SMS authentication has been around for years because it is simple and familiar. A code arrives on a phone, and the user enters it.  

But now that identity platforms are moving toward phishing-resistant authentication, SMS and voice are becoming less central to the authentication stack. Much to the dismay of many companies, because retiring them can create a practical problem. 

What happens when an authentication method your organization still relies on is no longer provided in the same way? 

Microsoft Entra ID offers a useful example. It’s moving organizations toward phishing-resistant authentication while still requiring them to plan for users who depend on SMS or voice. Organizations can keep providing these authentication methods through a customer-managed telecom provider where there is a legitimate need. 

But they’ll also have to face new decisions around providers, costs, and operational ownership. 

In a nutshell:

  • SMS isn’t necessarily going away. What’s changing is who provides and manages it – businesses may need to take over that responsibility. 
  • Not everyone can move to passkeys immediately. Regulatory requirements, device limitations, and user readiness can make SMS difficult to retire completely. 
  • Businesses need to understand who is affected first. Identify users who rely on SMS, whether they have alternatives, and what their specific requirements are. 
  • Keeping SMS comes with new operational responsibilities. External providers mean new considerations around costs, regional availability, contracts, security, and fraud prevention. 
  • An authenticator app could be a middle ground. Microsoft Authenticator may offer a way to move away from SMS without requiring an immediate switch to passkeys. 
  • Test the transition before rolling it out widely. A pilot project can help uncover practical issues before the deadline becomes urgent. 

Why are platforms moving away from SMS authentication? 

Authentication has traditionally relied on proving that a user knows something or has access to something, like a password or a device. 

The problem is that attackers have become increasingly good at targeting those mechanisms. And, even more often, the people using them. I recently came across Verizon’s 2026 Data Breach Investigations Report, which pointed out that the human element was involved in 62% of breaches. This shows that attackers have gotten particularly good at manipulating through tactics like phishing and social engineering. 

Phishing-resistant authentication is supposed to remove some of that opportunity. Instead of asking users to receive and enter a code, methods such as passkeys use cryptographic credentials tied to the user’s device and the service they’re signing in to. 

This makes them significantly harder to compromise through attacks designed to steal passwords or one-time codes. 

Microsoft, for example, is making passkeys the default authentication experience in Entra ID as part of its broader move toward phishing-resistant authentication. Other identity providers and organizations are taking similar steps to reduce reliance on passwords and one-time codes. 

At the same time security improvements like these aren’t necessarily simple to migrate to. An authentication method can be more resistant to phishing and still require an organization to rethink how thousands of people are going to access its systems. 

What retiring native SMS authentication entails 

When a provider retires native SMS authentication, SMS itself doesn’t necessarily disappear. What changes is how it is delivered and who is responsible for it. 

Until then, an organization may have been able to use SMS authentication as part of its existing identity platform setup. The platform handled the underlying delivery, while the organization simply configured the authentication method for its users. 

Once native delivery is retired, that setup may no longer exist. 

Companies then generally have two options: move users to a different authentication method or find another way to provide SMS authentication for the users who still need it. 

Example from Microsoft Entra ID – two official routes forward 

Microsoft Entra ID, which is arguably the most publicized story of passkeys becoming the default login method, shows two available options quite well. 

From February 1, 2027, Microsoft’s retiring their internal telecom delivery for SMS and voice authentication. They say that organizations with a legitimate business, regulatory, or technical need to continue using SMS or voice can instead configure a customer-managed telecom provider through the Microsoft Security Store. 

Route 1: Move users away from SMS altogether 

Companies that can adopt a different authentication method are able to move toward options such as: 

  • passkeys 
  • Windows Hello 
  • FIDO2 security keys. 

Route 2: Keep SMS, but change how it is delivered 

Those who genuinely need to continue using SMS or voice will need to a third-party telecom provider. 

That means the authentication method may remain, but the operational model changes entirely. The company may suddenly need to work with a partner it had no existing relationship with in the past. 

That can introduce new questions around provider selection, contracts, costs, regional availability, compliance, and where authentication-related data is processed. 

As we can see, retiring native SMS authentication does not always mean that SMS is gone. It can mean that SMS will no longer be something the identity platform will provide and manage on the organization’s behalf. 

Why some companies might not be able to move away from SMS authentication 

Some of the reasons why certain user bases (whether they be B2B or B2C) might not be able to use passkeys include:  

Regulatory, business, or operational requirements 

For example, an organization operating under a specific compliance regime may be required to maintain an out-of-band SMS channel for certain users or workflows. While perusing online discussions, I’ve seen that IAM experts mention healthcare quite frequently here. Particularly, in the scenario where a patient is locked out from their accounts, and needs to regain access but in a manner that can be handled regardless of age and tech capabilities.  In that case, removing SMS entirely as an option could create both a usability and compliance issue. 

From my perspective, this is an important distinction – moving toward stronger authentication doesn’t mean every organization can (or should) move every user to the same method overnight. 

In these cases, the question is whether every affected user has a realistic alternative to SMS or voice today. 

Device limitations 

Those of us working in technology can sometimes operate in a bubble. We spend our days working with modern identity platforms, so it’s easy to assume that the devices and technology needed to support them are widely available. 

But that’s not always the reality. Some people simply don’t have access to a compatible device where they can install an authenticator app.  

That can create challenges when an organization moves toward an authentication method that depends on users having access to specific devices or applications. Not every organization allows personal devices to be used for work authentication, either. 

In those cases, the organization may need to provide an alternative. Whether that’s a corporate device, a hardware security key, or another authentication method. 

As you can see, a seemingly “IAM only” project can become a broader question about device availability, budgets, and workplace policies. 

User readiness and adoption 

Finally, technology can be available long before an organization is ready to use it across its entire workforce. 

Consider demographics or tech-savviness. Some people may have only recently become comfortable with an authentication method that no longer feels new to the rest of us. Asking them to move again, just as they’ve adjusted, can make another transition more difficult. 

If you’re reluctant, then it’s worth considering that 45% of people who had never used a passkey also said they had never even heard of one. 

For large or diverse organizations, adoption takes time. Some users may need training, additional support, or a gradual transition before they can confidently use a new method. 

How should your business respond to the move to passkeys 

A provider’s decision to retire or change how an authentication method is delivered doesn’t necessarily require a one-size-fits-all response from you. The first step is to understand where the organization stands today. 

1. Find out who is actually affected 

Start by identifying which users still rely on the authentication method being retired and how they use it. 

Your goal is to understand the scale of the change before deciding what the solution should be. 

I recommend ticking the following questions off your list: 

  • How many users are affected? 
  • Is the retiring method their only available authentication option? 
  • Are there specific user groups with different, unique login requirements? 
  • Do you already have existing alternatives some of the groups currently using SMS/voice could move to relatively easily? 

Without that visibility, it’s difficult to plan a meaningful transition. 

2. Knowing the scale, decide whether SMS still needs to remain 

For some organizations, the answer may be simple: move all affected users to another authentication method. 

For others, SMS or voice may still need to remain for specific users or scenarios. 

If that’s the case, the organization needs to understand what continuing to use that method will require under the new delivery model. That can include evaluating providers, costs, regional availability, contractual requirements, and operational responsibilities. 

This also raises the question of what safeguards external SMS providers offer against unexpected costs. When evaluating providers, it’s worth checking whether they support configurable limits, such as three OTPs per 15 minutes or 1,000 OTPs per tenant per hour. Cost alerts and automatic cut-offs when a limit is reached can help prevent abuse from turning into an unexpected bill. Other features to look for include geoblocking, fraud detection, and monitoring. 

3. Test the transition before rolling it out 

Once the organization has chosen a path, avoid treating the change as a single switch. Start with a smaller group of users and test the approach in practice. I recommend ensuring that the sample you test it with is representative of various groups – not just the most tech-savvy, to not skew your pilot phase results. 

Once you know how you could approach various questions or technical dilemmas, you’ll know how to expand the rollout gradually. 

4. Make sure someone owns the transition 

Finally, someone needs to be responsible for moving the change forward. That doesn’t mean one person has to do all the work. But there should be clear ownership of the decision, the rollout, and the potential impact on the business. 

Without that, even a relatively straightforward technical change can remain on the roadmap until the deadline becomes urgent. 

The earlier organizations understand their options, the more time they have to choose the path that works for their users, and make the transition without unnecessary disruption. 

5. Check if an app like MS Authenticator could be a viable alternative 

While I haven’t seen this option mentioned elsewhere, businesses that aren’t ready to move to passkeys just yet could consider using an authenticator app such as Microsoft Authenticator instead. It would let them move away from SMS-based authentication without requiring a full transition to passkeys or signing a deal with a third-party provider, while still using a stronger authentication method. This would require a device where such an app can be installed but could arguably make an easier transition forward. 

Stronger authentication may be the destination, but every organization needs its own route 

The shift away from SMS authentication is hardly surprising. The industry has a clear direction of travel: stronger, phishing-resistant authentication. Getting there, though, can be a different story. 

Every organization has its own mix of users, devices, policies, technical constraints, and business requirements. A transition that takes one company a few weeks may require much more planning somewhere else. 

Before making a change, it helps to take a step back and look at who is actually affected, which options are realistic for them, and where SMS still serves a purpose. 

That gives you a much clearer starting point (and hopefully prevents an authentication change from turning into a last-minute project when a deadline gets closer). 

If your organization is now trying to figure out what the retirement of native SMS authentication means for you, reach out. At Qwey, we can help you assess your options and find a path forward that fits your environment.