A P3C Technologies help article  |  Updated September 18, 2026

Why this matters right now

Microsoft is retiring text-message and phone-call multi-factor authentication for Microsoft 365. As of
September 1, 2026, users still enrolled in SMS or voice authentication are being automatically
enabled for passkeys and prompted to register one. On February 1, 2027, Microsoft-provided SMS
and voice delivery is retired outright — and anyone whose only sign-in method is a text or a phone call will hit a blocking prompt before they can get into their account.

If a texted code is the only way you verify a sign-in, now is the time to add something better. This guide walks through both halves of that: seeing what you currently have, and adding something new.

Before you start: get to the right page safely

Everything below happens on Microsoft’s Security info page:

https://mysignins.microsoft.com/security-info

Shorter version, easier to remember: aka.ms/mysecurityinfo

Type that address into your browser yourself, or use a bookmark you created. Do not search for it
and click the top result. Attackers routinely buy paid search ads that point at pixel-perfect fake Microsoft
sign-in pages, capture what you type, and then forward you to the real site so you never notice. A login page is the last place you want to trust a search result. Sign in with your normal Microsoft 365 work email and password.


Part 1: Review the methods you already have

Once you are signed in, the Security info page lists every authentication method attached to your account, along with your default sign-in method at the top. Most people have never looked at this page, and most
people find at least one surprise on it.

Read down the list and ask yourself three questions:

  • Do I still have this? An old phone number you gave up two carriers ago, or an Authenticator app on a phone you traded in, is not a backup — it is a dead end you will discover at the worst possible moment.
  • Do I recognize this? A phone number or device you do not recognize is a serious red flag. Stop and contact us immediately.
  • Is a text message or phone call doing all the work? If “Phone” is your only entry, or your default, that is the one to fix first.

While you are on this page, you can also review your recent sign-in activity. If you have been getting
authentication prompts you did not trigger, that history is where you look.


Part 2: Add a new sign-in method

On the Security info page, click + Add sign-in method, then pick from the list your organization
allows. The options you see are controlled by your administrator, so not everyone sees the same menu.

What we recommend, in order:

  • Passkey. The most phishing-resistant option available, and the direction Microsoft is actively pushing everyone. It uses your device’s fingerprint reader, face recognition, or PIN. There is no code for anyone to intercept or trick out of you.
  • Microsoft Authenticator app. Excellent and widely supported. You approve a push notification and confirm a number shown on screen — that number-matching step is what stops attackers from spamming you with prompts until you tap the wrong one.
  • Another authenticator app. If your team already standardizes on something else, Google Authenticator, LastPass Authenticator, and Duo all work. Choose I want to use a different authenticator app when prompted.
  • Hardware security key. A good fit for shared workstations, high-risk roles, or staff without a smartphone.

Setting up an authenticator app: install it on your phone first, then come back to the Security
info page, select the app method, and use the app’s “scan a QR code” function to photograph the code on
your computer screen. The site will ask you to complete one test approval to confirm it worked. Do that test. An unverified method is not a method.

Download the real app

Scammers publish look-alike authenticator apps to the Apple App Store and Google Play, complete with convincing icons and fabricated reviews. An imposter MFA app is worse than no MFA app at all. Check the publisher name, not just the app name — Microsoft Authenticator is published by Microsoft Corporation. If you are not certain you have the right one, stop and ask us before you scan anything.

How many methods should you have? Two is the sweet spot: a strong primary, plus one backup so a
lost or broken phone does not lock you out. Resist the urge to add five. Every extra method is another door, and your account is only as strong as its weakest one.


Part 3: Change your default, and clear out what you don’t use

Adding a passkey does not automatically make it your default. Near the top of the Security info page, find
Default sign-in method and click Change to point it at your strongest option. This
is the one Microsoft reaches for first every time you sign in.

Then clean house. Next to any method you no longer use — a retired phone number, a device you no longer own — click Delete and confirm. Microsoft requires you to keep at least one valid method on the
account at all times, so add the new one before removing the old one.

One caveat worth knowing: deleting an old method does not automatically end sessions that are already signed in. If you are cleaning up because you think something is wrong, deleting is not enough. Use Sign out everywhere on the same page, change your password, and call us.


Getting a new phone? Read this first.

A new phone is the single most common cause of MFA lockouts we see. Set up your authentication method on the new phone and confirm it works before you wipe, trade in, or hand off the old one. Once the old device is gone, the method registered to it is gone with it, and recovering access means an administrator has to reset your MFA registration or issue you a temporary access pass. That is a phone call and a delay you can avoid entirely with five minutes of planning.


If something doesn’t look like this guide

  • The method you want isn’t offered. Your administrator controls which options appear. A missing choice almost always reflects a policy setting, not a mistake on your end. Ask us and we can enable it.
  • You can’t change anything at all. Some organizations restrict self-service changes. Same answer — that is a policy we can adjust.
  • You’re locked out already. You cannot fix this from the Security info page, because getting to it requires signing in. Call us and we will reset your registration.
  • You have a personal Microsoft account with a similar address. Personal and work accounts are separate, with separate security settings. Changing one does nothing to the other. Make sure you are signed in with your work email.

Not sure where your team stands?
If P3C manages your Microsoft 365 environment, we can tell you exactly who is still relying on a text message and
help move them before the February deadline forces the issue.

Call 262.423.6267
or email support@p3ctech.com

Submit a support ticket

P3C Technologies LLC  |  West Bend, WI  |  p3ctech.com