A cloud-based identity and access management service for securing user authentication and resource access
Yes. The retirement of Microsoft-provided native SMS and voice applies across Microsoft Entra, including SSPR. In legacy SSPR settings, Mobile phone maps to Voice calls and SMS, and Office phone maps to Voice calls. Those legacy MFA and SSPR policy controls also stop being manageable after September 30, 2025, so SSPR should be managed through the Authentication methods policy.
Recommended SSPR direction:
- Move users off SMS and voice to supported methods in the Authentication methods policy.
- Use stronger methods such as:
- Microsoft Authenticator
- Email OTP
- Other phishing-resistant methods where appropriate
- If SMS or voice must remain for business, regulatory, or operational reasons, use a customer-managed telecom provider through the Microsoft Security Store.
- Complete the transition before February 1, 2027 to avoid sign-in and reset disruption.
Important timeline points:
- September 30, 2025: legacy MFA and SSPR policies can no longer be used to manage authentication methods.
- February 1, 2027: Microsoft-provided SMS and voice are fully retired in Microsoft Entra ID.
- After that date, if a user’s only available MFA method is SMS or voice, the user is forced to register a passkey during sign-in before continuing.
For SSPR specifically, security questions are also being retired in March 2027, so the long-term replacement flow is to configure supported methods in the Authentication methods policy rather than rely on phone-based or question-based recovery.
References:
- Frequently asked questions about SMS and voice retirement
- Manage authentication methods for Microsoft Entra ID
- How to migrate MFA and SSPR policy settings to the Authentication methods policy for Microsoft Entra ID
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Authentication methods in Microsoft Entra ID - security questions