By Simon Batt
Publication Date: 2026-05-19 00:56:00
Summary
- Microsoft will stop using SMS for personal 2FA, citing it as insecure and prone to fraud.
- Microsoft will push passwordless options like passkeys and verified email to improve security and UX.
- SMS 2FA has become a major attack vector; moving away makes accounts harder for hackers to access.
While having two-factor authentication (2FA) enabled is always safer than not having it, not all methods are equal. We’re used to the trusty SMS 2FA method, where a company sends you a text during the login process and asks you to enter a code. However, when a security measure goes on long enough without any major revamps, bad actors find ways to…




