Skip to Content (custom)
Texas Association of Counties
Toggle Navigation (custom)

    TAC County Information Resources Agency (CIRA)

    TAC CIRA provides technology services, including email and website services, and training and informational resources to county and local government entities, such as drainage and hospital districts.

    FAQs

    Microsoft MFA Change

    On July 14, Microsoft announced they will be discontinuing text (SMS) or phone call-based multi-factor authentication (MFA). Their announcement can be found in this article.  The date of the termination is Feb. 1, 2027. After that time, users will not be able to use SMS/Phone Call as a form of MFA.

    What is MFA?

    As part of this change, starting Sept. 1, Microsoft will be prompting users with SMS/phone call MFA enabled for their organization to setup a newer MFA method: Passkeys. Passkeys are certificates stored on a device or in a cloud service. Passkeys are more resistant to phishing than most other MFA methods because they can only be used with the web domain that setup the passkey. These passkeys can be created on a mobile device using a QR code and then synced to a cloud service such as Apple iCloud or Android Play, as well as password managers like LastPass, 1Password and BitWarden.

    SMS/phone call MFA users will be able to skip the passkey setup until Feb. 1, at which point they will be forced to use other MFA options such as Microsoft Authenticator or Passkeys.

    Users who are already using other MFA methods such as Microsoft Authenticator can still use those methods. Microsoft said that any user with SMS MFA enabled for them will still be prompted to set up Passkeys.

    Microsoft will provide more info and create additional technology related to this change in September and October. 

    FAQ

    Who will be effected by this change? Microsoft says that users with SMS/phone call as an enabled and available MFA method will be effected, even if they are using other MFA methods such as Microsoft Authenticator.

    Can we opt out of this change? You can only delay the change. SMS/phone call-based MFA will cease operating on February 1, 2027. The passkeys setup can be skipped by the users until then.

    What happens if a user loses their device? Passkeys in iCloud, for example, will sync to other devices on that iCloud account. However, if there is a problem with that sync, Microsoft 365 administrators have temporary access options to then allow the user to set up new Passkeys.

    Can my MFA users exclusively use Passkeys for their MFA? Not yet. Microsoft plans to deploy that capability in mid-September as of this writing. Until then, the user must be set up with another MFA method such as Microsoft Authenticator or SMS/phone call.

    Are there any benefits to this change? SMS/phone call-based MFA is more vulnerableto cyber attacks.In addition, passkeys are considered more phishing-resistant than some other MFA methods.

    Is a smart device required for MFA once SMS/phone call MFA is discontinued? In most cases, yes. Microsoft tenants can set up conditional access policies to secure access without MFA. However, this requires the purchase of additional Microsoft licensing. Other alternatives are password managers such as 1Password, BitWarden andLastPass.

    Is there a paid replacement for the SMS/phone call MFA? Microsoft  mentioned third party partners who will offer paid SMS-based alternatives. TAC CIRA expects to learn more details mid-September. Due to the incomplete information, TAC CIRA cannot say if we will be able to support or provision these services.