Do you still trust SMS as an MFA solution?

Many companies still use SMS messages as part of multi-factor authentication (MFA). While SMS is much more secure than no MFA, it is no longer considered sufficiently secure against modern cyber threats. SMS authentication can be vulnerable to attacks such as SIM swapping, social engineering, and other methods that allow attackers to obtain authentication codes.

Microsoft has therefore announced that companies will need to move to stronger and phishing-resistant authentication methods, such as Passkeys, Windows Hello for Business, and Microsoft Authenticator. From 1 September 2026, Microsoft will automatically prompt users using SMS or phone calls for MFA to register a Passkey, and from 1 February 2027, Microsoft's built-in SMS and phone call service for MFA will be discontinued.

This highlights how quickly the cybersecurity landscape is changing. Solutions that were considered adequate a few years ago are not necessarily sufficient today. Therefore, it is important to regularly review the company's security posture, update security processes, and ensure that the best available solutions are being used at any given time.

I can assist in analysing your current MFA setup, identifying users who still rely on SMS authentication, and implementing more secure solutions that comply with Microsoft's latest requirements and best practices in cybersecurity. This way, you ensure that the company is not only better protected today but also prepared for the changes that lie ahead.

Similar Posts