Microsoft Is Killing SMS Login Codes: Is Your Business Ready?

Share this post
Microsoft login


You turned on multi-factor authentication (MFA) for your Microsoft 365 accounts, checked the box, and felt good about it. That was the right instinct. But here is the part nobody told you: not all MFA is created equal, and the method you chose might be the weakest link in your entire security setup.

If your team logs in by waiting for a six-digit text message to arrive on their phone, you need to read this before Microsoft makes the decision for you.

What Is MFA and Why Does the Method Matter?


Multi-factor authentication means you need more than just a password to log in. You need a second proof of identity, and that second factor is where things get interesting.

Most small businesses set up MFA the fastest, easiest way: a text message (also called SMS) gets sent to the user’s phone with a short code. It feels secure. You have your password AND your phone. What could go wrong?

Quite a bit, actually.

The problem is that SMS text messages were never designed to be a security tool. They travel over the public phone network, which has well-documented vulnerabilities. Cybercriminals have gotten remarkably good at exploiting those gaps, and small businesses in professional services like accounting, law, and dental practices have become prime targets because of the sensitive data they hold.

How Hackers Beat Text-Message MFA


There are several well-established methods attackers use to intercept or bypass SMS-based codes, and none of them require hacking your phone directly.

SIM swapping is one of the most common. An attacker calls your mobile carrier, impersonates you using information gathered from social media or data breaches, and convinces the carrier to transfer your phone number to a SIM card they control. From that moment forward, your text messages go to them, not you.

Real-time phishing is another approach that has become alarmingly common. A fake login page captures your username and password the moment you type them, then immediately logs into the real site and triggers an SMS code. A prompt appears on the fake page asking you to enter that code, and when you do, the attacker is in. The whole exchange takes under sixty seconds.

SS7 protocol attacks exploit a decades-old weakness in the global telephone network that allows text messages to be intercepted in transit. This one requires more technical sophistication, but it is a real and documented threat.

The bottom line: if a criminal wants into an account protected only by a password and a text code, there are reliable ways to get there.

Microsoft Is Removing SMS as an MFA Option


Here is the piece of news that should get your attention right now. Microsoft has announced plans to deprecate SMS and voice call authentication methods for Microsoft Entra ID (formerly Azure Active Directory), the identity system underpinning Microsoft 365. The timeline Microsoft has communicated points to these legacy methods being phased out, with SMS authentication being retired for managed tenants.

This means businesses still relying on text-message codes to protect their Microsoft 365 accounts will eventually lose that option entirely. If you wait for Microsoft to force the change, your users will be locked out during a scramble to switch. That is not a good day for anyone.

The smarter move is to get ahead of it now, on your schedule, with proper planning and zero disruption to your team.

What You Should Use Instead: Authenticator Apps


An authenticator app like Microsoft Authenticator generates a time-sensitive code directly on your employee’s phone without sending anything over the phone network. Nothing to intercept. Nothing to redirect with a SIM swap.

Better yet, Microsoft Authenticator supports a feature called number matching and passwordless sign-in, where instead of typing a code, the user simply approves a push notification on their phone. This is faster than waiting for a text and dramatically more secure.

Here is a quick comparison so you can see the difference clearly:

FeatureSMS Text CodeAuthenticator App
Vulnerable to SIM swapYesNo
Can be intercepted in transitYesNo
Works without cell serviceNoYes (offline TOTP)
Supports passwordless loginNoYes
Being phased out by MicrosoftYesNo



For accounting firms managing client tax data, law firms protecting privileged communications, dental practices guarding patient records under HIPAA, or manufacturers handling proprietary designs, the authenticator app is not optional. It is the standard.

The Bigger Picture: MFA Is Just One Layer


Switching to an authenticator app is an important and necessary step, but it is one piece of a layered security strategy. Cybercriminals adapt quickly, and even authenticator-based MFA can be circumvented by sophisticated phishing attacks that trick users into approving fraudulent login requests.

That is why the businesses we work with at Plus 1 Technology do not just flip a switch and call it done. We look at the full picture, including conditional access policies, device compliance requirements, and employee security awareness, all of which are covered under our managed cybersecurity services.

If you want a quick read on the broader cybersecurity landscape facing small businesses right now, our cyber scorecard is a great place to start. It takes about three minutes and gives you a clear snapshot of where your biggest gaps are.

How to Make the Switch Without Breaking Your Workflow


Transitioning your team from SMS to an authenticator app does not have to be painful. Here is a straightforward approach:

1. Audit your current MFA setup by reviewing which users are relying on text-message codes versus an authenticator app inside your Microsoft 365 admin center.
2. Deploy Microsoft Authenticator to your team with clear step-by-step instructions, and give them a deadline that gives them time to set it up before the old method is disabled.
3. Enable number matching and additional context in your Microsoft Entra settings to reduce the risk of accidental or fraudulent approval of login prompts.
4. Train your team on what a legitimate login prompt looks like and when they should deny one they did not initiate.

This process is something we handle regularly for businesses across the Pottstown, King of Prussia,  Norristown, and Reading areas. It typically takes less than a week for a team of 10 to 30 users when it is handled with a clear plan.

FAQ: Authenticator App vs. SMS MFA


Can someone hack me even if I have MFA turned on?
Yes, if you are using SMS-based MFA. SIM swapping, real-time phishing, and SS7 protocol attacks can all bypass text-message codes. Authenticator apps are significantly more resistant to these attacks, though no single security tool eliminates all risk entirely.

When exactly is Microsoft removing SMS authentication?
Microsoft has been progressively deprecating legacy authentication methods. The company has signaled that SMS and voice-based MFA for Entra ID will be retired, with communications being sent to affected tenants ahead of cutoff dates. If you have not received a notice yet, that does not mean it is not coming. Proactive migration is strongly recommended.

Is switching to an authenticator app complicated for non-technical employees?
Setting up Microsoft Authenticator takes most users under five minutes with clear instructions. The day-to-day experience is actually easier than waiting for a text message. Users tap “Approve” on their phone and they are in. A managed IT provider can handle the rollout so your team has support during the transition.

The Cost of Waiting Is Higher Than the Cost of Acting


Every day your team logs in with a text-message code is a day your business data sits behind a security method that hackers have proven they can beat. Add the fact that Microsoft is actively removing this option, and there is really no reason to delay.

You do not need to figure this out alone. Plus 1 Technology works with accounting firms, CPA practices, law firms, dental offices, and small manufacturers across southeastern Pennsylvania to make security improvements like this simple, fast, and minimally disruptive to your team. Schedule a free IT consultation with Plus 1 Technology and we will show you exactly where your MFA setup stands and what it will take to close the gaps.

Share this post

Other Related Blogs

What can we do better?

We love to hear from our clients, please let us know if there are any areas that you think we could improve upon.