Skip to content
Tech News
← Back to articles

Microsoft is killing off SMS login codes, citing AI-powered hacking

read original more articles
Why This Matters

Microsoft is discontinuing SMS-based two-factor authentication due to increasing security risks amplified by AI-driven hacking techniques. This move underscores the industry's shift towards more secure authentication methods like passkeys, biometrics, and PINs, aiming to better protect user accounts from sophisticated attacks. For consumers and organizations, adopting these advanced methods is crucial to maintaining account security in an evolving threat landscape.

Key Takeaways

In brief: Sending codes to users via SMS has long been discredited as the least secure multi-factor authentication method, and Microsoft will soon discontinue support for this practice altogether. Citing the rising danger of hackers armed with AI tools, the company has now provided a timeline for phasing out SMS codes.

IT admins will no longer be able to log into Microsoft Entra ID accounts using SMS-based 2FA codes starting February 1. The deadline is part of Microsoft's broader shift toward passkeys, widely considered one of the most secure login methods.

Admins recently began receiving an email from the company, obtained by Windows Latest, which outlines the SMS phaseout. Earlier this year, a support document also warned that Microsoft will eventually cease sending SMS codes to ordinary Windows Home and Professional users, but when that will happen remains unclear.

Security experts have advised against sending 2FA codes via text messages for years, primarily because they are easily intercepted. However, Microsoft's recent announcement also claims that AI has made phishing and other hacking methods more effective.

Traditional phishing strategies are more likely to trick users into handing over passwords and other sensitive data when used in tandem with AI. The technology also makes it easier for attackers to carry out SIM-swapping attacks.

A recent Windows 11 update also retired picture passwords. Initially introduced to promote Windows 8's touch capabilities, tracing gestures over pictures to log into Windows has not been considered truly secure for some time.

Microsoft has instead promoted PINs, biometrics, and passkeys over other methods, especially passwords. The company already encourages users to delete their passwords and use passkeys as their first login method. Starting September 1, Entra will prompt users to establish a passkey.

Easier to set up and use, passkeys lock authentication to specific devices without storing critical data on servers, leaving nothing for attackers to steal. However, researchers recently demonstrated that systems compromised with malware can leak passkey data stored in Google Chrome's memory.

Meanwhile, Google recently began testing another sign-in method for users who forget their passwords and do not have access to passkeys. After providing the company with a selfie video, users can log in from any other device by uploading another one, which is compared to the original. It remains to be seen whether the method is more or less secure than other biometric options.