Microsoft Again Urges Entra ID Users to Move From SMS to Passkeys


entra id passkeys
Image credit: Microsoft

Microsoft is again warning Entra ID administrators to move users away from SMS and voice authentication before the company retires the methods in February 2027.

Microsoft previously confirmed that SMS and voice MFA will be retired in February 2027 and later issued another warning about the February 2027 deadline.

Now, Microsoft has repeated the warning through Microsoft 365 Message Center advisory MC1474104.

The company recommends moving affected users to phishing-resistant authentication methods such as passkeys, FIDO2 security keys, QR code authentication, and other supported Entra ID options.

Organizations that fail to migrate users could see sign-in disruptions once Microsoft removes its native SMS and voice authentication capabilities.

SMS first-factor authentication is also going away

The retirement includes SMS sign-in when organizations use it as a first-factor authentication method, including deployments that rely on Choose Your Own Telephony Provider.

Microsoft already removed SMS first-factor sign-in for Microsoft Entra ID Free tenants in August 2026.

At the same time, Microsoft is making passkeys a bigger part of Entra ID authentication. The company began rolling out passkeys as the default authentication experience for enterprise users in September 2026.

Users currently enabled for SMS or voice authentication will automatically gain passkey support as the rollout reaches their organization. Microsoft says affected users will then receive a prompt to register a passkey the next time they complete multifactor authentication.

Admins can scan for affected users

Administrators with Global Reader, Authentication Policy Administrator, or Security Reader roles can use Microsoft’s Entra SMS/Voice Policy Scanner PowerShell script to find users who still rely on the retiring methods.

Organizations that still require phone-based authentication can also configure third-party telecom providers through the Microsoft Security Store.

The retirement only affects Microsoft Entra ID workforce authentication scenarios. It does not apply to Azure AD B2C or Microsoft Entra External ID customer identity scenarios.

Microsoft continues to promote passkeys as a more phishing-resistant replacement, although experts have warned about the Entra passkey rollout through social engineering.

Via BleepingComputer

More about the topics: microsoft, microsoft entra, passkeys

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages