Microsoft has issued a reminder to administrators regarding the upcoming retirement of SMS first-factor sign-in for Entra ID users, effective February 2027. This change necessitates that organizations transition their users to more secure, phishing-resistant authentication methods to prevent service disruptions.
Organizations are required to ensure all users adopt phishing-resistant authentication methods before the February 2027 deadline. After this date, SMS or voice will no longer be supported for multifactor authentication or account sign-ins. Recommended alternatives include passkeys, QR code authentication, and FIDO2 security keys.
The decision to retire SMS first-factor sign-in stems from its vulnerability to phishing, fraud, and account compromise risks. Microsoft previously retired SMS first-factor sign-in for Entra ID Free tenants in August and no longer enables it for newly created tenants. This retirement specifically applies to Microsoft Entra ID workforce tenant authentication scenarios.
In July, Microsoft announced that passkeys would become the default authentication experience for the Entra ID enterprise identity service, with rollout beginning this month. Users currently enabled for SMS or voice authentication will automatically be enabled for passkeys and prompted to register one during their next multifactor authentication attempt. Microsoft will cease providing telecom delivery for SMS and voice authentication as a native Entra ID capability on February 1, 2027.
Microsoft has provided detailed documentation for deploying and managing phishing-resistant passwordless authentication in Entra ID. Administrators with Global Reader, Authentication Policy Administrator, or Security Reader roles can identify users relying on SMS or voice authentication by utilizing the Entra SMS/Voice Policy Scanner PowerShell script. Organizations requiring phone-based authentication must configure third-party providers.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft has reminded administrators to migrate Entra ID users to phishing-resistant authentication methods, such as passkeys, as SMS first-factor sign-in will be retired starting February 2027. This change aims to enhance security by moving away from methods vulnerable to phishing, requiring organizations to adopt stronger authentication protocols for user access.