Changes to MFA Methods for Microsoft SSO

SMS is being phased out as a second authentication factor

SMS verification, which has been supported for Microsoft SSO until now, is being phased out. New SMS-based MFA methods can no longer be registered as of now.

SMS registrations that have already been set up will remain active until December 31, 2026 and will be deactivated thereafter.

Therefore, please switch to a different MFA method by the end of 2026.

Our recommendation: Passkeys

Microsoft recommends using passkeys for Microsoft SSO. In some German-language operating systems and applications, the term Hauptschlüssel is also used for this purpose.

Passkeys offer better protection against phishing attacks than SMS codes and, at the same time, make logging in easier. For example, a passkey can be stored on a smartphone, a computer, in a password manager, or on a hardware security key.

When you log in, you verify your identity directly on your device — for example, using a fingerprint, facial recognition, or your device PIN. There is no need to enter an SMS code.

Managing Your MFA Methods

You can find your MFA methods at

https://mysignins.microsoft.com/security-info, opens an external URL in a new window

There, you can add new login methods or remove methods you no longer need.

Detailed instructions for setting up passkeys on various operating systems and devices are available as an accessible PDF, opens an external URL in a new window or on the CoLab page, opens an external URL in a new window.

Subscription

You will receive all current information directly by email.