SMS MFA is changing. Small businesses should use the transition to strengthen authentication.
Multi-factor authentication remains one of the most useful account protections a small business can deploy. But not every MFA method provides the same protection, and the industry is moving toward phishing-resistant sign-in methods such as passkeys and security keys.
If your business still uses text-message codes for multi-factor authentication, this is not a reason to panic or disable MFA. SMS MFA is generally better than relying on a password alone.
It is, however, a good reason to review how your important accounts are protected.
Security guidance has increasingly moved toward phishing-resistant authentication. NIST notes that text codes are particularly vulnerable compared with stronger MFA methods, and recommends considering phishing-resistant authenticators for sensitive information and privileged users. Microsoft is also actively moving its cloud identity platform away from native SMS and voice authentication: beginning September 1, 2026, affected users are being prompted toward passkeys, with Microsoft-provided SMS and voice delivery scheduled to end February 1, 2027.
The useful business question is not “Is SMS MFA bad?” It is: where would stronger authentication meaningfully reduce our risk, and how do we migrate without disrupting the office?
Why ordinary MFA can still be phished
A password plus a six-digit code feels substantially stronger than a password alone, and it is. The weakness is that the user can still be tricked into giving both pieces to an attacker.
A convincing phishing page can imitate a legitimate sign-in screen, collect the password, ask for the current MFA code, and relay those credentials to the real service while the code is still valid. Some push-notification methods can also be abused through repeated prompts or social engineering.
Phishing-resistant authentication works differently. Modern passkeys and FIDO-based security keys use public-key cryptography and bind the authentication to the legitimate service. There is no reusable six-digit code for an employee to accidentally type into a fake website.
That distinction matters most for accounts that can cause disproportionate damage if compromised: email, cloud administration, financial systems, password managers, remote-access tools, and systems containing client or patient information.
Do not turn this into a company-wide emergency migration
Small businesses often make security harder than necessary by trying to change everything at once. A better approach is to rank accounts by consequence.
Anyone who can create users, reset passwords, change security settings, or access the entire cloud environment should use the strongest practical authentication method.
Email is frequently the recovery path for other accounts. Tax, healthcare, finance, and executive users also warrant stronger protection.
Identify which systems support passkeys, security keys, authenticator applications, or only SMS. You cannot improve what nobody has documented.
Stronger authentication is not useful if one lost phone locks the company out. Recovery methods should be documented, secured, and tested.
What a passkey actually changes
A passkey replaces the familiar shared secret model with a cryptographic credential. The private key stays with the user’s device or credential provider; the service stores the corresponding public key. The user typically approves sign-in with the same device unlock mechanism they already use, such as a PIN or biometric.
This can be both more secure and easier for employees. There is no password to remember for that sign-in and no one-time code to copy from a text message. NIST describes properly implemented passkeys as phishing-resistant, and modern platforms increasingly support them directly on phones and computers.
Hardware security keys are another strong option. They are particularly useful for administrators, shared workstations, higher-risk roles, or environments where the business wants tighter control over the physical authenticator.
Microsoft 365 organizations have a concrete deadline to plan around
For organizations using Microsoft Entra ID in the public cloud, Microsoft announced a specific transition in 2026. Starting September 1, users enabled for SMS or voice authentication are being moved toward passkey registration. Microsoft says its own SMS and voice delivery will be retired February 1, 2027.
Businesses that still have a legitimate need for SMS or voice will have a path involving customer-managed telecom providers, but for most small organizations the cleaner long-term direction is to move users toward phishing-resistant methods before the deadline.
If you manage Microsoft 365, this is worth reviewing now rather than waiting for an employee to encounter a blocking registration prompt during a busy morning.
A practical authentication review for a small business
- List your cloud applications and identify who administers each one.
- Confirm that MFA is enabled everywhere it is available.
- Identify accounts still dependent on SMS or voice.
- Move administrators and other high-impact users to phishing-resistant authentication first.
- Document at least one secure recovery method for critical accounts.
- Remove old accounts and unnecessary administrative privileges.
- Teach employees that an unexpected MFA prompt is a security event, not an annoyance to approve.
- Review authentication methods during employee onboarding and offboarding.
This is also a good example of why cybersecurity is an operating process rather than a collection of products. Authentication changes over time. Employees change devices. Applications add better options. People leave the company. A configuration that was reasonable two years ago may no longer be the configuration you would choose today.
Do the simple thing first
If some employees currently have no MFA, enable an appropriate MFA method rather than waiting for a perfect passkey rollout. If MFA is already broadly deployed, start improving the highest-impact accounts.
The goal is not to chase every new security feature. It is to steadily remove easy paths into the business while keeping the environment usable.
For more on how identity controls fit into a broader security program, see our cybersecurity services and managed IT services. Tax and accounting firms can also review our IT and WISP guidance for accounting practices.
Authoritative guidance
- NIST: Multi-Factor Authentication for Small Business
- NIST: Passwords, MFA, and Passkeys
- Microsoft: Passkeys by Default and SMS/Voice Authentication Retirement
Need to review how your business handles authentication?
HarrisFCS can help inventory accounts, strengthen identity controls, and build the changes into normal IT operations without turning security into another project the owner has to manage personally.