VYPR
patchPublished Sep 21, 2026· 1 source

Microsoft Entra ID to Retire SMS First-Factor Sign-Ins Globally by February 2027

Microsoft will disable SMS-based first-factor authentication for Entra ID workforce tenants worldwide on February 1, 2027, pushing organizations towards more secure, phishing-resistant methods.

Microsoft is set to retire SMS first-factor sign-ins for all Microsoft Entra ID workforce tenants globally by February 1, 2027. This significant security-focused change will prevent users from authenticating using a registered telephone number and an SMS one-time passcode as their primary login method. Organizations that fail to migrate affected users before this deadline risk disrupting access to Microsoft 365 and other services protected by Entra ID.

The retirement, internally tracked as SignInNoPassword, targets a method that allows users to enter a phone number instead of a username and password, followed by a six-digit SMS code for authentication. While initially intended to simplify access, particularly for frontline workers, Microsoft now strongly advises organizations to transition these users to modern, phishing-resistant authentication solutions.

Starting February 1, 2027, Entra ID will block all authentication attempts that rely solely on a phone number and SMS code. Existing configurations enabling this method will cease to function, and related management controls will be removed from Microsoft's administration interfaces. This policy applies to worldwide and US Government Community Cloud tenants, but it specifically excludes Azure AD B2C and Microsoft Entra External ID customer identity scenarios.

Microsoft is phasing out SMS-based authentication due to its inherent vulnerabilities to phishing, social engineering, SIM-swapping, and telecommunications interception. Attackers can easily capture SMS codes via convincing phishing pages and replay them, undermining the security offered by this method. In contrast, phishing-resistant methods like passkeys, which utilize FIDO standards and origin-bound public-key cryptography, keep private credentials on the user's device and tie authentication operations to specific services, making them far more secure.

This move is a continuation of Microsoft's broader strategy to transition towards passwordless and phishing-resistant authentication. The company had previously retired SMS as a first-factor option for Entra ID Free tenants and stopped enabling it for new tenants. The February 2027 deadline extends this policy to all existing workforce tenants, marking a critical juncture for identity management within the Microsoft ecosystem.

Organizations currently allowing employees to use SMS as their primary sign-in method must treat this deadline as a critical identity migration project. After enforcement, accounts relying exclusively on SMS first-factor authentication will face access failures, and any Conditional Access policies or operational procedures built around this method may cease to function as expected. Even third-party providers offering SMS or voice challenges for multi-factor authentication will not preserve SMS as a first-factor sign-in option.

To prepare, administrators are urged to identify users currently enabled for SMS sign-in and verify if they have alternative registered authentication methods. Tools like Entra ID sign-in logs and authentication method reports can assist in this identification process. Affected users should be guided to register phishing-resistant credentials such as passkeys, Windows Hello for Business, or FIDO2 security keys. Microsoft also suggests QR code authentication as a viable alternative for frontline and shared-device scenarios.

Microsoft recommends a phased migration approach, including piloting new authentication options, updating user enrollment instructions, and preparing help-desk procedures. A well-managed migration campaign will help reduce last-minute support burdens and identify potential application compatibility issues before the hard deadline of February 1, 2027. By proactively addressing SMS-dependent accounts and deploying secure alternatives, organizations can avoid access lockouts and significantly enhance their Microsoft Entra ID security posture.

Synthesized by Vypr AI
Microsoft Entra ID to Retire SMS First-Factor Sign-Ins Globally by February 2027 · VYPR