Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop

Microsoft just sent a warning to IT admins, and it’s a big one. The company wants everyone to stop using SMS and voice-based authentication, and it’s citing AI-powered phishing as the main reason.

Why is Microsoft killing SMS authentication?

In an email spotted by Windows Latest, Microsoft explained that the AI era calls for stronger, phishing-resistant authentication. Basically, AI has made it far easier for attackers, even the less skilled ones, to manipulate SMS and voice channels. SIM swapping has also become easier with AI, allowing bad actors to move your number to a SIM card they control without much effort.

Windows Latest

Microsoft says it’s seeing a sharp rise in AI-driven attacks to steal passwords and MFA codes, and these attacks have a noticeably higher success rate than older, pre-AI phishing attempts. So no, AI isn’t hacking your SIM card directly, but it is making it a lot easier to trick people into handing over their credentials willingly.

When is this happening?

Microsoft has laid out a two-step timeline. Starting September 1, Entra users using SMS or voice authentication will be asked to set up a passkey during sign-in. If you’re not ready for that switch, you’ll need to move away from SMS or voice authentication before the rollout begins.

Rachit Agarwal / Digital Trends

Then, on February 1, 2027, Microsoft will fully retire SMS and voice authentication for Entra ID, and passkeys will become mandatory. There’s no opt-out either, so every single tenant will be affected, no exceptions.

What about personal accounts?

If you use a personal Microsoft account for Outlook, Xbox, or Windows 11, you’re not off the hook either. Microsoft has already started phasing out SMS for authentication and account recovery on personal accounts too, though there’s no confirmed deadline yet for regular users.

Recommended Videos

We should suggest not waiting around for Microsoft to flip the switch on you. Set up a passkey now, or switch to Microsoft Authenticator if that’s more your style. Passwords alone just aren’t cutting it anymore, especially with AI making phishing scarier by the day.

Need help?

Don't hesitate to reach out to us regarding a project, custom development, or any general inquiries.
We're here to assist you.

Get in touch