SSPR with SMS/Voice retirement

passione 120 Reputation points
2026-09-08T15:57:55.95+00:00

Hello everyone, I've got a couple of questions related to SSPR since the retirement of the Voice/SMS for auth.

  • Does the retirement of native SMS/Voice MFA also affect SSPR (Self-Service Password Reset) verification methods, or are these managed independently in the Authentication Methods Policy?
  • What is the recommended alternative verification flow for SSPR once SMS/Voice is no longer available as a method?
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

2 answers

Sort by: Oldest
  1. AI answer

    2026-09-08T15:58:14.7766667+00:00

    Yes. The retirement of Microsoft-provided native SMS and voice applies across Microsoft Entra, including SSPR. In legacy SSPR settings, Mobile phone maps to Voice calls and SMS, and Office phone maps to Voice calls. Those legacy MFA and SSPR policy controls also stop being manageable after September 30, 2025, so SSPR should be managed through the Authentication methods policy.

    Recommended SSPR direction:

    1. Move users off SMS and voice to supported methods in the Authentication methods policy.
    2. Use stronger methods such as:
      • Microsoft Authenticator
      • Email OTP
      • Other phishing-resistant methods where appropriate
    3. If SMS or voice must remain for business, regulatory, or operational reasons, use a customer-managed telecom provider through the Microsoft Security Store.
    4. Complete the transition before February 1, 2027 to avoid sign-in and reset disruption.

    Important timeline points:

    • September 30, 2025: legacy MFA and SSPR policies can no longer be used to manage authentication methods.
    • February 1, 2027: Microsoft-provided SMS and voice are fully retired in Microsoft Entra ID.
    • After that date, if a user’s only available MFA method is SMS or voice, the user is forced to register a passkey during sign-in before continuing.

    For SSPR specifically, security questions are also being retired in March 2027, so the long-term replacement flow is to configure supported methods in the Authentication methods policy rather than rely on phone-based or question-based recovery.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. Marcin Policht 106.8K Reputation points MVP Volunteer Moderator
    2026-09-08T18:46:04.4033333+00:00

    Yep - the retirement of Microsoft's native SMS and voice capabilities applies across Microsoft Entra ID, including SSPR. In the legacy SSPR settings, Mobile phone corresponds to SMS and voice calls, while Office phone corresponds to voice calls. The legacy MFA and SSPR policy controls also stopped being available for managing authentication methods after September 30, 2025, so SSPR should now be managed through the Authentication methods policy.

    For SSPR, the recommended approach is to move users away from SMS and voice and configure supported authentication methods through the Authentication methods policy. Microsoft Authenticator is a primary alternative, while Email OTP can provide another supported recovery option. Other stronger, phishing-resistant methods can also be used where appropriate.

    If your organization must continue using SMS or voice for business, regulatory, or operational reasons, it can use a customer-managed telecom provider through the Microsoft Security Store instead of Microsoft's native SMS and voice service.

    The deadline is February 1, 2027, when Microsoft-provided SMS and voice capabilities are retired in Entra ID. You should complete the transition before that date to avoid disruptions to authentication and password reset. If a user reaches that point with SMS or voice as their only available MFA method, they will be required to register a passkey during sign-in before they can continue.

    There is also a separate SSPR change coming in March 2027, when security questions are retired. The long-term approach for SSPR is therefore to configure supported authentication methods through the Authentication methods policy rather than relying on SMS, voice calls, or security questions.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.