TL;DR: Passwordless authentication is becoming the standard way to log in, and Microsoft will retire SMS and voice-based MFA for Microsoft 365 on 1 February 2027. If your firm still relies on text message codes, now is the time to plan the switch to passkeys.

Why passwordless authentication matters to your firm right now

Microsoft has confirmed that SMS and voice authentication for Microsoft 365 stops working on 1 February 2027. From September 2026, staff using text codes will start seeing prompts to set up a passkey instead. It affects every partner and every member of staff who logs into email or your case management system.

The National Cyber Security Centre has also changed its position. In April 2026, at CYBERUK, it announced it will recommend passkeys “wherever a service supports them”. For a law firm holding privileged client information, any delay in tightening login security is a delay in reducing your exposure to phishing.

What is passwordless authentication?

Passwordless authentication means logging in without typing a password. The most common form is a passkey. When you set one up, your device creates two matching digital keys. One stays on your device, the other is held by the service you are logging into.

When you log in, your device and the service check that their two keys match. You confirm it is you by unlocking your device with a fingerprint, face scan or PIN. Nothing gets typed, and nothing travels across the internet that a criminal could intercept.

This is what makes passkeys effective against phishing. A fake login page can look identical to the real one, but it cannot request the key on your device, because that key only responds to the genuine website it was created for. Even if a member of staff clicks a convincing phishing link, there is nothing for them to hand over.

Why is Microsoft retiring SMS and voice MFA?

Text messages and phone calls can be intercepted, and attackers have got better at tricking people into approving codes they never requested. Passkeys close that gap entirely.

Matt Dunn, COO and CTO at Labyrinth Technology, explains:

“Phish-resistant multi-factor authentication, such as passkeys, is extremely effective in combating the risk of phishing attacks. This is because it uses a device-bound key which cannot be compromised through a traditional email phishing or man-in-the-middle attack.”

The timeline is fixed. From 1 September 2026, Microsoft prompts SMS and voice users to register a passkey. From 1 February 2027, Microsoft-provided SMS and voice authentication stops working, with no opt-out.

“We’ve started talking to our clients about this, and it’s already clear this change will create a lot of friction,” Matt adds.

What is MFA fatigue and why does it matter for law firms?

MFA fatigue is when an attacker who already has your password sends repeated approval requests to your phone, hoping you eventually tap “approve” just to stop the notifications. Passkeys remove this risk, since there is no approval prompt to accept.

This matters more where client money is involved. Action Fraud recorded 143 cases of conveyancing fraud between April 2024 and March 2025, with losses of £11.7 million and an average loss of £78,393 per case. Most follow the same pattern: an attacker gets into an email thread and sends convincing instructions to change bank details at completion. Passkeys make that initial compromise far harder to achieve.

What should law firms do before the February 2027 deadline?

Audit who is still using SMS or voice MFA

Ask your IT provider for a list of every user still relying on text or phone call authentication. This is the group who will see prompts from September 2026.

Roll passkeys out in stages

Start with a small group that includes at least one partner, so you catch device issues early. Pay attention to staff using personal phones under a bring your own device policy, since their settings tend to be less consistent than firm-managed laptops.

Check your case management system

Confirm whether it supports passkeys directly, or only through your Microsoft 365 login, before you switch everyone over.

How Labyrinth Technology helps

Labyrinth Technology’s authentication solutions already supports passwordless authentication for clients moving away from passwords and one-time codes. For firms on Microsoft 365, that typically starts with Microsoft Entra ID passkeys, with WatchGuard AuthPoint or Okta for firms needing more advanced access controls.

Microsoft’s deadline is 1 February 2027. From today, that gives you under six months to get every partner and every fee earner switched over before the fallback disappears.

Get in touch today.

Newsletter

Stay informed with practical IT insights

Get useful updates, security advice, and technology guidance from the Labyrinth Technology team.