Microsoft to Disable SMS as Primary Entra ID Sign-In Method in 2027
Microsoft will end SMS as a primary Entra ID sign-in method by February 1, 2027, shifting to phishing-resistant authentication methods like passkeys.
Microsoft will end SMS as a primary Entra ID sign-in method by February 1, 2027, shifting to phishing-resistant authentication methods like passkeys, Windows Hello, and FIDO2 security keys.
Full article551 words · extracted from gbhackers.com · click to collapse
Microsoft will turn off SMS as a primary sign-in method for Microsoft Entra ID workforce tenants on February 1, 2027, accelerating its transition to phishing-resistant authentication.
This change affects workers who currently use a registered phone number and a one-time SMS code as their initial sign-in credential, a passwordless flow utilized by frontline organizations.
Microsoft Disable SMS as Primary Entra ID
After the deadline, Entra will no longer accept a phone number and SMS code as a first-factor sign-in. Existing configurations that allow SMS sign-in will stop working, and Microsoft will remove sign-in management experiences. Azure AD B2C and Microsoft Entra External ID customer scenarios are not included in this announcement.
Microsoft characterizes this move as a security enhancement, citing that SMS codes can be compromised through phishing kits, social engineering, SIM swapping, and interception or redirection attacks.
As an alternative, Microsoft recommends passkeys, Windows Hello for Business, or FIDO2 security keys, which rely on public-key cryptography and link to a specific device or credential manager. This prevents users from inadvertently approving credentials on attacker-controlled lookalike sites.
The retirement of SMS as a primary sign-in method coincides with the broader discontinuation of Microsoft-provided SMS and voice delivery. Starting September 1, 2026, Entra will automatically enable passkeys for users currently using SMS or voice authentication and will prompt enrollment during authentication.
By February 1, 2027, Microsoft will end SMS and voice delivery for most users. However, Global Administrators and external users will have until July 1, 2027, to make the transition, while internal guest users will still be subject to the February deadline.
The migration to new authentication methods is advisory. Users who rely solely on Microsoft-provided SMS or voice for multifactor authentication will encounter a blocking prompt for passkey registration after the specified deadlines.
They must enroll in a passkey to continue accessing their accounts, and Microsoft has stated there is no option to opt out of this enforcement.
Administrators should identify every account using SMS sign-in, SMS multifactor authentication (MFA), or voice authentication. Microsoft provides a PowerShell-based discovery method to identify active SMS and voice users.
Security teams should group affected users, enable an approved phishing-resistant method, test passkeys, and communicate recovery procedures before the cutover.
Organizations with a regulatory, technical, or operational need for telecom authentication can continue using SMS or voice by contracting with a customer-managed provider through the Microsoft Security Store.
Microsoft indicates that customers can evaluate providers starting September 18, 2026, and configure them from October 30. While this option may incur additional costs and compliance requirements, it will prevent the blocking prompt if users migrate before the deadline.
For frontline deployments, the impact may be especially noticeable, as SMS first-factor sign-in was designed to let users access supported services without needing a username or password.
Microsoft now recommends organizations consider QR code authentication for shared-device frontline scenarios. With February 2027 approaching, tenant owners should treat this change as an identity migration project rather than a simple policy cleanup to avoid service disruptions and an increase in help desk requests.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.