Microsoft is retiring text message and phone call verification codes for Microsoft 365 on 1 February 2027. If a text code or phone call is the only way you currently verify your sign-in, you will not be able to sign in after that date until you set up a different method. If you verify any other way, nothing changes for you.
We are flagging this well ahead of time so you can sort it at your own pace. It takes you a few minutes and there is no software cost involved.
This is one of only two emails we will send you about this change: this one, and one in September. Anything else that claims to be part of this programme is not from us.
What we suggest you do
Set up the Microsoft Authenticator app on your work account. If you already use Microsoft Authenticator to approve your sign-ins, you do not need to do anything. As a bonus, the app also fixes the old travel problem: sign-in codes that never arrive when you are overseas.
- Install Microsoft Authenticator from the official App Store (https://apps.apple.com/nz/app/microsoft-authenticator/id983156458) or Google Play (https://play.google.com/store/apps/details?id=com.azure.authenticator). Check you have the right app before you install: it is called Microsoft Authenticator, published by Microsoft Corporation, with the blue padlock-and-person icon shown below. Lookalike apps exist in both stores.
- Open the app, choose Add work or school account, then Sign in.
- Sign in with your Microsoft 365 work account.
- Follow the prompts to finish setting it up.

If you already use a different authenticator app for other services, we still suggest Microsoft Authenticator for your Microsoft 365 work account. It is the app we support, and it works with the newer sign-in methods Microsoft is introducing.
What you will see from 1 September
From 1 September 2026 Microsoft switches on its newer sign-in methods across Microsoft 365 and starts prompting people who still use text codes or phone calls, right at sign-in. You may be asked to set up a passkey, which lets you sign in with your fingerprint, face or device PIN instead of a code.
The prompt appears on screen while you are signing, as part of the sign-in itself. It is genuine and safe to accept, and you can also choose to skip it and carry on signing in as normal. You may see it even if you already use Microsoft Authenticator. Our second and final email, in September, will walk you through it and suggest a simple back-up sign-in method to go with it.
Watch out for copycats
Changes like this are a gift to scammers, because “Microsoft is retiring codes, click here” is an easy email to fake. Two simple checks:
- Genuine Microsoft prompts appear inside your sign-in, on the screen, while you are signing in. They do not arrive as an email demanding urgent action.
- If a call or email claims to be from Anvil or Microsoft and asks for codes, passwords or sign-in details, hang up and call us back on 09 579 5432 to check. We will never mind.
If this approach does not suit your situation some situations need a different answer, including:
- You share a login with colleagues, for example a reception, info or warehouse user account.
- You cannot, or prefer not to, use a personal phone for work sign-in.
- You do not have a smartphone.
There are workable options for all of these. Please contact us and we will help you plan the right one.
Thanks
Anvil Solutions Ltd – [email protected]

