Skip to content
Tech News
← Back to articles

Microsoft reminds admins to migrate Entra ID users to passkeys

read original get Yubico YubiKey 5 NFC → more articles
Why This Matters

Microsoft is pushing enterprise IT admins to move Entra ID users off SMS-based authentication before it's fully retired as a first-factor sign-in method in February 2027. This matters because SMS and voice authentication are vulnerable to phishing and interception, and the shift signals a broader industry move toward passwordless, phishing-resistant security like passkeys and FIDO2 keys. Organizations that delay migration risk sign-in disruptions and weaker account security.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC — Enhance your organization's security with the Yubico YubiKey 5 NFC, a FIDO2 security key that provides phishing-resistant two-factor authentication. As Microsoft encourages migration to passkeys and other phishing-resistant methods, this hardware token offers a reliable and easy-to-use solution to protect user accounts and ensure seamless sign-in experiences.

See Yubico YubiKey 5 NFC on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Microsoft has reminded administrators to migrate Entra ID users to phishing-resistant methods, such as passkeys, to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.

Admins also have alternatives, including QR code authentication, FIDO2 security keys, and other Entra ID-supported authentication methods.

Before this date, organizations should ensure all users use a phishing-resistant method because they will no longer be able to use SMS or voice to complete multifactor authentication and sign in to their accounts.

"The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method," Microsoft said in a Microsoft 365 Message Center update on Friday.

"If your organization currently uses SMS sign-in for first-factor authentication, migrate users to supported alternatives based on their scenarios."

Microsoft retired SMS first-factor sign-in for Microsoft Entra ID Free tenants in August due to phishing, fraud, and account compromise risks and no longer enables SMS sign-in for newly created tenants.

The retirement process applies only to Microsoft Entra ID workforce tenant authentication scenarios and not to Azure AD B2C or Microsoft Entra External ID customer identity scenarios.

Microsoft has shared detailed guidance on deploying and managing phishing-resistant passwordless authentication in Entra ID on this dedicated documentation page.

Passkeys now default Entra ID authentication method

In July, Microsoft also announced that passkeys will start rolling out as the default authentication experience for the Entra ID enterprise identity service starting this month.

... continue reading