Summary
Details
[What and why]
You are receiving this message because SMS first-factor sign-in is enabled in your Microsoft Entra tenant.
Microsoft has observed significant fraud activity targeting SMS first-factor sign-in. SMS is a phishing-susceptible authentication method, and leaving this capability enabled can create risk even when users are not actively or successfully using it.
SMS first-factor sign-in allows users, such as frontline workers, to sign in using only a registered phone number and a one-time passcode (OTP) sent by SMS, without entering a username or password.
SMS first-factor sign-in does not enforce multifactor authentication (MFA).
To help protect customers, users, and Microsoft services, Microsoft will automatically disable SMS first-factor sign-in in tenants that meet either of the following conditions:
- No successful SMS first-factor sign-in activity has occurred during the previous 30 days.
- All SMS first-factor sign-in attempts during the previous 30 days were unsuccessful.
This change affects only SMS as a first-factor sign-in method. Users can continue to receive SMS verification codes for multifactor authentication (MFA) and Self-Service Password Reset (SSPR).
We strongly recommend that you review this setting and recent SMS first-factor sign-in activity before rollout begins. If your organization still requires SMS first-factor sign-in, confirm that legitimate users can sign in successfully and ensure that they have another sign-in method registered.
[Rollout schedule]
- Worldwide: Beginning in mid-September 2026 and expected to complete by late September 2026
During rollout, Microsoft will evaluate eligible tenants and disable SMS first-factor sign-in when the criteria described above are met.
[Impact on your organization]
Who is affected
- Organizations with SMS first-factor sign-in enabled in Microsoft Entra
- Tenants with no SMS first-factor sign-in activity during the previous 30 days
- Tenants where all SMS first-factor sign-in attempts during the previous 30 days were unsuccessful
- Users who rely exclusively on SMS first-factor sign-in
Platforms and services
- Microsoft Entra ID
- SMS first-factor passwordless sign-in (SignInNoPassword)
- Microsoft Entra authentication methods policies
What will happen
- Microsoft will review recent SMS first-factor sign-in activity in eligible tenants.
- If no successful SMS first-factor sign-in activity occurred during the previous 30 days, Microsoft will clear the Use for sign-in setting.
- If all SMS first-factor sign-in attempts during the previous 30 days were unsuccessful, Microsoft will clear the Use for sign-in setting.
- Clearing Use for sign-in disables SMS first-factor sign-in for the tenant.
- Users will no longer be able to use SMS as their only authentication factor for sign-in.
- Users who rely exclusively on SMS first-factor sign-in must register and use another sign-in method.
- SMS verification codes for MFA and SSPR will continue to work.
- Other authentication methods, including password-based sign-in, are not affected.
[Action required and recommendations]
Review your Microsoft Entra authentication methods policy to determine whether SMS first-factor sign-in is intentionally enabled and still required.
Before rollout begins, we recommend that you:
- Review SMS first-factor sign-in activity from the previous 30 days.
- Identify users who currently rely on SMS first-factor sign-in.
- Investigate unsuccessful SMS first-factor sign-in attempts.
- Ensure affected users have at least one alternate sign-in method registered.
- Communicate this change to affected users before rollout.
- Migrate users to passkeys or another phishing-resistant authentication method where possible.
- Disable SMS first-factor sign-in yourself if your organization no longer requires it.
To review or disable SMS first-factor sign-in:
- Sign in to the Microsoft Entra admin center with an account assigned at least the Authentication Policy Administrator role.
- Go to Entra ID > Authentication methods > Policies.
- Select SMS from the list of available authentication methods.
- Locate Use for sign-in under SMS-based authentication.
- Clear Use for sign-in to disable SMS first-factor sign-in.
- Save the policy.
Clearing Use for sign-in stops SMS first-factor sign-in. It does not prevent users from using SMS for MFA or SSPR.
Learn more
[Compliance considerations]
| Question | Answer |
| Does this change include an admin control? | Yes. Administrators can control SMS first-factor sign-in through Microsoft Entra authentication method policies. Administrators can review, enable, or disable the Use for sign-in setting for SMS-based authentication. |
Change History
Never Miss a Microsoft 365 Update
Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.