- Starting September 1, 2026, the access codes will be the default for Entra ID
- Microsoft to retire phone call/SMS authentication starting February 1, 2027
- Victims are more likely to open AI-assisted phishing emails
Microsoft has confirmed plans to make passcodes the default or preferred authentication method for Entra ID starting September 1, 2026, and announced further changes to account authentication in a bid to combat sophisticated attacks.
A few months later, starting February 1, 2027, the company will also stop providing its own voice call and SMS authentication codes for Entra ID in hopes that enterprise users will fully adopt passwordless login.
While passkeys don’t promise to completely stop attacks, they make phishing attempts much less effective because attackers would need access to victims’ hardware to gain access.
Microsoft continues its campaign for access codes
While the company may be ending support for its own phone call and SMS authentication methods, passkeys won’t be the only login method after the change. For example, Windows Hello for Business (biometrics) and FIDO2 security keys will still be available.
“The AI era demands stronger, phishing-resistant authentication,” says a company notice seen by latest Windows read. “We’re making passcodes the default authentication experience in Microsoft Entra to help customers securely adopt AI at scale.”
While AI hasn’t made attacks better at breaking traditional authentication methods, it has made them more convincing. According to the company’s own information, the click-through rate on phishing emails is 54% for AI-assisted campaigns, compared to only 12% for conventional ones.
As more people open malicious links, the effects worsen, hence the pressure to improve overall security.
Looking ahead, Microsoft’s suggested plan for affected organizations includes identifying users still using voice/SMS authentication, planning to roll out an enterprise-wide passcode, and keeping workers up to date.
“SMS and voice have served their purpose well, bringing multi-factor authentication to billions of users who otherwise would not have had any,” Microsoft concluded, stating that “the threat environment has evolved beyond its capabilities.”
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




