Overview
- Microsoft has started a phased removal of SMS as a method for two‑factor authentication and account recovery on personal Microsoft accounts and will prompt users to switch to other options.
- The company says SMS is now a leading source of fraud because texts travel unencrypted and can be intercepted or hijacked through SIM‑swap attacks, which lets attackers receive one‑time codes.
- Users will be guided to add a verified backup email and to create passkeys, which store a cryptographic key on a device and use biometrics or a device PIN for phishing‑resistant, passwordless sign‑ins.
- Microsoft is also promoting device prompts via Windows Hello and the Microsoft Authenticator app, but it has not set a final cutoff date and warns there are unresolved edge cases for older devices and virtual environments.
- Security experts say the move speeds a wider shift in online authentication away from SMS, and consumers should switch now to avoid future lockouts and to gain stronger protection when phone numbers change or devices are lost.