Microsoft is reminding administrators to move Microsoft Entra ID users to phishing-resistant authentication methods, including passkeys, before it retires SMS first-factor sign-in starting in February 2027.
Supported alternatives include QR code authentication, FIDO2 security keys, and other Microsoft Entra ID authentication methods.
Organizations should ensure users have a phishing-resistant method before then. Users will no longer be able to use SMS or voice to complete multifactor authentication and sign in to their accounts. The change applies to Microsoft Entra ID workforce tenant authentication, not Azure AD B2C or Microsoft Entra External ID customer identity scenarios.
Microsoft retired SMS first-factor sign-in for Microsoft Entra ID Free tenants in August because of phishing, fraud, and account-compromise risks. It also no longer enables SMS sign-in for newly created tenants. In July, Microsoft announced that passkeys would begin rolling out as the default authentication experience for the Entra ID enterprise identity service this month.
On February 1, 2027, Microsoft will retire its telecom delivery for SMS and voice authentication and will no longer offer them as a native Microsoft Entra capability. Organizations that must use phone-based authentication have to configure third-party telecom providers through the Microsoft Security Store.
Administrators with Global Reader, Authentication Policy Administrator, or Security Reader roles can identify SMS or voice authentication users with the Entra SMS/Voice Policy Scanner PowerShell script.
Comments
0No comments yet. Be the first to comment.