How to Migrate Users From SMS to Authenticator App and FIDO2 MFA
Retrospective: this article looks back at events from August 2018, written in 2026 with the benefit of hindsight.
SMS and voice codes are the weakest forms of MFA. Here is how to migrate Microsoft 365 users to the Microsoft Authenticator app and, for higher-risk users, to FIDO2 security keys or passkeys.
Step 1: Measure where you are
In the Entra admin center, go to Protection → Authentication methods → User registration details to see which methods each user has registered. Count users whose only method is SMS or voice.
Step 2: Enable target methods
In the Authentication methods policy:
- Enable Microsoft Authenticator for all users (number matching is on by default).
- Enable Passkey (FIDO2) for a pilot group and later for admins and high-risk users.
- Consider Temporary Access Pass for onboarding and recovery.
Step 3: Nudge users to register
Use the registration campaign feature to prompt users to set up Microsoft Authenticator at sign-in. Run it for several weeks with a limited number of snoozes.
Step 4: Require stronger methods
Use Conditional Access authentication strengths:
- "Multifactor authentication" for general users.
- "Phishing-resistant MFA" for administrators and privileged roles.
Step 5: Turn off SMS and voice
Once most users have registered Authenticator, disable SMS and voice in the authentication methods policy for the general population. Keep a documented exception path for users who cannot use an app.
Step 6: Fix recovery
Update self-service password reset settings so SMS is not the only recovery method, and train the help desk on identity verification.
Measure
Track the percentage of users with phishing-resistant methods registered. That number should rise every quarter.
- Reddit's Breach via SMS Interception (Aug 2018): Why SMS MFA Isn't Enough Incident Teardowns
- Detecting SMS MFA Interception: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Not All MFA Is Equal — The Case for Phishing-Resistant Methods CIO Briefings