Microsoft Phases Out SMS Authentication for Personal Accounts

Microsoft Phases Out SMS Authentication for Personal Accounts

First seen 20 May 2026, 13:39 UTC Theregistersupport.microsoft.comExtremetechNews.Risky.Bizwww.zdnet.com+1 85% similarity 51.9

Article Content

Browse articles
ThreatCluster

Microsoft has announced the discontinuation of SMS codes for personal account authentication and recovery, citing security vulnerabilities such as phishing and SIM-swap attacks. The company is transitioning to passwordless authentication methods, including passkeys and verified email, to enhance security and user experience. This change affects all personal Microsoft account users, aiming to reduce fraud risks associated with SMS-based methods. Users will be guided to create passkeys during the login process, which utilize biometrics or device PINs for secure access. The UK’s National Cyber Security Centre has endorsed passkeys as a standard, indicating a broader industry shift. Microsoft has been implementing passwordless accounts since 2025, making this announcement a formal confirmation of a trend already in progress. The exact timeline for the complete removal of SMS authentication has not been disclosed.

Key Points: • Microsoft is ending SMS authentication for personal accounts due to security vulnerabilities. • Users will transition to passwordless methods, including passkeys and verified email. • The UK’s National Cyber Security Centre has endorsed passkeys as a standard.

ThreatCluster AI

Timeline

2025-01-01
Microsoft begins passwordless account rollout
Microsoft announced that all new accounts would be passwordless by default, starting a shift in authentication methods.
Theregister
2026-04-01
UK endorses passkeys as authentication standard
The UK's National Cyber Security Centre officially recommended the adoption of passkeys for enhanced security.
Theregister
2026-05-20
Microsoft announces end of SMS authentication
Microsoft confirmed it will phase out SMS codes for personal accounts, promoting passkeys and verified email instead.
support.microsoft.com

Community

Browse all →

Tracked Entities in This Story