Microsoft has reminded administrators to migrate Entra ID users to phishing-resistant methods, such as passkeys, to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.
Admins also have alternatives, including QR code authentication, FIDO2 security keys, and other Entra ID-supported authentication methods.
Before this date, organizations should ensure all users use a phishing-resistant method because they will no longer be able to use SMS or voice to complete multifactor authentication and sign in to their accounts.
“The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method,” Microsoft said in a Microsoft 365 Message Center update on Friday.
“If your organization currently uses SMS sign-in for first-factor authentication, migrate users to supported alternatives based on their scenarios.”
Microsoft retired SMS first-factor sign-in for Microsoft Entra ID Free tenants in August due to phishing, fraud, and account compromise risks and no longer enables SMS sign-in for newly created tenants.
The retirement process applies only to Microsoft Entra ID workforce tenant authentication scenarios and not to Azure AD B2C or Microsoft Entra External ID customer identity scenarios.
Microsoft has shared detailed guidance on deploying and managing phishing-resistant passwordless authentication in Entra ID on this dedicated documentation page.
In July, Microsoft also announced that passkeys will start rolling out as the default authentication experience for the Entra ID enterprise identity service starting this month.
“As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they’ll be prompted to register a passkey,” Microsoft said.
“Following this transition, on February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability”
Admins with Global Reader, Authentication Policy Administrator, or Security Reader roles can find SMS or voice auth users by running the Entra SMS/Voice Policy Scanner PowerShell script.
Organizations that must use phone-based authentication have to configure third-party telecom providers through the Microsoft Security Store.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Microsoft patches max severity code execution, privilege escalation flaws
Microsoft: September updates break File History backup feature
Microsoft fixes broken copy and paste for Excel 2016 users
Microsoft Teams will let admins block custom file extensions
Microsoft Teams to get efficiency mode on PCs with limited resources
Gyazo server flaw exploited to steal 23.6 million user records
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
Patch automation needs more than speed. Action1 brings control into every stage of deployment.
Watch a working exploit hit live controls and see exactly what blocks, detects, or misses
Overdue a password health-check? Audit your Active Directory for free
Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.
Automate Onboarding and Access Reviews with No-Code IGA: See how it works
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



