In brief: Sending codes to users via SMS has long been discredited as the least secure multi-factor authentication method, and Microsoft will soon discontinue support for this practice altogether.