If you sign in to Microsoft 365 with a text message or a phone call to confirm it’s really you, the upcoming Microsoft 365 multi-factor authentication (MFA) changes are worth knowing about. The good news is that they’re straightforward to get ahead of, and for most people the switch costs nothing and takes only a few minutes to sort. Here’s what’s happening, who it affects, and the simple steps to stay secure and signed in.
What is changing with Microsoft 365 MFA
Multi-factor authentication (MFA) is the extra check you do when signing in – proving it’s you with a second step on top of your password. Until now, many people have used a text message (SMS) or a voice call as that second step. Microsoft is moving away from those methods towards something more secure called a passkey, and it’s asking everyone to make the switch.
There are two dates to keep in mind:
- From 1 September 2026 – passkeys become the default sign-in experience. If you currently use a text message or a phone call for MFA, you’ll be automatically enabled for passkeys and nudged to register one the next time you sign in. These early prompts can be skipped for now if you’re not quite ready.
- From 1 February 2027 – Microsoft retires its own text message and voice-call MFA service. After this date, anyone whose only sign-in method is a text or a call will be required to register a passkey during sign-in before they can carry on. That prompt cannot be skipped, and there’s no opt-out, so it’s far better to make the move well before then.
We fully support Microsoft’s move towards more secure, phishing-resistant sign-in, though we do feel these timelines will be a wee bit tight for some organisations. In our experience Microsoft has sometimes extended deadlines like these, but we’d strongly recommend planning on the basis that these dates will hold firm.
Who is affected, and who isn’t
This only affects people who currently use a text message (SMS) or a voice call for their Microsoft 365 MFA.
If you already use the Microsoft Authenticator app, another authenticator app, a passkey, or a hardware security token, no action is required and you won’t be affected.
It’s also worth being clear that this applies specifically to Microsoft 365 and Microsoft sign-in. It doesn’t change how you get into other systems or applications, unless those also rely on your Microsoft account to sign in.
Why Microsoft is doing this
Text messages and phone calls can be intercepted, redirected, or talked out of people by increasingly convincing scams, so they’re no longer considered a strong way to protect an account. A passkey works differently – it ties your sign-in securely to your device, so there’s no code for anyone to steal, trick out of you, or reuse. It’s more secure, and it’s usually quicker and simpler to sign in too. In short, this is a change that makes your account safer.
If you still genuinely need text or voice
Some organisations may still need text or voice sign-in for specific regulatory, technical, or business reasons. From February 2027 that will be possible through a separate telecoms arrangement, with associated per-message costs, and Microsoft is due to share the finer detail from mid-September 2026. For the vast majority of people, though, the recommended path is far simpler: move to the authenticator app or a passkey, at no additional cost.
What to do now
A few minutes today saves any last-minute scramble later. Here’s the short version:
- Check how you currently sign in at https://mysignins.microsoft.com/security-info.
- If you’re already on the authenticator app or a passkey, you’re all set – nothing more to do.
- If you still rely on a text or a call, set up the Microsoft Authenticator app using the steps below, then remove the older methods.
- Share this with your colleagues so anyone still using texts or calls can make the move in plenty of time.
How to set up the Microsoft Authenticator app for Microsoft 365 MFA
- On your computer, go to https://myaccount.microsoft.com and sign in to your Microsoft 365 account.
- Open Security info.
- Choose Add sign-in method, then select Microsoft Authenticator.
- On your mobile phone, download the Microsoft Authenticator app from the Apple App Store or the Google Play Store (or open it if you already have it).
- In the app, tap Add account from the menu in the top corner, then choose Work or school account.
- Back on your computer, click Next, then use your phone to scan the QR code shown on screen.
- Enter the six-digit code from the app when prompted, and click Next. Your new method will now appear in your list of sign-in methods.
- Click Set default sign-in method (or Change) and choose the app-based option so the app becomes your usual way of signing in.
- Important final step – remove the less secure methods. Click Delete beside any mobile phone (text) and voice entries that were set up previously.
That’s the job done. And a wee safety tip: if you ever lose your phone outside office hours, don’t wait for help – sign in to your account from any available device and choose Sign out everywhere to keep your account protected.
We’re here to help
If any of this feels a bit much, don’t worry – you don’t need to tackle it alone. If you’re a Lugo client and need a hand getting set up, just raise any questions through our LugoLove Ticket Portal at https://support.lugoit.co.uk/ and we’ll help you keep your account safe, secure, and signed in without any bother.
Not a Lugo client yet?
Changes like this one are a good reminder that keeping on top of your cyber security shouldn’t be a scramble every time Microsoft shifts the goalposts. If you’d like a partner who spots these things early and keeps your technology aligned, secure, and running smoothly, we’d love to help. Take a look at our Technology Alignment service to see how we level up your security and efficiency, or book a friendly, no-obligation chat with the team at a time that suits you 🩵






