SMS and voice MFA retire on February 1, 2027.
Anyone whose only method is a phone will be blocked at sign-in, with no fallback. Our experts find who is affected in your tenant, move every user to phishing-resistant methods and prove that it worked.
SMS and voice are no longer accepted as MFA.
Two dates, one deadline
Knowing the dates is easy. Knowing who is affected in your own tenant is not.
Passkey by default
Users enabled for SMS or voice are enabled for passkeys as the rollout reaches the tenant, and are prompted to register one at their next MFA. Sign-in is not blocked.
Enforcement
SMS and voice are retired. Registration becomes mandatory for every user in scope, and users without a compliant method cannot sign in.
The new default
New users register a phishing-resistant method at onboarding, with no fallback to SMS or call-back at any point.
The passkey prompt is a registration campaign: your tenant can enable, scope or disable it at any time before enforcement, starting with a pilot group.
What is accepted, what is at risk
Change management, user enrollment and configuration are the work between today and the new default.
Every method still works
- Phishing-resistant: passkeys, FIDO2, Windows Hello, Authenticator
- Phishable: SMS, voice call, email one-time code, password only
SMS and voice call
- Business impact: users whose only method is a phone are locked out
- No fallback: no help desk workaround once enforcement starts
What remains
- Phishing-resistant: passkeys, FIDO2 keys, Windows Hello for Business
- Authenticator: push with number matching and passwordless sign-in
Not every MFA resists phishing
The weakest method sets the real security level of the account, and attackers always pick it. Temporary Access Pass is a bootstrap method for onboarding and recovery.
Four packages, one clear path
Start with a free review of your tenant and scale to a full rollout. Every package runs in your production tenant and maps to our E-xperiences journey.
Readiness Free
Establish the baseline at no cost
- Microsoft Entra configuration discovery and review
- Authentication methods best practices
- Passwordless Readiness Report
- Findings and recommendations session (up to 2 hours)
Readiness Essentials
Remediate the critical gaps and start enrollment
- Configuration review and knowledge transfer for IT teams
- Passwordless Readiness Agent deployment
- Phishing-resistant registration for SMS and voice users
- Cleanup of weak methods, Conditional Access and Identity Protection policies
Readiness Standard
Scale passwordless across the organization
- Everything in Essentials
- Onboarding waves, troubleshooting, recovery and reporting
- Re-registration for incomplete profiles
- Micro-Visor Passwordless for end-user adoption
Readiness Advanced
Complete the rollout with knowledge transfer
- Everything in Standard
- Adoption agent and campaigns for every employee
- Windows Hello, passkeys, Temporary Access Pass and FIDO2 keys
- 6–8 hours of knowledge transfer, end-user and admin guides
Faster enrollment, fewer tickets
Our own E-Suite technology does the heavy lifting, so the change reaches every user at a lower cost.
Readiness Report
A read-only view of your current state: users at risk, real SMS and voice usage and Conditional Access gaps, in HTML and PDF.
Score and roadmap
One readiness score and a sequenced roadmap of waves, with a business case that quantifies help desk and licensing savings.
Readiness and Adoption agents
An admin agent that answers who loses access and what changed, and an agent in Teams that guides every employee until they finish.
Micro-Visor Passwordless
In-Teams guidance and self-service management of authentication methods, with targeted campaigns for the users who still need to act.
Configured does not mean adopted. Adoption is a user behavior, and only reporting proves it.
Frequently asked questions
We already have MFA. Is that not enough?
MFA proves a second factor, but it does not prove the site is real: push and code prompts can be relayed in real time. Phishing-resistant methods such as passkeys are bound to the domain and the device, so there is no secret left to steal or replay.
What if a user loses their phone?
Every user registers at least two methods, so a lost phone is a re-registration and not a lockout. A Temporary Access Pass restores access in minutes, time-limited and fully audited.
Can we control the passkey prompts users are already seeing?
Yes. The prompt is a registration campaign that your tenant can enable, scope to a pilot group or disable at any time before enforcement, so you can prepare communications and support first.
What about frontline or phone-less users?
FIDO2 security keys, Windows Hello for Business and certificates cover shared, frontline and phone-less users without depending on personal phones.
Why act now?
Weak methods are being retired on a published timeline, so the change happens with or without a plan. Most capabilities are already licensed; the value comes from activating and governing them before the deadline.
Get ready before Feb 1, 2027
Start with a free readiness review. A Synergy Advisors identity expert will confirm the scope with you.
Share your contextUsers, authentication methods, licensing and timeline.
Get a recommendationThe package or maturity step that fits, with scope and next steps.
Move before the deadlineIn English or Spanish, in person or remote.