OpusBUSINESS EXPERT

The text-message code you log in with stops working in February

Andy Shepherd6 min read

The text-message code is the second factor most small firms chose, and they chose it for good reasons. It needed no app, no training and no company phone. You typed your password, a text arrived, you typed six digits. Everyone from the apprentice to the director could do it on the handset they already owned.

Microsoft is taking it away.

The two dates

From 1 September 2026, anyone still set up for SMS or voice codes on a Microsoft work account is automatically enabled for passkeys and gets nudged to register one when they next sign in. That nudge can be snoozed, indefinitely by default, which is why most people reading this have already dismissed it a few times without registering anything.

From 1 February 2027, Microsoft stops providing the text messages and phone calls themselves. After that date, a user whose only sign-in method is a text code cannot snooze any more. They get a prompt that will not go away until they have set up a passkey, in the middle of trying to do something else.

Microsoft's own wording on this is unusually blunt: there is no opt-out from the February behaviour, and it applies to every tenant.

Why they are doing it, briefly

A text code proves somebody holding your phone approved a sign-in. It does not prove which website asked for it, and that gap is the whole of the attack we wrote about in you had multi-factor authentication on and they got in anyway. A passkey closes it, because it is tied to the address it was made for and will not work anywhere else.

So this is an upgrade, and we are not going to pretend otherwise. The part worth your attention is not whether to argue with it. It is which of your people are going to find February difficult.

The awkward middle

On the estates we run, the same handful of cases come up every time, and none of them are the ones the guidance anticipates.

The fitter with a cheap handset that will not hold a passkey properly. The part-time bookkeeper who will not install a work app on a personal phone, and is within her rights not to. The reception login that three people use, which cannot register a passkey to a face because there is no single face. The director who spends a fortnight abroad on a local SIM, for whom a UK text message has always been the fragile bit anyway. And the one that actually causes the emergency: the account with a mobile number attached that belonged to somebody who left in 2023, where nobody can sign in to change anything because the code goes to a phone in a drawer.

That last case is the reason to do this now rather than in January. Fixing a stale second factor is straightforward while the old method still works to authorise the change. Once it stops, you are into a support process, in the same week as everybody else.

If that pattern sounds familiar, it is the same shape as the shared login problem, arriving from a different direction.

The half nobody mentions

The retirement covers self-service password reset too.

If your people reset a forgotten password by having a code texted to them, that route closes on the same date. It is a smaller thing than being locked out of an account, right up until the Monday morning somebody has forgotten their password, cannot get a text, and the person who could help is on annual leave.

Worth checking what your reset options actually are before you need them.

Can you just keep using text messages?

Technically yes, and for almost every firm reading this the answer should still be no.

Microsoft is not blocking SMS outright. It is getting out of the business of sending the messages, and pointing organisations that genuinely need a telecoms channel towards contracting a carrier directly through its Security Store. Pricing is per message and varies by provider and region.

That is an answer built for a bank with a regulatory obligation. Signing a carrier contract so that a ten-person firm can carry on with the weakest available method is the wrong way round, and it costs money to stay in a worse position.

What to do with the five months

You do not need a project. You need a list, and the list is short.

  1. 01Find out who is still on text codes rather than an app or a passkey
  2. 02Check the mobile number on every account, especially the ones nobody signs into often
  3. 03Fix the accounts pointing at a phone that has left the building, while you still can
  4. 04Get the obvious people onto passkeys first, then work outwards at whatever pace the handsets allow

The first step is the one people assume is hard. It is not: there is a Microsoft-published script that reports exactly which of your users are still enabled for SMS or voice, and any non-zero answer means you are in scope. Whoever administers your tenant can run it in an afternoon.

Start the rollout where a stolen sign-in is worth the most money, which in most firms is whoever sends and chases invoices, and whoever holds administrator rights on the tenant. Everyone else can follow.

There is also a temporary opt-out, set through Microsoft Graph, which delays the September nudges while you sort out something else. It is worth knowing it exists and worth being honest about what it is: a way of buying quiet until February, not a way of avoiding February. If you use it, use it because you have a plan, not because the prompts are annoying.

The realistic version

Most firms will do nothing until someone gets locked out, and for most of them it will be fine, because the person will register a passkey at the blocking prompt, grumble, and get on with their day.

The exceptions are the accounts nobody signs into routinely: the mailbox for a service that only matters at renewal, the portal used once a quarter, the login attached to a number that is no longer in anyone's pocket. Those are the ones that go wrong, and they go wrong at the worst moment, because the only time you find out is when you needed the account.

An hour spent on the list in September is an hour. The same problem in February is a phone call to somebody who cannot help you quickly.

If you are not sure who administers your Microsoft 365 tenant, or whether anyone has ever looked at what is registered on these accounts, that is a short conversation.


We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.

If any of this sounds like your business, we will tell you plainly whether we can help.

We would like to use analytics cookies to understand how this site is used, advertising cookies to measure our ads, and to load our office map from Google. None of them loads on its own unless you accept — though Google Tag Manager itself loads either way, with every category switched off. The map also has a button of its own. Read our cookie policy