{"id":13529,"date":"2026-05-21T14:54:26","date_gmt":"2026-05-21T14:54:26","guid":{"rendered":"https:\/\/wildgreenquest.com\/?p=13529"},"modified":"2026-05-21T14:54:26","modified_gmt":"2026-05-21T14:54:26","slug":"microsoft-is-scrapping-sms-2fa-codes-what-you-need-to-do","status":"publish","type":"post","link":"https:\/\/wildgreenquest.com\/?p=13529","title":{"rendered":"Microsoft Is Scrapping SMS 2FA Codes\u2014What You Need To Do"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<figure class=\"embed-base image-embed embed-1\" role=\"presentation\">\n<div style=\"padding-top:56.12%;position:relative\" class=\"image-embed__placeholder\"><picture><source media=\"(min-width: 960px)\" sizes=\"50vw\" srcset=\"https:\/\/imageio.forbes.com\/specials-images\/imageserve\/6a0f0e20bace119ae3fc514c\/person-in-suit-holding-smartphone--pressing-payment-buttion-on-screen-\/0x0.jpg?width=960&amp;dpr=1 1x, https:\/\/imageio.forbes.com\/specials-images\/imageserve\/6a0f0e20bace119ae3fc514c\/person-in-suit-holding-smartphone--pressing-payment-buttion-on-screen-\/0x0.jpg?width=960&amp;dpr=1.5 1.5x, https:\/\/imageio.forbes.com\/specials-images\/imageserve\/6a0f0e20bace119ae3fc514c\/person-in-suit-holding-smartphone--pressing-payment-buttion-on-screen-\/0x0.jpg?width=960&amp;dpr=2 2x\"\/><\/picture><\/div>\n<div>\n<div class=\"bMqrj\">\n<p><span style=\"-webkit-line-clamp:2\" class=\"Ccg9Ib-7 _8XF2kHYM\">Microsoft starts scrapping 2FA SMS codes.<\/span><\/p>\n<p><small class=\"pGGCM2aD\">getty<\/small><\/div>\n<\/div>\n<\/figure>\n<p>Microsoft has confirmed it is starting to phase out SMS as a method of authentication, as well as account recovery, for all personal Microsoft accounts. If you use SMS as your primary 2FA code delivery mechanism, you had better pay attention and change to something else as soon as possible to prevent login problems down the line. <\/p>\n<p>The short message service has been the default text protocol to send messages between mobile devices for the longest time. But all bad things come to an end, and SMS is truly that as far as security is concerned. That\u2019s what so many people have moved to using encrypted messaging platforms such as WhatsApp and Signal. It\u2019s also why Microsoft has announced that it is scrapping the use of two-factor authentication codes sent using SMS for logging into personal Microsoft accounts. <\/p>\n<p><span class=\"link-embed__info\"><span class=\"link-embed__provider\">Forbes<\/span><span class=\"link-embed__title\">Microsoft Confirms Surprising Edge Password Security U-Turn<\/span><small class=\"link-embed__byline\">By <span class=\"link-embed__author\">Davey Winder<\/span><\/small><\/span><span class=\"link-embed__thumbnail-wrapper\"><span class=\"link-embed__thumbnail allow-inline-style\" style=\"background-image:url(https:\/\/specials-images.forbesimg.com\/imageserve\/6a0c5d9c7c743cd945fc01ec\/0x0.jpg)\"\/><\/span><\/p>\n<section id=\"microsoft-explains-why-it-scrapping\">\n<h2 class=\"subhead-embed\">Microsoft Explains Why It Is Scrapping SMS Authentication<\/h2>\n<p>\u201cSMS-based authentication is now a leading source of fraud,\u201d Microsoft has said, \u201cand by moving to passwordless accounts, passkeys, and verified email, we&#8217;re helping you stay ahead of evolving threats while making account access simpler and more seamless.\u201d<\/p>\n<p>That fraud comes in many guises, from attacks targeting senior citizens to SMS pumping attacks that target phone bills, but the type of fraud that Microsoft is addressing with this change is directed at account authentication. It doesn\u2019t take a tech genius to realize that transmitting 2FA codes in plain text, using cellular networks, is hardly the most secure method to do so. Interception and SIM-swap attacks are just two of the risks. But that doesn\u2019t really matter; what does is that there are many more secure methods of receiving 2FA codes, by way of an authenticator app, for example, and many more secure methods for logging in, such as a passkey. There really is no need to be using SMS anymore, especially when those other methods are as easy, if not easier, to use. Microsoft itself has now <a rel=\"nofollow\" class=\"color-link\" href=\"https:\/\/support.microsoft.com\/en-us\/accounts-billing\/manage\/microsoft-to-stop-sending-sms-codes-for-personal-accounts#wl\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.microsoft.com\/en-us\/accounts-billing\/manage\/microsoft-to-stop-sending-sms-codes-for-personal-accounts#wl\" aria-label=\"said\">said <\/a>that it \u201cbelieves that the future of authentication is passwordless, secure, and user-friendly.\u201d<\/p>\n<p><span class=\"link-embed__info\"><span class=\"link-embed__provider\">Forbes<\/span><span class=\"link-embed__title\">2 New Microsoft Defender Zero-Days Exploited\u2014Patch Now Rolling Out<\/span><small class=\"link-embed__byline\">By <span class=\"link-embed__author\">Davey Winder<\/span><\/small><\/span><span class=\"link-embed__thumbnail-wrapper\"><span class=\"link-embed__thumbnail allow-inline-style\" style=\"background-image:url(https:\/\/specials-images.forbesimg.com\/imageserve\/503493618\/0x0.jpg)\"\/><\/span><\/section>\n<section id=\"microsoft-says-personal-account-users\">\n<h2 class=\"subhead-embed\">Microsoft Says Personal Account Users Should Move To Passkeys<\/h2>\n<p>Microsoft has confirmed that users signing in to a personal account will be \u201cguided through a simple process to add a verified email and set up a passkey,\u201d so they can both log in and recover the account without using SMS. It is not yet clear what the timeline is for phasing out SMS codes altogether, but I would recommend making the change now to stay on top of things and, it must be said, to improve your security posture at the same time. You can also find out more and <a rel=\"nofollow\" class=\"color-link\" href=\"https:\/\/support.microsoft.com\/en-us\/topic\/09a49a86-ca47-406c-8acc-ed0e3c852c6d\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.microsoft.com\/en-us\/topic\/09a49a86-ca47-406c-8acc-ed0e3c852c6d\" aria-label=\"register a passkey here\">register a passkey here<\/a>.<\/p>\n<p>Once you have done so, there will be no more waiting around for those SMS codes to arrive on your smartphone, as signing in with a passkey is pretty much instant; just use your device\u2019s biometrics or PIN.  Passkeys are also highly phishing-resistant, while maintaining ease of use even when recovering an account. \u201cPasskeys ensure users can recover access even if they change phone numbers or lose devices,\u201d Microsoft confirmed. So, what are you waiting for?<\/p>\n<\/section>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/21\/microsoft-is-scrapping-sms-2fa-codes-what-you-need-to-do\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft starts scrapping 2FA SMS codes. getty Microsoft has confirmed it is starting to phase out SMS as a method of authentication, as well as account recovery, for all personal Microsoft accounts. If you use SMS as your primary 2FA code delivery mechanism, you had better pay attention and change to something else as soon<\/p>\n","protected":false},"author":1,"featured_media":13530,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[37],"tags":[],"class_list":["post-13529","post","type-post","status-publish","format-standard","has-post-thumbnail","category-brand-spotlights"],"_links":{"self":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts\/13529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13529"}],"version-history":[{"count":0,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts\/13529\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/media\/13530"}],"wp:attachment":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}