Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Microsoft Entra ID: Review and disable SMS first-factor sign-in if it is not needed

Message ID
MC1449181
View in Message Center
Service
Microsoft Entra
Category
preventOrFixIssue
Tags
User impactAdmin impact
Rollout
August 2026

Summary

Review and disable SMS first-factor sign-in in Microsoft Entra ID if not needed, as it poses phishing and fraud risks. Disabling it stops SMS-only sign-in but still allows SMS for MFA and password reset. Ensure users have alternative sign-in methods before disabling to avoid disruptions.

Details

[What and why]

You are receiving this message because SMS first-factor sign-in is currently enabled in your Microsoft Entra tenant.

Microsoft has observed significant fraud spikes targeting SMS first-factor sign-in. SMS is a phishable authentication method, and leaving this feature enabled creates risk even if you believe your users do not actively use it.

SMS first-factor sign-in allows users, such as frontline workers, to sign in using only a registered phone number and a one-time passcode (OTP) sent through SMS, without entering a username or password.

SMS first-factor sign-in does not enforce multifactor authentication (MFA).

Disabling SMS first-factor sign-in does not prevent users from receiving an SMS code for MFA or Self-Service Password Reset (SSPR).

We strongly recommend that you review this setting immediately. If your organization did not intentionally enable SMS first-factor sign-in or no longer requires it, you should disable it as soon as possible.

Note: If Microsoft detects significant fraudulent activity involving SMS first-factor sign-in in your tenant, Microsoft will take action to block SMS first-factor sign-in to help protect your tenant, users, and the service.

[Rollout schedule]

  • Worldwide: Beginning in early August 2026

[Impact on your organization]

Who is affected

  • Organizations with SMS first-factor sign-in enabled in their tenant
  • Users who sign in using only a registered phone number and an SMS OTP
  • Users who rely exclusively on SMS first-factor sign-in

Platforms and services

  • Microsoft Entra SMS first-factor passwordless sign-in (SignInNoPassword).
  • Microsoft Entra authentication method policy for SMS.

What will happen

  • SMS first-factor sign-in will remain enabled in your tenant until you clear Use for sign-in.
  • While the setting remains enabled, eligible users can sign in using only a registered phone number and an SMS OTP.
  • This capability can create a fraud and phishing risk even if your organization does not intentionally use it.
  • Clearing Use for sign-in stops users from signing in with SMS as their only authentication factor.
  • Users can continue using SMS for MFA and SSPR after Use for sign-in is cleared.
  • Users who rely exclusively on SMS first-factor sign-in must register and use another sign-in method.

The following authentication scenarios are not affected when you clear Use for sign-in:

  • SMS used as a multifactor authentication method
  • SMS used for Self-Service Password Reset (SSPR)
  • Other registered authentication methods

[Action required and recommendations]

Review your SMS authentication method policy and confirm whether SMS first-factor sign-in is intentionally enabled and required.

If your organization does not require SMS first-factor sign-in, complete these steps as soon as possible:

  1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
  2. Go to Entra ID > Authentication methods > Policies.
  3. Select SMS from the list of available authentication methods.
  4. Locate Use for sign-in under SMS-based authentication.
  5. Clear (uncheck) Use for sign-in.
  6. Save the policy.

Clearing Use for sign-in stops SMS first-factor sign-in. It does not prevent users from using SMS for MFA or SSPR.

We also recommend that you:

  • Identify users who currently use SMS first-factor sign-in.
  • Ensure affected users have another sign-in method registered before disabling the feature.
  • Communicate the change to affected users to prevent sign-in disruptions.
  • Migrate users to passkeys or another phishing-resistant authentication method where possible.
  • Review your authentication method policies and remove unnecessary dependencies on SMS first-factor sign-in.

Learn more

[Compliance considerations]

No compliance considerations identified. 

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.