Entra ID & IdentityHow-To & HardeningRetrospectives

How to Migrate Users From SMS to Authenticator App and FIDO2 MFA

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2018, written in 2026 with the benefit of hindsight.

SMS and voice codes are the weakest forms of MFA. Here is how to migrate Microsoft 365 users to the Microsoft Authenticator app and, for higher-risk users, to FIDO2 security keys or passkeys.

Step 1: Measure where you are

In the Entra admin center, go to Protection → Authentication methods → User registration details to see which methods each user has registered. Count users whose only method is SMS or voice.

Step 2: Enable target methods

In the Authentication methods policy:

  • Enable Microsoft Authenticator for all users (number matching is on by default).
  • Enable Passkey (FIDO2) for a pilot group and later for admins and high-risk users.
  • Consider Temporary Access Pass for onboarding and recovery.

Step 3: Nudge users to register

Use the registration campaign feature to prompt users to set up Microsoft Authenticator at sign-in. Run it for several weeks with a limited number of snoozes.

Step 4: Require stronger methods

Use Conditional Access authentication strengths:

  • "Multifactor authentication" for general users.
  • "Phishing-resistant MFA" for administrators and privileged roles.

Step 5: Turn off SMS and voice

Once most users have registered Authenticator, disable SMS and voice in the authentication methods policy for the general population. Keep a documented exception path for users who cannot use an app.

Step 6: Fix recovery

Update self-service password reset settings so SMS is not the only recovery method, and train the help desk on identity verification.

Measure

Track the percentage of users with phishing-resistant methods registered. That number should rise every quarter.

migrate sms mfa to authenticatorReddit SMS 2FA2018

More on this story