Theregister
Microsoft Phases Out SMS Authentication for Personal Accounts
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Microsoft has announced the discontinuation of SMS codes for personal account authentication and recovery, citing security vulnerabilities such as phishing and SIM-swap attacks. The company is transitioning to passwordless authentication methods, including passkeys and verified email, to enhance security and user experience. This change affects all personal Microsoft account users, aiming to reduce fraud risks associated with SMS-based methods. Users will be guided to create passkeys during the login process, which utilize biometrics or device PINs for secure access. The UK’s National Cyber Security Centre has endorsed passkeys as a standard, indicating a broader industry shift. Microsoft has been implementing passwordless accounts since 2025, making this announcement a formal confirmation of a trend already in progress. The exact timeline for the complete removal of SMS authentication has not been disclosed.
Key Points: • Microsoft is ending SMS authentication for personal accounts due to security vulnerabilities. • Users will transition to passwordless methods, including passkeys and verified email. • The UK’s National Cyber Security Centre has endorsed passkeys as a standard.