Particle.news

Microsoft Begins Phasing Out SMS for Personal Account Sign‑In

The company cites rising SMS interception and SIM‑swap fraud, directing account holders to set up passkeys and a verified backup email as replacements.

Overview

  • Microsoft has started a phased removal of SMS as a method for two‑factor authentication and account recovery on personal Microsoft accounts and will prompt users to switch to other options.
  • The company says SMS is now a leading source of fraud because texts travel unencrypted and can be intercepted or hijacked through SIM‑swap attacks, which lets attackers receive one‑time codes.
  • Users will be guided to add a verified backup email and to create passkeys, which store a cryptographic key on a device and use biometrics or a device PIN for phishing‑resistant, passwordless sign‑ins.
  • Microsoft is also promoting device prompts via Windows Hello and the Microsoft Authenticator app, but it has not set a final cutoff date and warns there are unresolved edge cases for older devices and virtual environments.
  • Security experts say the move speeds a wider shift in online authentication away from SMS, and consumers should switch now to avoid future lockouts and to gain stronger protection when phone numbers change or devices are lost.