use passkeys.

How passkeys work

Passkeys are built on the WebAuthn standard, which is supported by major browsers and operating systems. When a user creates a passkey, their device generates a pair of cryptographic keys: a public key stored on the server and a private key stored securely on the device. During authentication, the server sends a challenge that must be signed with the private key. Because the private key never leaves the device, there is nothing to phish or steal in a data breach.

This model is a significant improvement over traditional passwords and even over SMS-based MFA. A passkey is unique to a specific website or application, so it cannot be reused across services. It also eliminates the need for users to remember complex passwords or carry around a physical token. Biometric verification adds an extra layer of protection, ensuring that even if a device falls into the wrong hands, the attacker cannot easily authenticate.

Microsoft has made passkey support available across its ecosystem, including Windows 11, Microsoft 365, and Edge. Users can manage their passkeys through the Microsoft Authenticator app or through the Windows Hello interface. The company has also been working with other tech giants to ensure passkeys work seamlessly across platforms.

AI-powered phishing is the real threat

The decision to retire SMS and voice authentication is directly tied to the dramatic advances in AI-based cyberattacks. Traditional phishing emails were often easy to spot because they contained typos, awkward phrasing, or generic greetings. AI has changed that. Language models can now generate emails that look like they were written by a trusted colleague, complete with proper grammar, context, and even personalized details scraped from social media.

AI can also automate the entire attack lifecycle. An attacker can use AI to identify potential targets, craft customized messages, send them to thousands of recipients, and then engage with users who respond. This level of automation allows attackers to operate at a scale that was previously impossible without a large team of hackers.

Voice phishing, also known as vishing, has become equally dangerous. AI voice cloning technology can replicate a person's voice with just a few seconds of audio. Attackers can use this to call an employee and impersonate a manager, a vendor, or even a security officer. Combine that with SMS impersonation and SIM swapping, and the attack surface is enormous.

Microsoft has long been a proponent of passwordless authentication, but this latest move represents a significant escalation. By setting a firm date for the retirement of SMS and voice authentication, the company is forcing the industry to adapt to the new reality. The security landscape has shifted, and the tools that were adequate a decade ago are no longer sufficient.

What organizations should do now

IT admins should not wait until September 1 to take action. The first step is to conduct a thorough assessment of the current authentication setup. Identify all users who are using SMS or voice authentication and determine which devices they will use for passkeys. This is particularly important for remote workers and employees who may not have access to a company-issued device.

Next, enable passkey registration in the Microsoft Entra admin center. Administrators can configure policies to require passkeys for certain groups or for all users. They should also communicate with employees about the upcoming changes, explaining why the switch is necessary and how to set up passkeys.

Training is another critical component. Users need to understand that passkeys are not just another password they have to remember. They need to know how to register a passkey, how to use it on different devices, and what to do if they lose a device. A well-prepared organization can make the transition in a few weeks, but one that ignores the warning will likely struggle when the hard deadline arrives.

For individual users, the advice is simple: do not wait for Microsoft to force the change. Set up a passkey for your Microsoft account today, or switch to the Microsoft Authenticator app if you prefer a mobile-based solution. Passwords alone are no longer enough, especially with AI making phishing attacks more convincing and more dangerous by the day.


Source: Digital Trends News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy