{"id":732,"date":"2026-07-23T11:27:01","date_gmt":"2026-07-23T10:27:01","guid":{"rendered":"https:\/\/blogs.it.ox.ac.uk\/nexus\/?p=732"},"modified":"2026-07-23T16:42:55","modified_gmt":"2026-07-23T15:42:55","slug":"mfa-sms-voice-authentication-is-ending","status":"publish","type":"post","link":"https:\/\/blogs.it.ox.ac.uk\/nexus\/2026\/07\/23\/mfa-sms-voice-authentication-is-ending\/","title":{"rendered":"MFA SMS\/voice authentication is ending"},"content":{"rendered":"\n<p>Authenticating via a text message, or a voice call, is probably the multifactor authentication method that&#8217;s most familiar to the most people &#8211; it&#8217;s been the default that every organisation uses because phones are so ubiquitous. <\/p>\n\n\n\n<p>But phones are insecure &#8211; numbers can be spoofed and scammers have become adept with ruses to persuade carriers to switch your number to their device. Phones are no longer sufficiently secure to be relied upon as a multifactor authentication method.<\/p>\n\n\n\n<p>At Oxford new user accounts are already unable to setup SMS or call-based MFA. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key dates<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">1st September 2026<\/h2>\n\n\n\n<p>Passkeys will be the default authentication method offered to new accounts, with other options available but effectively deprecated.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1st February 2027<\/h2>\n\n\n\n<p>SMS and voice-based authentication will no longer work via Microsoft. To continue to offer phone authentication we would have to use a third-party supplier, at additional cost.<\/p>\n\n\n\n<p>After this date, if you have <strong><em>no other authentication method<\/em><\/strong> registered on your account, you will be prompted to only use a passkey.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Date<\/th><th class=\"has-text-align-left\" data-align=\"left\">What happens<\/th><th class=\"has-text-align-left\" data-align=\"left\">Notes<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">1 August 2026<\/td><td class=\"has-text-align-left\" data-align=\"left\">API support for temporary opt-out becomes available<\/td><td class=\"has-text-align-left\" data-align=\"left\">Only needed if we want to postpone the September change.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">1 September 2026<\/td><td class=\"has-text-align-left\" data-align=\"left\">SMS and voice users are auto-enabled for passkeys (and nudged to register)<\/td><td class=\"has-text-align-left\" data-align=\"left\">Communications will go out.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">18 September 2026<\/td><td class=\"has-text-align-left\" data-align=\"left\">Microsoft Security Store will start to offer third-party SMS\/voice auth options<\/td><td class=\"has-text-align-left\" data-align=\"left\">Unlikely we&#8217;ll use these, due to the extra cost and weakened security.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">30 October 2026<\/td><td class=\"has-text-align-left\" data-align=\"left\">Alternate auth telecom providers can be configured<\/td><td class=\"has-text-align-left\" data-align=\"left\">if applicable<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">1 February 2027<\/td><td class=\"has-text-align-left\" data-align=\"left\">Microsoft-provided SMS and voice are retired<\/td><td class=\"has-text-align-left\" data-align=\"left\">Passkeys only for people with no other registered MFA method.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Beyond that point<\/td><td class=\"has-text-align-left\" data-align=\"left\">Users with only SMS or voice get a&nbsp;<strong>blocking<\/strong>&nbsp;passkey registration prompt<\/td><td class=\"has-text-align-left\" data-align=\"left\">Enforced for all Microsoft tenants<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Points of note<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Passkeys are more secure because they can&#8217;t be easily phished: there&#8217;s no code a scammer can use. <\/li>\n\n\n\n<li>Older PCs, such as those without a fingerprint reader or a Hello-ready camera will need a physical security key.<\/li>\n\n\n\n<li>A lost device, whether a mobile phone or a Yubikey, will require a recovery process to get the user logged back in. Please be kind with the service desk staff after each of the milestone dates noted above as they gain familiarity with new recovery requests.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blogs.it.ox.ac.uk\/nexus\/files\/2026\/07\/image_2026-07-23_164245410.png\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"972\" src=\"https:\/\/blogs.it.ox.ac.uk\/nexus\/files\/2026\/07\/image_2026-07-23_164245410.png\" alt=\"\" class=\"wp-image-750\" srcset=\"https:\/\/blogs.it.ox.ac.uk\/nexus\/files\/2026\/07\/image_2026-07-23_164245410.png 800w, https:\/\/blogs.it.ox.ac.uk\/nexus\/files\/2026\/07\/image_2026-07-23_164245410-247x300.png 247w, https:\/\/blogs.it.ox.ac.uk\/nexus\/files\/2026\/07\/image_2026-07-23_164245410-768x933.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authenticating via a text message, or a voice call, is probably the multifactor authentication method that&#8217;s most familiar to the most people &#8211; it&#8217;s been the default that every organisation uses because phones are so ubiquitous. But phones are insecure &hellip; <a href=\"https:\/\/blogs.it.ox.ac.uk\/nexus\/2026\/07\/23\/mfa-sms-voice-authentication-is-ending\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":107,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-732","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/posts\/732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/users\/107"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/comments?post=732"}],"version-history":[{"count":5,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/posts\/732\/revisions"}],"predecessor-version":[{"id":753,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/posts\/732\/revisions\/753"}],"wp:attachment":[{"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/media?parent=732"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/categories?post=732"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/tags?post=732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}