Microsoft continues to build towards a passwordless future by phasing out an authentication method that’s become ‘a leading source of fraud’
Microsoft has announced plans to phase out SMS-based two-factor authentication (2FA) for personal Microsoft accounts, transitioning instead toward more secure authentication methods. The company will replace SMS codes with alternatives including passkeys, authenticator apps, and verified email addresses for both account recovery and login procedures.
According to Microsoft’s statement, SMS-based authentication has become “a leading source of fraud” and represents a significant security vulnerability. The company notes that SMS as MFA is “horribly vulnerable on multiple fronts,” acknowledging well-documented security risks associated with text message-based authentication methods, including SIM swapping attacks and message interception.
This move represents part of Microsoft’s broader strategic initiative toward a passwordless future. The company emphasizes that it believes “the future of authentication is passwordless, secure, and user-friendly.” By shifting away from SMS, Microsoft is positioning passkeys and authenticator apps as the foundation for more robust account security while advancing toward eventually eliminating traditional password-based authentication entirely.
The transition affects personal Microsoft accounts specifically and will impact users who currently rely on SMS codes for account recovery and two-factor authentication. While the exact timeline for the phaseout wasn’t specified in the announcement, the move signals Microsoft’s commitment to modernizing authentication infrastructure and setting a precedent in the technology industry for deprecating vulnerable legacy security methods.
Sources
- Microsoft continues to build towards a passwordless future by phasing out an authentication method that’s become ‘a leading source of fraud’
- Microsoft plans to end SMS two-factor authentication, potentially setting the pace for a passwordless Windows 11 future: “SMS as MFA is horribly vulnerable on multiple fronts.”