Microsoft to Retire SMS First-Factor Sign-In for Entra ID on February 1, 2027
Microsoft will stop honoring SMS as a first-factor sign-in method for Entra ID workforce tenants on February 1, 2027, urging admins to migrate users to phishing-resistant alternatives such as passkeys, Windows Hello for Business, and FIDO2 security keys.
Microsoft is reminding administrators to migrate Entra ID users off SMS-based first-factor sign-in (internally called SignInNoPassword) before the feature is retired on February 1, 2027. The change applies to worldwide and US Government Community Cloud workforce tenants, but not to Azure AD B2C or Microsoft Entra External ID. Microsoft cites phishing, SIM swapping, and message interception as the reasons for the retirement. Accounts that rely solely on a registered phone number plus a six-digit SMS code will fail after enforcement, cutting off access to Microsoft 365 and other Entra-protected services. SMS sign-in was already retired for Free tenants in August amid account-compromise risks, and passkeys are now the default authentication experience for new Entra ID users. Microsoft recommends migrating to passkeys, Windows Hello for Business, FIDO2 security keys, or administered QR-code-and-PIN authentication; SMS delivered via third-party telephony may still be used for multifactor (second-factor) verification, just not as the primary factor. Reports agree on the February 2027 timeframe; the most specific date given is February 1, 2027.
- SMS first-factor sign-in for Entra ID will be blocked on February 1, 2027.
- The internal Microsoft name for the feature being retired is SignInNoPassword.
- The retirement applies to worldwide and US Government Community Cloud workforce tenants, but not Azure AD B2C or Microsoft Entra External ID.
- Microsoft cites phishing, SIM swapping, and SMS interception as the security rationale.
- Accounts relying only on a phone number plus a six-digit SMS code will lose access to Microsoft 365 and other Entra-protected services after enforcement.
- SMS sign-in was already retired for Free tenants in August.
- Passkeys are now the default authentication experience for new Entra ID users.
- Recommended alternatives: passkeys, Windows Hello for Business, FIDO2 security keys, or administered QR-code-and-PIN authentication.
Coverage timelineoldest first · each row is one article
- · 5d agoMicrosoft reminds admins to migrate Entra ID users to passkeys
BleepingComputer· 35
Microsoft reminds admins to migrate Entra ID users to passkeys before SMS first-factor sign-in is retired in February 2027.
- · 5d agoMicrosoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027
Cyber Security News· 46
Microsoft will block SMS first-factor sign-in for Entra ID workforce tenants worldwide on February 1, 2027.
- · 5d ago