Legal

Your text-message login codes now have an expiration date

Microsoft made passkeys the default sign-in for Microsoft 365 on September 1, and the six-digit text codes your firm logs in with now have an expiration date.

1 min readOriginally posted on LinkedIn

Microsoft made passkeys the default sign-in for Microsoft 365 on September 1, and the six-digit text codes your firm logs in with now have an expiration date.

Microsoft-provided SMS and voice authentication retires for most users on February 1, 2027, and for global admins and external users on July 1, 2027. There is no opt-out. If a text code is someone's only second factor, they will eventually hit a screen that won't let them in until they register something else.

Better to handle that on a quiet Tuesday than in the middle of a trial week.

Here's the part worth understanding. A text code is still a secret someone can be talked into typing. Microsoft reports AI-driven phishing campaigns reaching click-through rates as high as 54%. A convincing fake login page collects the password and the code in the same breath.

Windows Hello for Business works differently. A face, fingerprint, or PIN unlocks a key held in the laptop's security chip. The PIN never leaves the device, and the key won't work on a lookalike site. There is no shared secret to hand over.

For a 15-attorney firm, one compromised mailbox is days of lost billable hours, uncomfortable calls to clients, and a harder conversation at your next cyber renewal.

Worth mapping out before February, not after.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions