Microsoft to Retire SMS and Voice Sign-In in Entra ID by February 2027
Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID beginning in February 2027. The company is urging administrators to migrate users to phishing-resistant authentication methods, including passkeys, to avoid sign-in disruptions.
Organizations can also use QR code authentication, FIDO2 security keys, and other authentication methods supported by Microsoft Entra ID.
By February 1, 2027, organizations must ensure that users are enrolled in supported authentication methods. Users will no longer be able to use Microsoft-provided SMS or voice services for authentication and sign-in.
“The retirement of SMS sign-in as a single-factor authentication method also applies if you continue to use SMS or voice as a multi-factor authentication method using your own telephony provider selection,” Microsoft said in its Microsoft 365 Message Center update.
“If your organization currently uses SMS sign-in for first-factor authentication, migrate your users to a supported alternative based on your scenario.”
Microsoft is phasing out SMS authentication because of security risks
Microsoft also said that SMS first-factor sign-in for Microsoft Entra ID Free tenants will be retired in August because of the risk of phishing, fraud, and account compromise. Newly created tenants will not have SMS sign-in enabled.
The retirement applies only to Microsoft Entra ID employee tenant authentication scenarios. It does not apply to Azure AD B2C or Microsoft Entra External ID customer identity scenarios.
Microsoft has published detailed guidance for deploying and managing phishing-resistant passwordless authentication with Entra ID.
Passkeys become the default Entra ID authentication method
In July, Microsoft announced that it would begin rolling out passkeys as the default authentication experience for its Entra ID enterprise identity service starting this month.
“Once this rollout reaches organizations, users who have SMS or voice authentication enabled will also automatically have a passkey enabled and will be required to register for a passkey the next time they perform multi-factor authentication,” Microsoft said.
“Following this transition, on February 1, 2027, Microsoft will retire Microsoft-provided communications delivery for SMS and voice authentication and will no longer offer SMS and voice as native Microsoft Entra functionality.”
How administrators can find users relying on SMS or voice authentication
Administrators with the Global Reader, Authentication Policy Administrator, or Security Reader roles can use the Entra SMS/Voice Policy Scanner PowerShell script to identify users who rely on SMS or voice authentication.
Organizations that still need phone-based authentication must configure a third-party communications provider through the Microsoft Security Store.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



