After SMS Authentication Ends

Entra ID: Microsoft Issues Another Reminder to Migrate to Passkeys

Microsoft Entra ID, Entra ID, Microsoft Entra ID SMS authentication phase out, Microsoft Entra ID passkey migration
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Stockinq/Shutterstock.com

Organizations using Microsoft Entra ID should start preparing to replace SMS-based sign-ins. Microsoft has once again reminded admins that SMS and phone call authentication as a first factor are being phased out.

Starting February 1, 2027, Microsoft will completely shut down its own telephony infrastructure for SMS and voice authentication. The change affects the use of text messages or phone calls as the first authentication factor, regardless of whether an organization has connected its own telecommunications provider through the Choose Your Own Telephony Provider feature. In practical terms, users affected by the change will no longer be able to sign in unless they switch to another authentication method in time.

Ad

Microsoft recommends alternatives including passkeys, FIDO2 security keys, and QR code sign-in, along with other authentication methods supported by Entra ID. Microsoft also provides detailed guidance for deploying phishing-resistant, passwordless authentication in its documentation. The change applies specifically to Microsoft Entra ID workforce tenants. Azure AD B2C and customer identities using Microsoft Entra External ID are not affected.

The shift is not entirely new. Microsoft already disabled SMS-based first-factor authentication for free Entra ID tenants in August, citing risks related to phishing, fraud, and compromised accounts. Newly created tenants no longer offer the SMS option by default.

Passkeys Enabled Automatically

At the same time, Microsoft is accelerating the transition to passkeys as the default authentication method. The corresponding change for Entra ID has been rolling out gradually since September. Affected users who have previously signed in using SMS or phone calls will have passkeys enabled automatically. At their next multifactor authentication sign-in, they will then be prompted to register a passkey directly.

Ad

Tools to Support the Migration

To help admins identify which users in their organization still rely on SMS or voice calls, Microsoft provides a PowerShell tool called the Entra SMS/Voice Policy Scanner. Access is available to roles including Global Reader, Authentication Policy Administrator, and Security Reader. For organizations where phone-based authentication remains unavoidable, third-party providers can be connected through the Microsoft Security Store.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel