Microsoft to End Native SMS Authentication in Entra ID by 2027

3 min read
Source: BleepingComputer
Microsoft to End Native SMS Authentication in Entra ID by 2027
Photo: BleepingComputer
TL;DR

Microsoft is retiring native SMS and voice authentication for Microsoft Entra ID workforce tenants, with a hard cutoff on February 1, 2027. Passkeys are now the default authentication method, and users without alternative methods will face mandatory registration prompts to avoid sign-in lockouts.

Key points

  • Microsoft will stop providing native SMS and voice delivery for Entra ID workforce tenants on February 1, 2027.
  • Global administrators and external users receive a temporary extension until July 1, 2027, while internal guest users must migrate by February 1.
  • Passkeys became the default authentication experience starting September 1, 2026, automatically enabling them for users currently using SMS or voice.
  • Users whose only MFA method is SMS or voice will encounter a blocking passkey registration prompt after the retirement date, with no opt-out available.
  • Organizations can use a customer-managed telecom provider via the Microsoft Security Store starting October 30, 2026, to retain phone-based authentication for compliance needs.

Background

This move follows Microsoft's August 2026 retirement of SMS first-factor sign-in for Entra ID Free tenants and its broader push to enforce phishing-resistant authentication. It also follows recent passkey-related security disclosures in August 2026, which highlighted vulnerabilities in surrounding controls rather than the cryptography itself, reinforcing the need for robust endpoint and zero-trust protections.

How outlets are covering it

BleepingComputer emphasizes the mandatory nature of the transition and the risk of sign-in disruptions for organizations that delay migration. Petri IT Knowledgebase highlights the phased rollout and the availability of a temporary opt-out for automatic passkey enablement, while stressing the need for early adoption to reduce help desk workloads. Redmondmag.com notes the concurrent retirement of Microsoft 365 companion apps and the option for customer-managed telecom providers. heise online focuses on the security rationale, citing SS7 protocol vulnerabilities and the trivial bypass of SMS-based two-factor protection, while noting that the change does not affect Azure AD B2C or Entra External ID.

Why it matters

The retirement of SMS and voice authentication forces organizations to adopt phishing-resistant methods like passkeys, FIDO2 security keys, or Windows Hello for Business. Failure to migrate users by the deadline will result in sign-in lockouts, as Microsoft will block authentication attempts using retired methods. This shift enhances overall security by eliminating vulnerable phone-based verification, but requires significant administrative effort to identify affected users and deploy new authentication methods.

What to watch

Administrators should run the Entra SMS/Voice Policy Scanner PowerShell script to identify users relying on SMS or voice authentication. Organizations must migrate these users to passkeys or other phishing-resistant methods before February 1, 2027. Those with regulatory requirements for phone-based authentication should configure a customer-managed telecom provider through the Microsoft Security Store by October 30, 2026. Microsoft will continue rolling out passkeys as the default authentication experience, and users will be prompted to register a passkey after completing MFA sign-ins.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer