According to Windows Latest, Microsoft, citing the lack of security of text messages, is planning to abandon the dual SMS-based identification in local accounts and to fully implement the “no password login” programme.

According to the Microsoft Official Bulletin, the SMS-based one-off authentication code has now become one of the main sources of cyber fraud and account hijacking. As text messages are born in the early communications environment, their messages are transmitted in explicit form within a fragile cellular network and are highly vulnerable to interception; and the growing SIM card exchange attacks make it easier for hackers to seduce operators and steal authentication codes. Microsoft has therefore decided to undertake a thorough security upgrade of identification.
Microsoft states: “Microsoft is committed to raising safety standards, so we will phase out SMS as a means of identifying and restoring personal Microsoft accounts. SMS-based authentication has now become the main source of fraud, and by moving to uncoded accounts, communication keys and certified e-mails, we will help users to cope with evolving security threats while making account access easier.”

Password keys are a more concise and secure means of identification, which uses local security mechanisms for assistive devices or biometric information from users to identify. When setting the key, the user can use facial, fingerprint or local password/PIN code. Such information would always be kept on specific equipment and could hardly be forged by third parties.
In the future, Microsoft personal account log-in and account recovery processes will be forced to shift to safer and more rapid fish-resistant validations, as follows:
Key:Based on FIDO2 international standards, identification is done directly using Windows Hello (Face Recognition, Fingerprint Scanning) or local equipment PIN code, which is embedded in your equipment.

Encrypted private keys are strictly stored in physical hardware such as a computer’s TPM security chip, and will never be transmitted on the Internet. They can fundamentally disrupt long-distance fishing and false website attacks; the pass key supports cross-equipment encryption synchronization through the Apple iCloud key string or Google password manager.
Microsoft certifier application:Receives secure push notifications, clicks to confirm or perform digital matching login through the phone host App.
Authenticated backup e-mail:As an alternative means of recovery in an age of no password. If the mobile phone is inadvertently lost, the user can still retrieve the account through a synchronized pass key and a back-up mailbox.
However, while the key is more secure, its use in practice is not always as easy. When setting up a new Windows computer or a temporary virtual machine, biometric data may not be easily available and the design key may be cumbersome each time. By contrast, SMS codes are faster and easier. Of course, such convenience comes at the expense of security. Fortunately, a validated e-mail link remains a viable option under the same circumstances.

Microsoft has started sending updates to individual users worldwide, forcing users to configure keys and backup mailboxes. Enterprise users are required to complete their migration to either Autocentor or FIDO2 by 30 September 2026, and the old text message validation will be discontinued on 1 October. In very few virtual machines or specific technology development environments where biometrics cannot be used, SMS validation may be retained as a cover-up.
