Microsoft is retiring text-message sign-in codes
Starting February 1, 2027, Microsoft is discontinuing SMS and phone-call codes as a way to verify your identity when you sign in to Microsoft 365. If your account still uses a texted code today, you'll need to switch to a more secure method beforehand.
This is Microsoft's change, not ours. IT Support RI has no control over it — Microsoft is rolling it out to every account worldwide. We're giving you early notice so your sign-in is never interrupted.
A security upgrade Microsoft is applying to everyone
Text-message codes can be intercepted through SIM-swap and phishing attacks, so Microsoft is moving all accounts to stronger sign-in methods — an authenticator app or a passkey. There's nothing wrong with your account; this is a platform-wide change on Microsoft's schedule.
You'll start getting prompted
Microsoft makes passkeys the default and begins nudging accounts still on SMS to set up a more secure method at sign-in.
SMS & phone-call codes stop working
Microsoft fully retires texted and voice codes. Accounts without another method set up will be forced to add one before they can finish signing in.
Switch to a secure method
Microsoft 365
Recommended: the free Microsoft Authenticator app (or a passkey). It replaces texted codes with a quick approval or fingerprint/face check.
On your phone, install Microsoft Authenticator from the Apple App Store or Google Play.Publisher: Microsoft Corporation.
On a computer, go to
aka.ms/mysecurityinfoand sign in with your work email.Click + Add sign-in method.
Choose Microsoft Authenticator (or Passkey if it's offered), then follow the prompts and scan the QR code with the app on your phone.
Approve the test notification on your phone to confirm it works.
Once the app is working, you can remove the old Phone / text message method from the same page.
Some options depend on how your organization is configured. If a step looks different or an option is missing, that's normal — reach out and we'll walk you through it.
Google Workspace
Recommended: a passkey or an authenticator app in place of texted codes — the same secure upgrade, done proactively.
On your phone, install an authenticator app such as Google Authenticator or Microsoft Authenticator (either works).
On a computer, go to
myaccount.google.com→ Security.Under "How you sign in to Google," open 2-Step Verification and verify it's turned on.
Best option — Passkey: open Passkeys and security keys → Create a passkey, then confirm with your fingerprint, face, or device PIN.
Or — Authenticator app: find Authenticator → Set up authenticator → scan the QR code with the app → enter the 6-digit code to confirm.
With your passkey or app working, remove your phone number as a verification method.
Two short video guides
A quick overview of why this matters, plus a step-by-step walkthrough of registering your phone with the Microsoft Authenticator app.
Would you rather we just handle it?
We can set this up for your whole team and make sure no one gets locked out before the deadline. That's what we're here for.