Your Microsoft text codes are going away
Microsoft is phasing out SMS-based authentication for personal Microsoft accounts and pushing users toward passkeys and verified email for sign-in and account recovery. The move — aimed at reducing fraud from SIM-swap attacks, phishing and intercepted text codes — affects Outlook, OneDrive, Windows, Xbox and Microsoft 365 personal users. Microsoft will guide remaining SMS users to add a verified email and set up passkeys (device biometrics, PINs or physical security keys); there is no universal cutoff date. For markets, the change is operational/security-focused with limited direct near-term impact on MSFT equity, but it reduces a class of reputational and customer-risk exposure, modestly strengthening Microsoft’s security posture. Users should update recovery emails, remove old phone numbers, enable Authenticator or passkeys and securely store recovery codes.