Microsoft Warns Entra Customers About February 2027 SMS Authentication Retirement
Microsoft Entra SMS and voice authentication will be retired on February 1, 2027, as Microsoft begins moving customers toward passkeys and other phishing-resistant sign-in methods.
Microsoft has started emailing affected Entra ID organizations about the upcoming change, according to Neowin. The company had previously announced that Entra ID SMS and voice MFA would be retired, but it is now contacting customers directly as the migration deadline approaches.
Microsoft will start the transition in September
The migration process begins on September 1, 2026. Entra ID will automatically enable passkey support for users who currently depend on SMS or voice authentication.
Affected users will also start seeing sign-in prompts encouraging them to register a passkey. Microsoft has increasingly been pushing customers toward passkeys as password and authentication attacks become more sophisticated.
Users who still have not configured a passkey or another supported phishing-resistant method by February 1, 2027 will face a mandatory registration block during sign-in. They will need to configure an accepted authentication method before accessing their accounts.
Microsoft says SMS authentication carries security risks
Microsoft says attackers can increasingly compromise SMS authentication through methods including SIM-swapping and Adversary-in-the-Middle phishing.
Passkeys avoid temporary authentication codes and passwords that attackers can intercept or steal.
Organizations that must continue using phone authentication for regulatory or compliance reasons will have another option. Microsoft will allow them to use customer-managed telecom providers available through the Microsoft Security Store.
Provider pricing will become available on September 18, 2026, while organizations can begin configuring supported providers from October 30.
Administrators should identify affected users now
IT administrators should review their Authentication Methods Policy and identify accounts that still depend on SMS or voice authentication before the September migration begins.
Microsoft recommends moving those users to passkeys proactively. Organizations can configure passkeys through Microsoft Authenticator or compatible hardware security keys.
The change is not limited to enterprise customers. Microsoft is also phasing out SMS authentication for personal Microsoft accounts.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages