Microsoft has reminded administrators to migrate Entra ID users to phishing-resistant methods, such as passkeys, to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.
Admins also have alternatives, including QR code authentication, FIDO2 security keys, and other Entra ID-supported authentication methods.
Before this date, organizations should ensure all users use a phishing-resistant method because they will no longer be able to use SMS or voice to complete multifactor authentication and sign in to their accounts.
"The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method," Microsoft said in a Microsoft 365 Message Center update on Friday.
"If your organization currently uses SMS sign-in for first-factor authentication, migrate users to supported alternatives based on their scenarios."
Microsoft retired SMS first-factor sign-in for Microsoft Entra ID Free tenants in August due to phishing, fraud, and account compromise risks and no longer enables SMS sign-in for newly created tenants.
The retirement process applies only to Microsoft Entra ID workforce tenant authentication scenarios and not to Azure AD B2C or Microsoft Entra External ID customer identity scenarios.
Microsoft has shared detailed guidance on deploying and managing phishing-resistant passwordless authentication in Entra ID on this dedicated documentation page.
Passkeys now default Entra ID authentication method
In July, Microsoft also announced that passkeys will start rolling out as the default authentication experience for the Entra ID enterprise identity service starting this month.
... continue reading