Microsoft Changes to Multi-Factor Authentication (MFA)

Body

Microsoft Deprecation of SMS and Voice Calling MFA Methods

Over the next several months, Microsoft will be globally changing how users are able to authenticate into their Microsoft account. You will no longer be able to use SMS and voice calling as a multi-factor authentication. This means that these changes also impact how you authenticate into your Cobleskill account.

Please see below, the list of changes that will directly impact your experience when signing into your Cobleskill account and the dates in which these changes are being pushed out:

  • September 1st, 2026 – Users that currently have SMS or voice configured as an authentication method will be prompted upon logging into their Cobleskill account to register a phishing resistant multi-factor authentication method.
  • February 1st, 2027 – Microsoft will no longer support SMS or Voice multi-factor authentication when attempting to sign into your Cobleskill account
  • After February 1st, 2027 – anyone that attempts to sign into their Cobleskill account after this date will be blocked from signing in and will be forced to register a phishing resistant multi-factor authentication method or will need to contact the service desk to remediate this issue.

 

Why is Microsoft Making these Changes? 

Microsoft's aggressive timeline for these changes is an attempt to strengthen identity security in response to the growing concern over the rapidly evolving AI characterized by increased sophistication, speed, and scale of phishing campaigns, SIM swapping, multi-factor authentication bypass, and cyberattacks. Text message and voice are no longer a secure multi-factor authentication method, these can be easily manipulated to the benefit of an attacker and users can be easily deceived by AI enabled attacks to provide the MFA code to an attacker.

Microsoft is strongly steering organizations toward phishing-resistant multi-factor authentication by nudging users to passkey registration and retiring SMS and voice multi-factor authentication.

What Should You Do Now?

If you currently have your multi-factor authentication methods configured to send you a code via text message to your phone number or you receive a phone call that provide you with a code you will be impacted by this change and you will need to configure at a minimum two of the following options below to prevent being potentially locked out of your Cobleskill account on February 1st, ideally you should aim for 3.

  • Passkey
  • FIDO security key
  • Windows Hello for Business
  • Microsoft Authenticator phone sign-in (passwordless)
  • Microsoft Authenticator Push notification (number matching)

These options are currently the only supported methods that you can configure multi-factor authentication on your Cobleskill account. You can learn how to configure each of these options by visiting the knowledge base article MFA | How to configure MFA on your Cobleskill account.

Benefits To Using The New Supported MFA Methods

The new supported methods that Microsoft is enforcing brings about additional benefits other than improved security. By using any of the new supported MFA methods you can experience the following benefits:

  • Significantly faster login experience
  • There is no need to type in a code to login (this still applies to Authenticator phone sign-in passwordless and Microsoft Authenticator Push notification number matching)
  • You simply need biometrics or a PIN when using passkey, FIDO security key, or Windows hello for business
  • Can be used across multiple devices by using a QR code when using a passkey
  • You will not need to enter your password when utilizing one of the following options:
    • Passkey
    • FIDO security key
    • Windows Hello for Business
    • Microsoft Authenticator phone sign-in (passwordless)
  • Using the FIDO security key does not require the need to a phone or laptop like the other methods do.

What Should Users Expect? - Configuring a Passkey

Step 1 – Passkey Notification

Starting September 1st upon successful login to your cobleskill account, users that have SMS or voice enabled as a method to authenticate will receive the following notification:

Uploaded Image (Thumbnail)
This image shows a prompt that is directing you to configure a passkey

Use this notification, when convenient, to assist you with configuring a passkey. you can postpone the configuration if the timing isnt perfect for you to setup a passkey the moment you get that notification but be aware that you will not be able to postpone the notification past February 1st as you will be blocked from signing in until you have a passkey configured.

Step 2 – Configuring a passkey

If you proceed with configuring a passkey click next on the prompt in the previous image and may see the following prompt:

Uploaded Image (Thumbnail)
This image is showing the different locations to save a passkey when creating one

Depending on where you would like to save the passkey determines which option you select. If you are using a FIDO security key you will need to select Security key, if you are saving the passkey on the Microsoft Authenticator app you will need to select the iPhone, iPad, or Android device option. Additionally, if you have Windows Hello for Business configured on your computer you should select This Windows device.

After you have determined where you would like to save the passkey select the option of your choice and follow the on screen instructions which will very depending on what option you chose.

If you have selected the QR code, after you scan the QR code from your mobile device, you will see a pop-up on your device indicating what application you would like to save the passkey onto, if you do not see the Microsoft Authenticator app selected by default you may need to select Save another way and select the authenticator app from the list of options. see image below for reference.

Uploaded Image (Thumbnail)

 

this image is showing what application should be used to create a passkey on your mobile device

Step 3 – Passkey Creation Confirmation

Once the passkey has been created successfully, you should see the following prompt:

Uploaded Image (Thumbnail)

 

This image is confirming that the passkey was created successfully

Step 4 - Sign in with your passkey

After you click done you should be take to your Cobleskill email inbox. The next time you attempt to log into your Cobleskill account instead of typing in your cobleskill email address and password you can simply select sign-in options at the bottom of the sign in page.

Select Sign-in Options on the Login Page
Select Sign-in Options on the Login Page

In the next window you will select Face, Fingerprint, PIN or Security key.

Select face, fingerprint, PIN or security key option
Select face, fingerprint, PIN or security key option

Afterwards, you will select the location where you stored your passkey, similar to what you did in Step 3. Once you select the appropriate option follow the instructions on the screen and you should be able to login to your Cobleskill account.

Uploaded Image (Thumbnail)

 

This image is showing where the save passkey is stored to be used when logging in.

 

Related Articles

 

For more details on how to configure or use the new supported multi-factor authentication methods, please visit the link below

Microsoft article explaining the transition:

Need Help?

If you need assistance or require this information in an alternate format, contact the IT Service Desk:

Location
Warner 016
Phone
(518) 255-5800
TDX Portal
Submit a Service Request (opens in new tab)

This article has been adjusted for EIT standards – [mm/dd/yy | Your Name]

Details

Details

Article ID: 11733
Created
Fri 8/21/26 9:34 AM
Modified
Thu 8/27/26 10:49 AM