Microsoft has put an end date on text-message sign-in codes.
On September 1 it started auto-enabling passkeys for Microsoft 365 users who still sign in with a texted or voice code. On February 1, 2027, Microsoft stops providing those codes at all. There is no opt-out.
If you run a CPA firm, here's why that lands on your desk and not your IT guy's. That texted code is almost certainly what you checked "yes" to on your last cyber insurance application. That one box has been doing a lot of quiet work.
The trouble is that a texted code can be handed over. Someone builds a sign-in page that looks like yours, you read the six digits off your phone and type them in, and now they're sitting in your mailbox — reading client files, watching for wire instructions, waiting for March. Microsoft's threat researchers found AI-written phishing emails getting clicked at roughly four times the rate of the older, sloppier kind.
A passkey can't be typed into a fake page. That's the entire point. For most firms it's already covered by the licenses you own — Authenticator, Windows Hello, or a security key.
You have until February. Doing this on your own calendar costs a lot less than doing it the week your renewal paperwork is due.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email