The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Sourcing
1source

via Pure Xbox

Pure Xbox · track record
8Stories
100%Verified
030d
All sources →
Markets
MSFT···

Live quote · not investment advice

From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/Microsoft Phases Out SMS Authentication for All Accounts
VERIFIEDBy Xavier Rivera· ·2 min read

Microsoft Phases Out SMS Authentication for All Accounts

Microsoft is phasing out SMS authentication and account recovery for all personal Microsoft accounts, including those used with Xbox, citing it as a leading source of fraud. The change promotes more secure passwordless options like passkeys to counter phishing and SIM-swap attacks while simplifying access.

Source:Pure Xbox
Post
Microsoft Phases Out SMS Authentication for All Accounts
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

Microsoft phases out SMS authentication and account recovery for personal Microsoft accounts, which affects Xbox users too. The company makes this change because SMS is now a leading source of fraud from phishing and SIM-swap attacks. Passkeys take over and allow sign-in with biometrics including Face ID, fingerprints and PINs.

Microsoft is officially phasing out SMS authentication and account recovery as an option from everyone's personal Microsoft account. The change directly affects Xbox accounts as well. The company states that SMS-based authentication is now a leading source of fraud.

Instead of receiving texts with a six-digit code to prove identity during sign-in, Microsoft is directing users toward other methods such as passkeys. These allow sign-in using Face ID, fingerprints and PIN numbers. Many people already rely on the Microsoft Authenticator app for their Xbox accounts, and the company indicates this will continue to function as normal.
Microsoft believes that the future of authentication is passwordless, secure, and user-friendly.

"Microsoft is committed to advancing security standards and as such, we will start phasing out SMS as a method of authentication and account recovery for personal Microsoft accounts," the company said. "Microsoft believes that the future of authentication is passwordless, secure, and user-friendly. SMS-based authentication is now a leading source of fraud, and by moving to passwordless accounts, passkeys, and verified email, we're helping you stay ahead of evolving threats while making account access simpler and more seamless."

SMS authentication is vulnerable to phishing and SIM-swap attacks. Microsoft is replacing it with passkeys and verified email for better protection and convenience. Passkeys provide a modern, phishing-resistant way to sign in using a device's built-in authentication such as Face ID, fingerprint or PIN. They are described as faster and more secure than passwords or SMS codes.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

Recent updates to Microsoft account sign-in now support passkeys with device biometric authentication, making phishing virtually impossible. The official Microsoft Support website offers details on protecting a Microsoft account. Users are advised to check the Security section of their Microsoft account dashboard to review current settings.
SMS-based authentication is now a leading source of fraud, and by moving to passwordless accounts, passkeys, and verified email, we're helping you stay ahead of evolving threats while making account access simpler and more seamless.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Xbox owners have occasionally lost access to digital game libraries after accounts were hacked. The company recommends reading the "How to help keep your Microsoft account secure" page on its website to improve settings and avoid potential fraud. The shift underscores Microsoft's commitment to passwordless authentication across personal accounts.

EXPERT TAKE

Expert Take: Cloud admins should audit Microsoft account security settings now to migrate users to passkeys and Authenticator before SMS options disappear entirely.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
MicrosoftXboxSecurityAuthentication
More fromPure Xbox
  • Third-Party Titles Headed to Xbox from September State of Play

    Gaming · 1mo
  • Xbox Network Down Worldwide, Microsoft Working on Fix

    Gaming · 3mo
  • Asha Sharma Hands Out Free Xbox Consoles at FanFest LA

    Gaming · 4mo
More inTech
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 10h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 13h
  • Anthropic Launches Cyber Mission to Secure Infrastructure and Open-Source Code

    Tech · 16h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.

  • Tech· 

    Critical CVE-2026-16823 hits IBM Security Verify Access

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 contain critical authentication bypass flaw CVE-2026-16823. The NVD rates it 9.1 and warns of remote exploitation without credentials.

  • Tech· 

    IBM patches nine Guardium Data Protection flaws

    IBM has released patches addressing nine vulnerabilities in Guardium Data Protection across versions 12.0 through 12.2.2. Two of the flaws are rated critical and could allow remote attackers to seize control of edge clusters or execute scripts in user browsers.