To prevent authentication disruptions, Microsoft is calling on IT administrators to move Entra ID users toward phishing-resistant alternatives ahead of its planned discontinuation of SMS first-factor sign-in in February 2027. The company has outlined several replacement options available within Entra ID, including passkeys, QR code authentication, and FIDO2 security keys.

Once the retirement takes effect, organizations relying on SMS or voice-based methods for multifactor authentication will find those options unavailable for account access. Microsoft emphasized in a Friday update to the Microsoft 365 Message Center that "The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method."

The company advised that "If your organization currently uses SMS sign-in for first-factor authentication, migrate users to supported alternatives based on their scenarios."

Microsoft had already begun phasing out SMS first-factor authentication for Microsoft Entra ID Free tenants in August, citing exposure to phishing, fraud, and account compromise. The company also stopped enabling SMS sign-in by default for newly provisioned tenants at that time.

The deprecation applies specifically to workforce tenant authentication within Microsoft Entra ID and does not extend to Azure AD B2C or Microsoft Entra External ID scenarios involving customer identity management.

Administrators seeking implementation guidance can access Microsoft's comprehensive documentation on deploying and managing phishing-resistant passwordless authentication methods through the company's dedicated resource page.

Passkeys Becoming Default Authentication Experience

Passkeys are being positioned as the standard authentication method for Entra ID, with Microsoft announcing in July that rollout would commence this month. As the feature reaches each tenant, users with SMS or voice authentication enabled will automatically gain passkey capability. Microsoft stated that "the next time they perform multifactor authentication, they'll be prompted to register a passkey."

The company clarified that "Following this transition, on February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability."

Administrators holding Global Reader, Authentication Policy Administrator, or Security Reader roles can identify users still configured for SMS or voice authentication by executing the Entra SMS/Voice Policy Scanner PowerShell script.

Organizations with business requirements for phone-based authentication will need to establish connections with third-party telecom providers via the Microsoft Security Store.