SMS MFA Is Going Away: A Household Migration Plan
Do not panic-remove SMS everywhere in one weekend. Add stronger methods first, prove recovery works, then demote SMS. Move email, password manager, carrier, banking, cloud, health, and social accounts toward passkeys, security keys, or authenticator apps with backup codes and second-device recovery.
Operating principle: Enroll and test a stronger sign-in method plus an independent recovery path before removing SMS. The headline is directional, not universal: SMS MFA remains available at many services, but NIST classifies use of the public telephone network as restricted and Microsoft is phasing out SMS codes for personal-account sign-in.
The Short Version
- SMS is not gone everywhere, but security guidance and major vendors are clearly moving away from it.
- Authenticator apps are better than SMS; passkeys and hardware security keys are stronger for phishing resistance.
- Recovery must be proven before removing the phone number from critical accounts.
The Reader Question
What should I replace text-message login codes with?
This plan is for the person who handles account recovery for a household, including relatives who may share devices or need accessibility support. It assumes every account owner consents to the changes and can still sign in. If an account is already compromised, use the provider's recovery process first; do not add authenticators to a session or device an attacker may control.
Before You Start: Safe Defaults
- Start with the email account and password manager because they recover everything else.
- Use two security keys or two passkey-capable devices for critical accounts.
- Enable carrier account PINs, port locks, or SIM-swap protections where available.
- Store backup codes somewhere other than the phone that might be lost.
Reference Model
The model separates enrollment from removal. Inventory dependencies first, add a suitable method, prove both routine sign-in and recovery from a clean device, and only then demote SMS. That order avoids turning a security upgrade into a lockout.
Decision Matrix
| Choice | Best Fit | Recovery Requirement | Important Limit |
|---|---|---|---|
| SMS or voice code | Temporary fallback when the service offers nothing else | Current carrier PIN, port-out controls, and verified number | Phishable and dependent on carrier and phone-number control. |
| TOTP authenticator app | Broad compatibility and offline code generation | Documented export or encrypted backup, recovery codes, or a second enrolled device | Codes can still be phished; cloud sync changes the trust and recovery model. |
| Synced passkey | Low-friction, phishing-resistant sign-in across a supported device ecosystem | Recovery for the platform account and access to another trusted device | Availability, sharing, and cross-platform recovery differ by provider. |
| Device-bound passkey or security key | Email, password manager, finance, admin, and other high-impact accounts | At least two enrolled authenticators stored separately, plus provider recovery | A single key is a single point of lockout; account recovery can remain the weaker path. |
Build the Account and Recovery Map
Do not treat this as a list of websites. Record the dependency graph: which email resets the account, which platform account syncs its passkeys, which phone receives carrier alerts, and which adult is authorized to recover a child's or dependent adult's account. Record only what the household needs to operate the plan. Never put passwords, recovery-code values, identity-document numbers, or passkey secrets in the migration board.
For each account, capture owner, impact if lost, current methods, target method, recovery email/phone, enrolled-device count, backup-code storage location, and last test date. Rank email, password managers, mobile-carrier accounts, platform accounts, financial services, domain registrars, health portals, and tax services above low-impact shopping or entertainment accounts.
Migration Order
Move accounts in an order that protects recovery first: email, password manager, carrier, banking, cloud storage, device accounts, health, taxes, domains, shopping, and social. A social account is annoying to lose; the email account can reset or recover almost everything.
Carrier Lockdown
SMS risk is tied to phone-number control. Set a carrier PIN, enable port-out or SIM-change protections where available, review account email, and remove old authorized users. Carrier controls do not make SMS ideal, but they reduce one common failure path.
Ask the carrier what its controls actually cover: account login, number transfer, SIM replacement, eSIM activation, and in-store support may use different verification. A carrier lock cannot stop a phished SMS code, malware on the phone, or a provider's weak recovery desk. Treat it as defense in depth while accounts still depend on the number.
Household Board
Use a simple table with account, current MFA, target MFA, backup code stored, second device enrolled, SMS removed, and review date. This makes migration visible instead of trusting memory.
Pilot One Low-Risk Account
Choose an account that supports the target method but will not disrupt finances, medical access, work, or the primary email if recovery fails. Add the passkey, key, or authenticator app while SMS remains available. Sign out, then test normal login from a clean browser. Next test the documented lost-phone path without deleting a working credential: use the spare key or second device, locate but do not consume a recovery code, and confirm the provider's recovery contact data.
The pilot passes only when the account owner can complete both login and recovery without coaching and the backup is not stored with the daily device. If a passkey opens through an unexpected platform account, a TOTP app has no usable export or second-device path, or the provider silently falls back to SMS, stop and revise the household standard before expanding.
Implementation Details
Schedule changes when the account owner, a trusted device, and the existing recovery method are available. Read the provider's recovery documentation before touching a critical account. Shared accounts need an explicit owner and an approved sharing feature; do not solve access by sharing one person's device unlock code or exporting secrets through chat.
- Create the account and recovery map without recording secrets.
- Secure the carrier and the platform account that will sync passkeys.
- Pilot the chosen method on a low-impact account.
- Upgrade primary email and the password manager, enrolling two independent authenticators where supported.
- Save fresh recovery codes in an encrypted vault or sealed offline packet outside the lost-phone scenario.
- Test routine sign-in and the documented recovery route from a clean browser or spare device.
- Change financial, cloud, health, tax, domain, shopping, and social accounts in descending impact order.
- Remove SMS only when the replacement and recovery path pass; otherwise retain it temporarily with a dated migration note.
Evidence and Testing Method
- Documentation-backed: NIST SP 800-63B-4's July 2025 final guidance treats PSTN out-of-band authentication as restricted, not universally prohibited, and requires phishing-resistant options at higher assurance levels.
- Vendor-specific: Microsoft says personal accounts are moving away from SMS login codes. That does not establish an industry-wide shutdown date.
- Household test to perform: record the account, method, clean-browser sign-in result, recovery route, date, and account owner's confirmation. Store no code or secret in the result.
- Recovery evidence: two enrolled authenticators or one authenticator plus current recovery codes, stored so loss of one phone does not remove both.
- Editorial limit: TechGeeks did not enroll or recover readers' accounts and did not independently lab-test every provider's passkey, TOTP, or SMS behavior. Provider UI and recovery rules can change without notice.
Validation Checklist
- Critical accounts have at least two recovery paths that do not depend on one phone.
- Backup codes are stored outside email and outside the lost-phone scenario.
- Carrier account has PIN or port-out protections where available.
- SMS is removed or demoted on accounts that support stronger methods.
- A family member can follow the recovery note if a phone is lost.
Maintenance Cadence
- After each migration: confirm the provider lists the intended methods and has removed stale phones, devices, app passwords, and sessions.
- Monthly during the project: move the next impact tier and chase any account still marked SMS-only.
- Every six months: review recovery contacts, spare-key location, platform-account access, carrier protections, and whether recovery codes need replacement.
- After a lost phone, number change, death, separation, or provider policy notice: re-evaluate ownership and recovery immediately, with the account owner's consent.
Troubleshooting
| Symptom | Likely Cause | First Check |
|---|---|---|
| Cannot remove SMS | Service requires phone fallback | Add stronger methods and carrier protections, then review periodically. |
| Authenticator lost | No backup or second device | Use backup codes or account recovery, then enroll redundant methods. |
| Security key lost | Only one key enrolled | Use backup key or recovery codes; enroll a replacement immediately. |
Common Mistakes
- Removing SMS before enrolling a replacement.
- Using one authenticator app with no backup or export path.
- Buying one security key and storing it on the same keyring as the daily key.
- Forgetting the carrier account itself.
- Leaving old phone numbers as recovery methods.
Useful Gear And Buyer Notes
Choose authentication gear after mapping the household's devices and account support. Confirm the connector and wireless interface, FIDO protocol support, platform compatibility, accessibility needs, spare-key enrollment rules, and a return path; a four-pack is not useful if a critical provider accepts a different authenticator type.
Affiliate disclosure: As an Amazon Associate, TechGeeks may earn from qualifying purchases. The product links below are buying references, not a requirement to buy a specific brand or seller. Verify compatibility, seller quality, warranty, and current specs before ordering.
- Amazon search: YubiKey security key 4 pack
- Amazon search: password manager family plan
- Amazon search: fireproof document safe
- Amazon search: encrypted USB drive
- Amazon search: label maker
Related TechGeeks Reading
- How Do You Recover From Losing TOTP, Passkeys, or Password Vault Access?
- Passkeys Still Need a Backup Plan
- Network Security Field Notes: Start Here
What This Does Not Protect or Validate
NIST's restriction does not prove SMS is already unavailable, forbidden for every consumer, or worse than having no second factor. Microsoft's personal-account change does not prove another provider will follow the same schedule. Phishing-resistant authentication reduces credential-phishing risk, but it does not prove the endpoint is clean, the recovery desk is strong, or the account cannot be taken over through an active session or delegated access.
A successful sign-in test does not prove recovery works after every device is lost. A visible spare key does not prove it is enrolled to the current account. Test within the provider's supported workflow, and do not deliberately lock out a critical account merely to produce evidence.
Current Context and Publication-Day Checks
This article was fact-checked July 15, 2026 against NIST SP 800-63B-4 and current Microsoft, FTC, CISA, and FIDO guidance. Before publication, recheck Microsoft's rollout language, each named provider's supported methods, the NIST authenticator classification, FTC carrier-protection guidance, and every reference URL. Avoid promising that a specific passkey sync, export, family-sharing, or recovery feature exists without checking the exact platform and account type that day.
Practical FAQ
Are authenticator apps enough?
They are usually better than SMS, but passkeys and security keys are stronger against phishing when supported.
Should I remove SMS everywhere?
Only after stronger methods and recovery are proven. Some accounts still require a phone number.
What about elderly family members?
Use the simplest stronger option they can reliably use, then document recovery and keep backup codes accessible but secure.
References
- NIST SP 800-63B-4: Authentication and Authenticator Management
- Microsoft: Moving Personal Accounts Away from SMS Codes
- FTC: Use Two-Factor Authentication to Protect Your Accounts
- FTC: SIM Swap Scams
- CISA: More Than a Password
- CISA: Mobile Communications Best Practice Guidance
- FIDO Alliance: Passkeys
- EFF: Passkeys and Privacy
Final Thought
The goal is not to delete SMS fastest. The goal is to make account recovery stronger before the phone number stops being reliable.

