Microsoft is scrapping SMS 2-factor authentication because it’s “a leading source of fraud”

Microsoft is scrapping SMS 2-factor authentication because it’s “a leading source of fraud”

By Simon Batt
Publication Date: 2026-05-19 00:56:00

Summary

  • Microsoft will stop using SMS for personal 2FA, citing it as insecure and prone to fraud.
  • Microsoft will push passwordless options like passkeys and verified email to improve security and UX.
  • SMS 2FA has become a major attack vector; moving away makes accounts harder for hackers to access.

While having two-factor authentication (2FA) enabled is always safer than not having it, not all methods are equal. We’re used to the trusty SMS 2FA method, where a company sends you a text during the login process and asks you to enter a code. However, when a security measure goes on long enough without any major revamps, bad actors find ways to…