Retiring SMS and Voice Authentication in Entra ID (Microsoft) MFA

Summary

Description of the timeline for retiring SMS and Voice Authentication methods in Fall 2026

Body

Overview 

As part of an industry-wide push toward stronger account security, Microsoft is retiring native text message (SMS) and phone call verification. 

To comply with Microsoft's changes and protect university accounts against modern security threats like phone number spoofing and message interception, Purdue Information Technology is phasing out SMS and Voice verification methods over the Fall 2026 semester. We are managing this transition through a controlled, phased schedule to minimize disruption to university operations and ensure adequate support for campus users. 

 

What Is Changing and When? 

 

  • August 15, 2026: New users will no longer be able to set up phone calls or text messages for account verification. If you already use a phone for verification, your access will not change on this date. 
  • October 16, 2026: Text message and phone call verification options will be removed as secondary backup methods if you already have the Microsoft Authenticator app or another security method set up.  
  • November 16, 2026: Phone calls and text messages as an authentication method will be completely turned off for all accounts. You must have an alternative verification method set up before this date to avoid being locked out of your account. 

 

What do I have to do?  

If you currently sign in to Purdue protected applications using text messages or phone calls, you need to register another authentication method before November 16, 2026. 

 

Recommended Action: Set Up Microsoft Authenticator 

The Microsoft Authenticator app is the fastest and most secure way to sign in. 

  1. Download the app: Install Microsoft Authenticator from the Apple App Store (iOS) or Google Play Store (Android) on your mobile device. 
  1. Access your security settings: On a computer, go to https://mysignins.microsoft.com/security-info and sign in. 
  1. Add a method: Choose Add sign-in method, and select Authenticator app
  1. Follow the prompts: Scan the QR code shown on your computer screen using the app on your phone to complete setup. 

 

Once setup is complete, we recommend selecting the Authenticator app as the default sign-in method when the most advisable is unavailable. This setting is currently used when signing into the VPN. 

To change this setting:

  1. Locate Sign-in method when most advisable is unavailable (look for small text next to the Change link). 
  2. Click Change and select the desired Microsoft MFA default method
    • Recommended: Microsoft Authentication – Notification 
  3.  Save changes. 

 

What if I don't act? 

After November 16th, 2026, SMS and phone call verification will be permanently disabled. If you haven't registered another supported method, you will be unable to sign in and will need to contact the IT Service Desk at it@purdue.edu or 765-494-4000 to help regain access. 

 

Need assistance?

If you need help setting up your new verification method, please contact the Purdue IT Service Desk by clicking on the 'Purdue IT Request' button associated with this article.

https://it.purdue.edu/help/ 

  • Purdue West Lafayette: 765-494-4000 it@purdue.edu 
  • Purdue Fort Wayne: 260-481-6030 helpdesk@pfw.edu 
  • Purdue Northwest: 219-989-2888 csc@pnw.edu 

 

Frequently Asked Questions 

  

Q: Why are text messages and phone calls being retired as authentication methods? 

  

Text messages and phone calls are outdated security methods. They can be intercepted or redirected by attackers. Moving to more secure options like the Microsoft Authenticator app helps ensure your account remains protected against unauthorized access. 

  

Q: Why is Purdue making this change before Microsoft's final deadline? 

  

Microsoft will fully turn off native phone verification in early 2027. Purdue is phasing out these options during the Fall 2026 semester to give our campus adequate time, support, and guidance to transition smoothly without risking last-minute sign-in disruptions. 

  

Q: What should I do to prepare? 

 

If you currently rely on text messages or phone calls to sign in, you should set up an alternative verification method as soon as possible. We recommend downloading and configuring the Microsoft Authenticator app on your smartphone. 

  

Q: How do I add a new authentication method? 

 

  1. Go to your Security Info page at https://mysignins.microsoft.com/security-info
  2. Select +Add Sign-in Method
  3. Choose Microsoft Authenticator or another approved method from the list and follow the on-screen instructions. 
    1. A free download link will be provided during enrollment. 

 

Q: How do I check which methods I’ve enrolled? 

 

Visit your Security Info page to view your registered methods. Any method labeled Phone will be impacted by this change. 

 

Q: I use the Authenticator app already. Will I be impacted? 

No. You will not be impacted unless you rely on SMS text messages or voice calls for verification. 

 

Q: I know I use my phone to sign in, but I’m not sure if it’s the Authenticator app or SMS/Voice. How can I test it? 

 

How you verify depends on what you are signing into: 

 Testing with Web Applications (Purdue SSO)  

Open an incognito or private browser window and navigate to a Purdue application (such as Brightspace, SuccessFactors, or your Student Portal). When prompted to verify: 

  • If your phone texts or calls you: You are using SMS or Voice. 
  • If a notification pops up or you open an app for a code: You are using the Microsoft Authenticator app. 

Testing with the VPN  

The VPN automatically defaults to the primary method configured on your account: 

  • Go to your Security Info page and sign in. 
  • Check your Default sign-in method (small text located next to the Change link). 
  • If listed as Phone, you are using SMS or Voice and will need to select a supported method before October 16th (such as Microsoft Authenticator, a hardware token, or a Security Key). 

 

Q: What if I don’t have a smartphone? 

 

If you do not own a smartphone, or plan to be in a part of the world where you will not have Internet access and are therefore unable to use Microsoft Authenticator, a physical token may be utilized. 

Purdue IT recommends the following models due to compatibility, cost, and operational consistency: 

YubiKey 5 Series Models 

USB-C YubiKey 5C NFC Two-Factor Security Key | Yubico 

Visit the following link for more information on obtaining a physical token for MFA: https://service.purdue.edu/TDClient/32/Purdue/KB/Article/524/How-do-I-obtain-a-physical-token-FOB-for-MFA 

 

Q: What if I need assistance? 

 

If you need help setting up an alternative authentication method, please reach out to the IT Service Desk for assistance before the retirement deadlines. 

https://it.purdue.edu/help/ 

  • Purdue West Lafayette: 765-494-4000 it@purdue.edu 
  • Purdue Fort Wayne: 260-481-6030 helpdesk@pfw.edu 
  • Purdue Northwest: 219-989-2888 csc@pnw.edu 

 

 

 

Details

Details

Article ID: 2380
Created
Mon 8/10/26 5:14 PM
Modified
Mon 8/17/26 3:11 PM

Related Articles

Related Articles (2)

Guide to setting up Microsoft MFA to protect your Purdue email account.
Microsoft Multi-Factor Authentication (MFa) is used to protect Purdue email and Microsoft accounts.