Summary
Details
[What and why]
You are receiving this message because SMS first-factor sign-in is currently enabled in your Microsoft Entra tenant.
Microsoft has observed significant fraud spikes targeting SMS first-factor sign-in. SMS is a phishable authentication method, and leaving this feature enabled creates risk even if you believe your users do not actively use it.
SMS first-factor sign-in allows users, such as frontline workers, to sign in using only a registered phone number and a one-time passcode (OTP) sent through SMS, without entering a username or password.
SMS first-factor sign-in does not enforce multifactor authentication (MFA).
Disabling SMS first-factor sign-in does not prevent users from receiving an SMS code for MFA or Self-Service Password Reset (SSPR).
We strongly recommend that you review this setting immediately. If your organization did not intentionally enable SMS first-factor sign-in or no longer requires it, you should disable it as soon as possible.
Note: If Microsoft detects significant fraudulent activity involving SMS first-factor sign-in in your tenant, Microsoft will take action to block SMS first-factor sign-in to help protect your tenant, users, and the service.
[Rollout schedule]
- Worldwide: Beginning in early August 2026
[Impact on your organization]
Who is affected
- Organizations with SMS first-factor sign-in enabled in their tenant
- Users who sign in using only a registered phone number and an SMS OTP
- Users who rely exclusively on SMS first-factor sign-in
Platforms and services
- Microsoft Entra SMS first-factor passwordless sign-in (SignInNoPassword).
- Microsoft Entra authentication method policy for SMS.
What will happen
- SMS first-factor sign-in will remain enabled in your tenant until you clear Use for sign-in.
- While the setting remains enabled, eligible users can sign in using only a registered phone number and an SMS OTP.
- This capability can create a fraud and phishing risk even if your organization does not intentionally use it.
- Clearing Use for sign-in stops users from signing in with SMS as their only authentication factor.
- Users can continue using SMS for MFA and SSPR after Use for sign-in is cleared.
- Users who rely exclusively on SMS first-factor sign-in must register and use another sign-in method.
The following authentication scenarios are not affected when you clear Use for sign-in:
- SMS used as a multifactor authentication method
- SMS used for Self-Service Password Reset (SSPR)
- Other registered authentication methods
[Action required and recommendations]
Review your SMS authentication method policy and confirm whether SMS first-factor sign-in is intentionally enabled and required.
If your organization does not require SMS first-factor sign-in, complete these steps as soon as possible:
- Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
- Go to Entra ID > Authentication methods > Policies.
- Select SMS from the list of available authentication methods.
- Locate Use for sign-in under SMS-based authentication.
- Clear (uncheck) Use for sign-in.
- Save the policy.
Clearing Use for sign-in stops SMS first-factor sign-in. It does not prevent users from using SMS for MFA or SSPR.
We also recommend that you:
- Identify users who currently use SMS first-factor sign-in.
- Ensure affected users have another sign-in method registered before disabling the feature.
- Communicate the change to affected users to prevent sign-in disruptions.
- Migrate users to passkeys or another phishing-resistant authentication method where possible.
- Review your authentication method policies and remove unnecessary dependencies on SMS first-factor sign-in.
Learn more
[Compliance considerations]
No compliance considerations identified.
Change History
Never Miss a Microsoft 365 Update
Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.