PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Microsoft Is Ditching SMS 2FA Login Codes, Prioritizing Passkeys Instead

SMS-based authentication is now a leading source of fraud, Microsoft says.

 & Jon Martindale Contributor

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS
(Credit: Studio Romantic/Shutterstock)

Microsoft is looking to move away from SMS-based two-factor authentication for local account logins, citing its vulnerability to exploitation and fraud, according to Windows Latest. Instead, Microsoft wants everyone to start using passkeys (and eventually, ditch passwords altogether).

Although text messages have proved a useful way to add an extra layer of security to account logins, they were never designed for this purpose. SMS messages are sent in plaintext, making them a vulnerable vector for man-in-the-middle and number spoofing attacks.

"Microsoft is committed to advancing security standards and as such, we will start phasing out SMS as a method of authentication and account recovery for personal Microsoft accounts," Microsoft said in an official advisory. "SMS-based authentication is now a leading source of fraud, and by moving to passwordless accounts, passkeys, and verified email, we're helping you stay ahead of evolving threats while making account access simpler and more seamless."

Passkeys are a cleaner, more secure way to authenticate, leveraging the local security of a secondary device or your biometric information to confirm your identity. When setting one up, you can use your face, fingerprint, or a local password/PIN. That information never leaves that particular device, making it all but impossible for a third party to spoof it.

Last year, Microsoft said that anyone setting up a new Microsoft account would be encouraged to use a passkey during sign-up, removing passwords as the default.

However, while passkeys are more secure, they're not always be as convenient. When setting up new Windows PCs or temporary virtual machines, the biometric data may not be so readily available, and setting up a passkey every time can be laborious. SMS messages, in contrast, could be fast and convenient. However, that convenience comes at the cost of security. Fortunately, in those cases, verified email links will remain an option.

Microsoft hasn't given a date for fully phasing out SMS messages as a secondary authentication method, but users without a passkey will soon be prompted to set one up.

As someone who lives in an area with spotty reception and wonky Wi-Fi calling, this is welcome news. But even in areas where receiving an SMS isn't as pot-luck as it is for me, it's probably time to finish with SMS codes. It's antiquated and has proved for many years to be an insecure method of protecting users and their accounts.

About Our Expert

Jon Martindale

Jon Martindale

Contributor

Jon Martindale is a tech journalist from the UK, with 20 years of experience covering all manner of PC components and associated gadgets. He's written for a range of publications, including ExtremeTech, Digital Trends, Forbes, U.S. News & World Report, and Lifewire, among others. When not writing, he's a big board gamer and reader, with a particular habit of speed-reading through long manga sagas. 

Jon covers the latest PC components, as well as how-to guides on everything from how to take a screenshot to how to set up your cryptocurrency wallet. He particularly enjoys the battles between the top tech giants in CPUs and GPUs, and tries his best not to take sides.

Jon's gaming PC is built around the iconic 7950X3D CPU, with a 7900XTX backing it up. That's all the power he needs to play lightweight indie and casual games, as well as more demanding sim titles like Kerbal Space Program. He uses a pair of Jabra Active 8 earbuds and a SteelSeries Arctis Pro wireless headset, and types all day on a Logitech G915 mechanical keyboard.

Read full bio