01303 883111 info@meridian-micro.com Support Login
meridianmicro
Get in Touch
01303 883111 info@meridian-micro.com
Security

Microsoft Retires SMS and Voice Call MFA in August 2026: What UK SMEs Must Do Now to Switch to Passkeys

August 11, 2026 Meridian Micro
MasterCard SecureCode ICA Banken

Microsoft is making one of the most significant identity changes in recent memory this August 2026:
the company is making passkeys the default authentication method in Entra whilst simultaneously retiring SMS and voice call MFA options—an irreversible change that affects every user in your tenant
. For the
43% of UK businesses that experienced a cyber breach or attack in the last 12 months
, this shift to phishing-resistant authentication represents a critical security improvement, but it requires immediate planning and action from IT teams managing Microsoft 365 environments.

If your Kent SME relies on SMS text messages or voice calls as a second factor for Microsoft 365 authentication, you need to plan your migration to passkeys, authenticator apps, or hardware security keys now, before the legacy methods disappear from your tenant.

Why Microsoft Is Retiring SMS and Voice Call MFA in August 2026

SMS and voice call authentication have been security weak points for years. Attackers exploit these methods through SIM-swapping attacks, interception, and social engineering targeting mobile providers.
The NCSC (National Cyber Security Centre) recommends moving away from SMS-based MFA for all business-critical systems
, and Microsoft’s August 2026 enforcement finally makes this official policy rather than guidance.

The timing matters because
last month’s Microsoft 365 Message Center items were heavy on identity and access changes, most notably the retirement of SMS and voice MFA and the shift to passkeys as the default
. This is not a distant future change—it is happening now, in August 2026, and UK SMEs managing Microsoft 365 tenants need to act this month.

Passkeys offer phishing-resistant authentication that cannot be intercepted, stolen through social engineering, or compromised through SIM-swapping. Unlike SMS codes or voice calls, passkeys use cryptographic proof tied to specific devices and services, making them fundamentally more secure against the growing AI-driven threats targeting UK businesses in 2026.

What Changes for Microsoft 365 and Entra ID Users

The practical impact depends on how your organisation currently authenticates:

For UK SMEs still using the older authentication methods, this is a mandatory transition.
The recommendation is to enforce 2-Step Verification (2SV) for all users and try to switch from SMS and push notifications to passkeys, authenticator apps or hardware security keys, especially for admins
.

Timeline and Tenant Rollout

As Microsoft adjusts timelines, keep an eye on your tenant’s rollout messages and update internal communications accordingly
. The Message Center in your Microsoft 365 admin portal will provide at least 30 days’ notice before these changes become active in your specific tenant, but August 2026 marks the general availability window.

If you have not yet received notification, check your Message Center now and review your current MFA configuration to understand which users are still relying on SMS or voice call authentication.

How UK SMEs Should Migrate to Passkeys This Month

The migration requires both technical configuration and user communication. Here is the practical action plan for Kent SMEs:

1. Audit Your Current MFA Configuration

Before you can migrate, you need to know where you are starting from:

This audit shows you the scope of the migration and helps you prioritise which users need immediate attention.

2. Configure Passkey Support in Your Tenant

Microsoft 365 tenants need passkeys enabled in the authentication methods policy:

If your organisation already has passkeys and passwordless authentication configured, you are ahead of the curve—now you need to ensure all users migrate from legacy methods.

3. Communicate the Change to Your Team

Users need clear, practical guidance about what is changing and what they must do:

The transition will be smoother if users understand the “why” behind the change, not just the “what.”

4. Prioritise Administrator and Privileged Accounts

Administrator accounts represent the highest-value targets for attackers, so these should migrate first:

For SMEs managing Microsoft 365 E3 licences or similar enterprise plans, this aligns with the broader shift toward Zero Trust security models that rely on strong, phishing-resistant authentication at every layer.

Alternative Authentication Methods Beyond Passkeys

Passkeys are the default and recommended method, but Microsoft supports other phishing-resistant options:

Each method has trade-offs in terms of cost, user experience, and deployment complexity. For most UK SMEs, a combination of passkeys and Microsoft Authenticator provides the best balance of security and usability.

What This Means for Wider Security and Patch Management

The retirement of SMS and voice call MFA is part of a broader pattern of accelerating security requirements across Microsoft 365.
The total number of vulnerabilities patched by Microsoft so far this year (1,380) has already surpassed 2020’s record-breaking year (1,250)
, and identity controls represent the first line of defence against these threats.

UK SMEs managing Microsoft 365 environments face an increasingly complex set of monthly updates, security changes, and configuration requirements. The MFA retirement sits alongside the Windows 10 feature freeze, Edge security update alerts, and Windows 11 Patch Tuesday changes as part of a sustained push toward higher baseline security standards.

For organisations that have historically treated SMS-based MFA as “good enough,” this August marks the end of that approach. The new baseline is phishing-resistant authentication, and it is now mandatory rather than optional.

How Meridian Micro Can Help Kent SMEs with Microsoft 365 Authentication Changes

Migrating authentication methods across an entire organisation requires technical expertise, user communication, and ongoing support. If your Kent SME needs assistance with the MFA retirement and passkey migration, Meridian Micro can help:

The retirement of SMS and voice call MFA is not optional, and the deadline is approaching fast. Contact Meridian Micro today on 01303 883111 to ensure your Microsoft 365 environment is ready for the authentication changes arriving this month.