As of September 7, 2026, Microsoft Entra ID has terminated the use of unregistered directory contact data for self-service password reset (SSPR). This SSPR retirement means mobile numbers, business phones, and secondary emails not explicitly registered as authentication methods no longer function for verification. Users relying on these legacy fields are now locked out of self-service recovery.
This enforcement follows the September 1, 2026, shift where passkeys became the default authentication experience in Entra ID. While users can currently snooze this transition, the runway is limited. By February 1, 2027, Microsoft-provided SMS and voice authentication will be fully retired. At that point, the passkey registration prompt becomes mandatory, and users relying solely on SMS or voice will be required to register a passkey to sign in.
The threat landscape demands this move. Microsoft environments face over 600 million daily identity attacks. AI-enabled phishing campaigns now achieve click-through rates of 54%, compared to 12% for traditional campaigns. As Nadim Abdo, CVP of Identity and Network Access Engineering at Microsoft, noted, the threat environment has evolved beyond the capabilities of SMS and voice. This reality is codified in NIST SP 800-63B Revision 4, which reclassified SMS and PSTN one-time passcodes as a restricted authenticator – the only method in that category.
This enforcement addresses the same structural failure at the identity provider level. Whether the pattern manifests as AI middleware vulnerabilities that treated authentication as optional, or the critical authentication failures in Cisco management infrastructure, the industry has consistently underinvested in treating identity as foundational. Microsoft is now forcing the transition to phishing-resistant methods where it matters most – at the point of entry.
Infrastructure readiness is high. According to the FIDO Alliance State of Passkeys 2026, there are 5 billion passkeys in active use, with 68% of organizations deploying or piloting them. Registration success rates hold at 99%, and sign-in success rates are 95% – three times higher than legacy methods. As Forrester Principal Analyst Geoff Cairns observed, phishing-resistant authentication is no longer optional.
Agent-native workflows increase the risk profile further. AI agents inherit the identity of their human counterparts, making weak authentication a vector for automated exploitation. If an agent operates on a phishable credential, the blast radius of compromise scales with the agent’s reach. The February 1, 2027, hard deadline is not a product sunset – it is the point where the last escape hatch closes for organizations still running on SMS and voice.
Microsoft reports 99.6% phishing-resistant authentication coverage internally, signaling the deprecation of legacy MFA as an industry baseline. For identity practitioners, the operational question is no longer whether to migrate but how fast the passkey lifecycle can be optimized. The authentication gap is closing. What remains is execution.
