Back to News & Insights
Professional Firms September 14, 2026 4 min read

Your Firm's Text-Message Login Codes Have a Retirement Date

On September 1 Microsoft made passkeys the default in Entra ID. On February 1, 2027, text and voice codes stop working, and there is no opting out of that one.

Most accounting and tax firms we work with satisfy their multi-factor authentication requirement the same way: a code arrives by text message. It works, staff understand it, and it has never been worth revisiting. That arrangement now has an end date on it, published by Microsoft, and the second half of the timeline is not optional.

On September 1, Microsoft made passkeys the default authentication experience in Entra ID. Microsoft's documentation describes what happened that day: any user in your tenant who was enabled for SMS or voice in the Authentication Methods Policy, or in legacy MFA settings, was automatically enabled for passkeys. Your registration campaign settings were moved to a Microsoft-managed state targeting passkeys, which brings those users into scope without anyone in your firm touching a setting.

The visible result is a prompt. The next time an affected person signs in and completes MFA, they get nudged to register a passkey. By default they can snooze that prompt an unlimited number of times, which is why most firms will experience September as a mild annoyance and conclude nothing important happened.

Something important happened.

The date that actually binds

From February 1, 2027, Microsoft-provided telecom delivery for SMS and voice is retired in Entra ID. After that date, a user whose only available MFA method is a text or a phone call is required to register a passkey during sign-in before they can continue. Microsoft describes the prompt as blocking, and states directly that there is no opt out from the February 1 behavior and that it will be enforced for all tenants.

There is a temporary opt-out, and it is worth understanding precisely what it buys you. It covers the window from September 1, 2026 through February 1, 2027, it is set through Microsoft Graph rather than the admin center, and all it does is delay the automatic passkey enablement and the registration nudge. It does not move the February date. If you use it, you are buying quiet, not time.

Why this is a compliance conversation and not just an IT one

Tax preparation firms sit inside the FTC Safeguards Rule. The FTC's own guidance is direct about the requirement: implement multi-factor authentication for anyone accessing customer information on your system. The single exception is where your Qualified Individual has approved an equivalent form of secure access controls in writing. Separately, the IRS reminded practitioners in IR-2026-92 on August 18 that the Gramm-Leach-Bliley Act requires financial institutions to protect customer data, and that a Written Information Security Plan is not optional.

Here is the part firms get wrong when they hear about this change. Text-message codes are still multi-factor authentication under the FTC's definition. A code sent to a phone is a possession factor. Nothing about February 1 puts your firm out of compliance with the Safeguards Rule on its own.

What breaks is operational. Your people stop being able to sign in. A firm that discovers this during the last week of January, with extensions coming due and staff locked out of the tax software and the document portal and email, is not facing a compliance finding. It is facing a work stoppage, at the worst possible moment in the calendar, caused entirely by a deadline that was published months in advance.

The compliance angle that does matter is the WISP. If your written plan names SMS as your authentication method, and that method ceases to exist, your plan describes a firm that no longer exists. Updating it is a small task in September and an awkward one during an examination.

What we would do between now and Thanksgiving

Find out who this touches before you decide anything. Microsoft publishes a PowerShell script that identifies which users in your tenant are enabled for SMS or voice. Running it takes a global reader, authentication policy administrator, or security reader role. In most small firms the answer is nearly everyone, but we have seen tenants where the real number was a handful of seasonal preparers and two partners, which changes the size of the project considerably.

Decide whether you are moving to passkeys or paying for telecom. Microsoft is opening a path for organizations that have a genuine regulatory or operational need to keep SMS: telecom provider information becomes available through the Microsoft Security Store on September 18, and configuration opens October 30. That path involves a carrier contract and a cost your firm does not have today. For most firms, that cost buys nothing they need. Document the decision either way, because your Qualified Individual is the person who has to defend it.

Move the partners first, not last. The instinct is to pilot with the most technical staff. The better order is the people whose lockout would stop the most work, because they are the ones you cannot afford to be troubleshooting in filing season. A passkey on a phone the partner already carries takes a few minutes to register.

Handle the seasonal-staff problem now. Preparers who work January through April are the group most likely to arrive in 2027 with an unregistered account and no passkey, and the least likely to see any nudge between now and then. Whatever your onboarding checklist says about setting up MFA, it needs rewriting before the seasonal hiring cycle starts, not during it.

Then update the WISP. One paragraph, describing the authentication methods your firm actually uses.

None of this is difficult. It is a few hours of administrative work spread across the fall, and the entire reason to do it in the fall is that the alternative is doing it in February.

If you want a second set of eyes on the timeline and what it means for your firm's security plan, we are glad to talk it through.

Join the conversation

Straight talk welcome. Comments are moderated, no pitches, no spam.

Comments load once the Hyvor Talk Website ID is set in article.html.