Microsoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027
Microsoft will block SMS first-factor sign-in for Entra ID workforce tenants worldwide on February 1, 2027.
Microsoft will stop honoring SMS first-factor sign-in, internally called SignInNoPassword, for Microsoft Entra ID workforce tenants on February 1, 2027. Users who authenticate only with a registered phone number and a six-digit SMS code will lose access to Microsoft 365 and other Entra-protected services. The retirement covers worldwide and US Government Community Cloud tenants but not Azure AD B2C or Microsoft Entra External ID. Microsoft cites phishing, SIM swapping, and interception, and recommends passkeys, Windows Hello for Business, FIDO2 keys, or administered QR-code-and-PIN authentication.