Why It's Time to Move Beyond SMS: Embracing Microsoft Authenticator and Passkeys
For many years, SMS verification codes have been the most common way to secure online accounts. When you log in, a code is sent to your mobile phone and you enter it to confirm your identity. While this was once considered a strong security measure, the cyber security landscape has changed dramatically.
Today, SMS-based authentication is increasingly viewed as a legacy technology. Cyber criminals have developed sophisticated techniques to intercept, redirect, or trick users into providing SMS verification codes. As a result, businesses and individuals are being encouraged to move towards more secure alternatives such as the Microsoft Authenticator app and passkeys. Microsoft has made it clear that the future of authentication is passwordless and phishing-resistant, with passkeys becoming the preferred sign-in method across its platforms.
The Problem with SMS Authentication
SMS authentication relies on your mobile phone number. While this may appear secure, phone numbers can be compromised through:
· SIM swap attacks
· Social engineering scams
· Phishing websites
· Malware on mobile devices
· Interception of text messages
Microsoft has publicly stated that SMS authentication is vulnerable to phishing, interception, and other forms of attack, making it significantly less secure than modern authentication methods. The company is actively moving away from SMS as a primary authentication method.In practical terms, an attacker no longer needs to guess your password. If they can convince you to enter an SMS code into a fake login page, they may gain access to your account in real time.
Why Microsoft Authenticator Is Better
The Microsoft Authenticator app provides a much stronger level of protection than SMS messages.
Instead of relying on a text message, the app sends a secure approval request directly to your trusted mobile device. In many cases, you simply tap “Approve” after verifying a number displayed on screen.
Benefits include:
· Better protection against phishing attacks
· No dependence on mobile phone coverage
· Faster sign-in experience
· More difficult for attackers to intercept
· Support for passwordless sign-in
For most users, moving from SMS to Microsoft Authenticator is the simplest and most effective security improvement they can make today.
Passkeys: The Future of Secure Sign-In
While Authenticator is a significant improvement, passkeys represent the next generation of authentication.
A passkey allows you to sign in using:
· Face recognition
· Fingerprint scanning
· Windows Hello
· Device PIN
· Hardware security keys
Behind the scenes, passkeys use advanced cryptography rather than shared secrets or one-time codes. This means there is no code for an attacker to steal and no password for a user to forget. Microsoft describes passkeys as phishing-resistant and designed to provide stronger protection than traditional passwords or SMS-based authentication.
For the end user, the experience is remarkably simple. Instead of entering a password and waiting for a code, you simply confirm your identity using your face, fingerprint, or device PIN.
Microsoft’s Direction Is Clear
Microsoft is making passkeys the default authentication experience within Microsoft Entra ID and has announced the retirement of its native SMS and voice authentication services in the future. The company’s guidance is clear: organisations should move users from phishable authentication methods to phishing-resistant methods such as passkeys.
For personal Microsoft accounts, Microsoft has also begun phasing out SMS-based authentication and account recovery, encouraging users to adopt passkeys, Authenticator, and verified email instead.
This is not simply a technology upgrade. It reflects a broader industry shift towards stronger identity protection as cyber attacks become increasingly sophisticated.
Should SMS Become Redundant?
In our view, yes.
SMS authentication still provides better protection than using only a password, but it should no longer be considered the preferred solution.
Businesses should now view SMS as a fallback or temporary measure while transitioning users to stronger authentication methods. New deployments should focus on Microsoft Authenticator and passkeys wherever possible.
This approach aligns with recommendations from Microsoft and broader cyber security frameworks, which increasingly favour phishing-resistant authentication methods over traditional SMS verification.
What Blue Sprout Recommends
For our clients, the recommended progression is:
1. Enable Multi-Factor Authentication for all users.
2. Move from SMS authentication to Microsoft Authenticator.
3. Adopt passwordless authentication where appropriate.
4. Roll out passkeys across supported devices.
5. Educate staff on phishing-resistant sign-in methods.
By taking these steps, organisations can significantly reduce the risk of account compromise while also simplifying the user sign-in experience.
Final Thoughts
The days of relying on SMS codes for account security are coming to an end. As cyber threats evolve, stronger authentication methods are becoming essential rather than optional.
Microsoft’s investment in Authenticator and passkeys demonstrates where the industry is heading: fewer passwords, fewer codes, and far better protection against phishing and account takeover attacks.
If your organisation is still primarily using SMS-based authentication, now is the ideal time to plan the transition. Moving to Microsoft Authenticator and passkeys will improve both security and user experience while future-proofing your identity platform for the years ahead.
Need help implementing Microsoft Authenticator, Passkeys, or Passwordless Sign-In across your organisation? Contact Blue Sprout to discuss a secure migration strategy tailored to your business.