Microsoft Entra ID Is Retiring SMS and Voice MFA: What Caribbean Businesses Need to Know

Microsoft is retiring SMS and voice authentication for Entra ID by February 1, 2027, making passkeys the default sign-in method. For Caribbean businesses, this transition demands immediate action. Learn what is changing, when, and the steps you must take to ensure your organisation remains secure and operational. No opt-out. Act before September 2026.
Split screen graphic of a smartphone displaying SMS verification checkmarks and a laptop showing a global verified map.

Microsoft Entra ID Is Retiring SMS and Voice MFA

Microsoft has announced a major shift in authentication security. By February 1, 2027, Microsoft-provided SMS and voice authentication for Entra ID will be fully retired, and passkeys will become the default authentication experience.

For Caribbean businesses using Microsoft Entra ID (formerly Azure Active Directory), this change demands immediate attention. Here is what you need to know and the steps you must take to ensure your organisation remains secure and operational.

Why Microsoft Is Making This Change

The AI era demands stronger, phishing-resistant authentication. SMS and voice are among the most vulnerable authentication methods available today; they provide significantly weaker protection against phishing, SIM-swap, and replay attacks than modern alternatives. Passkeys, built on FIDO standards, use origin-bound public key cryptography, ensuring credentials cannot be replayed or shared with malicious actors.

The result: Microsoft is making passkeys the default sign-in method for Entra ID, replacing traditional methods like passwords, SMS, and email codes that are susceptible to phishing.

What Is Changing and When

DateWhat Happens
September 1, 2026Users currently enabled for SMS or voice are automatically enabled for passkeys and will be nudged to register a passkey when they next complete MFA.
February 1, 2027Microsoft-provided SMS and voice authentication delivery is fully retired in Entra ID. Customer-managed telecom providers are unaffected.
After February 1, 2027Users whose only available MFA method is SMS or voice will receive a blocking prompt to register a passkey before they can continue signing in. There is no opt-out; this applies to all tenants.

Who Is Affected?

If no users in your tenant are enabled for SMS or voice, no action is required.

However, if you have users relying on SMS or voice for multi-factor authentication, you must move every one of those users off SMS and voice before February 1, 2027.

What Caribbean Businesses Must Do Now

1. Identify Affected Users

Determine who in your tenant is still enabled for SMS or voice authentication.

2. Move Users to Passkeys

Enable passkeys and run a registration campaign to drive adoption at scale before the auto-enablement on September 1, 2026. Acting before this date allows you to move users on your own schedule and avoid blocking prompts.

3. Communicate the Change

Notify your users of what is changing, when, and the action they need to take. Clear communication reduces confusion and resistance.

4. Evaluate a Telecom Provider Only If Required

If you have a regulatory or operational need to keep SMS or voice, you may configure a customer-managed provider through the Microsoft Security Store. Provider options and pricing will be published beginning September 18, 2026, with configuration available from October 30, 2026.

Why Passkeys Are the Right Choice

Microsoft recommends passkeys as the default phishing-resistant credential in Entra ID. Here is why:

  • Phishing-Resistant: Passkeys cannot be phished, replayed, or shared
  • Passwordless Experience: No passwords to remember, reset, or steal
  • Cross-Device Support: Works across Windows, macOS, iOS, and Android devices
  • Built on Open Standards: Based on FIDO2, ensuring broad interoperability

How BG Cyber Connect Can Help

Transitioning your organisation to passkeys requires planning, communication, and technical execution. BG Cyber Connect can assist Caribbean businesses with:

User Discovery and Assessment
We help identify all users still relying on SMS or voice authentication and assess your current authentication methods policy.

Passkey Deployment and Registration Campaigns
We design and execute registration campaigns to drive passkey adoption at scale, minimising disruption to your operations.

User Communication and Change Management
We provide templated communications and change management support to ensure your users understand the transition and complete their registration.

Ongoing Security Monitoring
We ensure your authentication posture remains secure and compliant with evolving best practices.

The Bottom Line

Every SMS and voice user must be on a phishing-resistant method, passkeys are recommended, before Microsoft-provided SMS and voice retire on February 1, 2027. Acting before September 1, 2026, lets you move users on your own schedule and avoid blocking prompts.

The deadline is firm. There is no opt-out.

Need Help Preparing for the Passkeys Transition?

BG Cyber Connect specialises in helping Caribbean businesses navigate critical technology transitions. Contact us today to ensure your organisation is ready.

Contact BGCC for a Free Authentication Security Assessment

Explore our comprehensive IT and security services: BGCC Cybersecurity Solutions

Vector illustration of a hooded hacker and thief stealing data from a laptop displaying a WordPress dashboard.

Critical Elementor Pro Vulnerability Under Active Exploitation

A critical security vulnerability in Elementor Pro, the popular WordPress page builder plugin with over 6 million active installations, is currently being actively exploited. The vulnerability (CVE-2026-32475) allows unauthenticated attackers to upload malicious PHP files and achieve complete site takeover. Over 190,000 exploit attempts have already been blocked. Update to version 4.2.2 immediately.

Read More »
WordPress logo on a cracked red background opposed by a cyber security shield with a padlock representing website protection

Critical WordPress Core Vulnerability

On July 17, 2026, the WordPress Security Team released urgent security updates addressing a critical vulnerability chain in WordPress core affecting versions 6.8 through 7.0.1. Two flaws, CVE-2026-60137 (SQL Injection) and CVE-2026-63030 (Remote Code Execution), can be chained to allow unauthenticated attackers to take complete control of vulnerable sites. No plugins required. No authentication needed. Update to 6.8.6, 6.9.5, or 7.0.2 immediately.

Read More »

Schedule Appointment

Book Now!