← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Microsoft urges Entra ID admins to migrate users to passkeys before SMS sign-in retirement

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • SMS first-factor sign-in for Entra ID will be retired starting February 2027.
  • Admins must migrate users to phishing-resistant methods like passkeys or FIDO2 keys.
  • SMS sign-in was retired for Entra ID Free tenants in August due to security risks.
  • Passkeys are becoming the default authentication experience for Entra ID enterprise identity service.

Upcoming Retirement of SMS First-Factor Sign-in

Microsoft has issued a reminder to administrators regarding the upcoming retirement of SMS first-factor sign-in for Entra ID users, effective February 2027. This change necessitates that organizations transition their users to more secure, phishing-resistant authentication methods to prevent service disruptions.

Mandatory Migration to Phishing-Resistant Methods

Organizations are required to ensure all users adopt phishing-resistant authentication methods before the February 2027 deadline. After this date, SMS or voice will no longer be supported for multifactor authentication or account sign-ins. Recommended alternatives include passkeys, QR code authentication, and FIDO2 security keys.

Security Rationale and Previous Actions

The decision to retire SMS first-factor sign-in stems from its vulnerability to phishing, fraud, and account compromise risks. Microsoft previously retired SMS first-factor sign-in for Entra ID Free tenants in August and no longer enables it for newly created tenants. This retirement specifically applies to Microsoft Entra ID workforce tenant authentication scenarios.

Passkeys as the New Default

In July, Microsoft announced that passkeys would become the default authentication experience for the Entra ID enterprise identity service, with rollout beginning this month. Users currently enabled for SMS or voice authentication will automatically be enabled for passkeys and prompted to register one during their next multifactor authentication attempt. Microsoft will cease providing telecom delivery for SMS and voice authentication as a native Entra ID capability on February 1, 2027.

Admin Guidance and Tools

Microsoft has provided detailed documentation for deploying and managing phishing-resistant passwordless authentication in Entra ID. Administrators with Global Reader, Authentication Policy Administrator, or Security Reader roles can identify users relying on SMS or voice authentication by utilizing the Entra SMS/Voice Policy Scanner PowerShell script. Organizations requiring phone-based authentication must configure third-party providers.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Microsoft has reminded administrators to migrate Entra ID users to phishing-resistant authentication methods, such as passkeys, as SMS first-factor sign-in will be retired starting February 2027. This change aims to enhance security by moving away from methods vulnerable to phishing, requiring organizations to adopt stronger authentication protocols for user access.