For most people, the second step of a secure login has long meant one thing: a six-digit code arriving by text message. It was easy to understand, worked on any phone, and required no setup beyond a number. That era is now visibly ending. Major platforms have begun announcing firm dates after which they will no longer send login codes over SMS or voice calls, moving users instead to stronger methods such as authenticator apps and passkeys. For a business whose staff all sign in with texted codes, this is not a distant industry debate - it is a scheduled change with a deadline, and the businesses that treat it as such will have a calm migration while the rest get a forced one.
The reason the texted code is being retired is that it was always the weakest of the second factors, and attackers have industrialised the ways around it. Phone numbers can be hijacked by convincing a carrier to move them to a new SIM, at which point the codes arrive in the attacker's pocket instead of yours. Codes can be phished in real time: a fake login page asks for the code just as the real site sends it, and the victim types it straight to the thief. The code travels over networks that were never designed to carry secrets. None of this means SMS codes were useless - they stopped a great deal of casual account takeover - but the protection they offer has eroded while stronger alternatives have matured, and the platforms have concluded the trade is no longer worth defaulting to.
What replaces the text message is, in practice, one of two things. An authenticator app generates codes on the device itself, so there is nothing travelling over the phone network to intercept and no number to hijack. A passkey goes further, replacing the code ritual entirely with a cryptographic sign-in tied to the device and unlocked the way the phone is - by fingerprint, face or PIN - which also cannot be phished, because there is no code to type into a fake page. Both are free, both are supported almost everywhere that matters, and both are genuinely easier to live with than waiting for a text in a dead-signal meeting room. The friction is entirely in the switching, not in the using.
The sensible move for a business is to migrate on its own schedule rather than the platform's. That means taking an inventory of which critical accounts - email, banking, cloud services, anything that can reset other passwords - still rely on texted codes, and moving them to an authenticator app or passkeys deliberately, starting with the accounts that matter most. It means doing this while the old method still works, so that any hiccup in enrolment happens with a fallback available rather than after the switch-off. And it means bringing staff along with a simple explanation and a few minutes of setup help, because the person who ignores every migration email until their code stops arriving is the person who will need emergency support on the worst possible morning. The texted code served its time. The businesses that retire it themselves, ahead of the deadline, will barely notice the transition - which is exactly the way a security upgrade should feel.