Skip to content

Security1 publisher2 min readPublished

Entra ID stops accepting SMS as a first factor in February 2027

Microsoft told admins on Friday that SMS first-factor sign-in retires from February 2027, and that its own SMS and voice delivery ends on February 1, so tenants that want to keep phone codes must buy telephony elsewhere.

The Watch · Security desk

Illustration accompanying Entra ID stops accepting SMS as a first factor in February 2027

What happened

  • Microsoft has told administrators to move Entra ID users onto phishing-resistant methods such as passkeys before it starts retiring SMS first-factor sign-in in February 2027, to avoid sign-in disruption.
  • Entra ID Free tenants lost SMS first-factor sign-in in August, when Microsoft cited phishing, fraud and account compromise risk, and newly created tenants no longer get SMS sign-in enabled.
  • Admins can enumerate affected users with the Entra SMS/Voice Policy Scanner PowerShell script, which runs under Global Reader, Authentication Policy Administrator or Security Reader.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Identity teams now choose between finishing passkey enrollment before the date and paying a third-party telecom provider configured through the Microsoft Security Store to keep sending codes.
  • constraint Sourcing telephony elsewhere no longer buys time on the first factor, so the usual workaround of swapping providers does not defer the migration.
  • cost Every user who ignores the passkey registration prompt becomes a help desk ticket on the cutover date, and the bill lands on service desks rather than on the security budget.
  • precedent Microsoft tested this cutoff on Free tenants first and then set a fixed date for the rest.

Two retirements land in the same month, and they reach different tenants. The first is SMS as a first factor: a user enters a phone number, receives a code, and signs in without a password. Microsoft is retiring that starting in February 2027 [1]. The second is delivery of the codes themselves. "Following this transition, on February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability" [11].

So a tenant that uses SMS only as a second factor is still in scope [15]. Paying someone else to send the messages does not buy an extension on the first factor. "The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method," Microsoft said in a Microsoft 365 Message Center update on Friday [4].

The change covers workforce tenant authentication in Entra ID. Azure AD B2C and Entra External ID customer identity scenarios are excluded [7], so customer-facing sign-in built on those needs no work. Free tenants went through this in August, when Microsoft retired SMS first-factor there citing phishing, fraud and account compromise risk, and stopped enabling SMS sign-in for newly created tenants [6].

Microsoft said in July that passkeys would start rolling out as the default authentication experience for Entra ID [9]. Enablement is automatic. "As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they'll be prompted to register a passkey," Microsoft said [10]. Registration still depends on each user finishing that prompt. A user who dismisses it keeps using SMS until the retirement, and after it cannot use SMS or voice to complete multifactor authentication or sign in [3].

Finding out how many of those users you have is a script run. Admins holding Global Reader, Authentication Policy Administrator or Security Reader can list SMS and voice users with the Entra SMS/Voice Policy Scanner PowerShell script [12]. The supported destinations Microsoft names are passkeys, QR code authentication, FIDO2 security keys and other Entra-supported methods [2].

Both retirements fall in February 2027, so most tenants are scheduling one cutover [14]. Organizations that have to keep phone-based authentication after it have to configure a third-party telecom provider through the Microsoft Security Store [13].

What to watch

  • Whether Microsoft publishes a per-tenant schedule for the passkey default rollout, which sets when users first see the registration prompt.
  • Whether third-party telephony listings in the Microsoft Security Store carry per-message pricing before the cutover.
  • Any movement on the February 1, 2027 date for paid tenants, after Microsoft held the August cutoff for Free tenants.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories