Healthcare

Microsoft is retiring texted sign-in codes

Microsoft is retiring text-message and phone-call sign-in codes. The clock started September 1.

1 min readOriginally posted on LinkedIn

Microsoft is retiring text-message and phone-call sign-in codes. The clock started September 1.

Here's what's actually happening. If your team signs in to Microsoft 365 with a code texted to a phone, Microsoft has already begun nudging those users to register a passkey instead. On February 1, 2027, Microsoft stops providing SMS and voice codes for most users, and there's no opt-out.

I bring it up because of how this usually looks in a small practice. One person at the front desk holds the login. The code goes to a phone that may or may not be in the building that morning. When that stops working on a Monday, nobody is checking patients in, and the schedule backs up for the rest of the day while someone sorts out identity verification over the phone.

The replacement is genuinely better. A passkey is your face or fingerprint on a device you already carry. It's faster than typing a six-digit code, and it can't be phished, because there's no code for anyone to talk your front desk out of.

The hard part isn't the technology. It's getting your people enrolled on purpose, in a quiet week, instead of discovering the deadline during a sign-in block.

If you run on Microsoft 365, worth putting on the calendar before your next cyber insurance renewal asks how you authenticate.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions