Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Microsoft Entra: Prepare for Microsoft to disable unused or unsuccessful SMS first-factor sign-in

Message ID
MC1465763
View in Message Center
Service
Microsoft Entra
Category
preventOrFixIssue
Tags
User impactAdmin impact
Rollout
September 2026

Summary

Microsoft will disable SMS first-factor sign-in in Microsoft Entra tenants with no successful or only unsuccessful SMS sign-ins in the past 30 days, starting mid-September 2026. SMS for MFA and password reset remains unaffected. Review and update authentication methods to ensure users have alternate sign-in options.

Details

[What and why]

You are receiving this message because SMS first-factor sign-in is enabled in your Microsoft Entra tenant.

Microsoft has observed significant fraud activity targeting SMS first-factor sign-in. SMS is a phishing-susceptible authentication method, and leaving this capability enabled can create risk even when users are not actively or successfully using it.

SMS first-factor sign-in allows users, such as frontline workers, to sign in using only a registered phone number and a one-time passcode (OTP) sent by SMS, without entering a username or password.

SMS first-factor sign-in does not enforce multifactor authentication (MFA).

To help protect customers, users, and Microsoft services, Microsoft will automatically disable SMS first-factor sign-in in tenants that meet either of the following conditions:

  • No successful SMS first-factor sign-in activity has occurred during the previous 30 days.
  • All SMS first-factor sign-in attempts during the previous 30 days were unsuccessful.

This change affects only SMS as a first-factor sign-in method. Users can continue to receive SMS verification codes for multifactor authentication (MFA) and Self-Service Password Reset (SSPR).

We strongly recommend that you review this setting and recent SMS first-factor sign-in activity before rollout begins. If your organization still requires SMS first-factor sign-in, confirm that legitimate users can sign in successfully and ensure that they have another sign-in method registered.

[Rollout schedule]

  • Worldwide: Beginning in mid-September 2026 and expected to complete by late September 2026

During rollout, Microsoft will evaluate eligible tenants and disable SMS first-factor sign-in when the criteria described above are met.

[Impact on your organization]

Who is affected

  • Organizations with SMS first-factor sign-in enabled in Microsoft Entra
  • Tenants with no SMS first-factor sign-in activity during the previous 30 days
  • Tenants where all SMS first-factor sign-in attempts during the previous 30 days were unsuccessful
  • Users who rely exclusively on SMS first-factor sign-in

Platforms and services

  • Microsoft Entra ID
  • SMS first-factor passwordless sign-in (SignInNoPassword)
  • Microsoft Entra authentication methods policies

What will happen

  • Microsoft will review recent SMS first-factor sign-in activity in eligible tenants.
  • If no successful SMS first-factor sign-in activity occurred during the previous 30 days, Microsoft will clear the Use for sign-in setting.
  • If all SMS first-factor sign-in attempts during the previous 30 days were unsuccessful, Microsoft will clear the Use for sign-in setting.
  • Clearing Use for sign-in disables SMS first-factor sign-in for the tenant.
  • Users will no longer be able to use SMS as their only authentication factor for sign-in.
  • Users who rely exclusively on SMS first-factor sign-in must register and use another sign-in method.
  • SMS verification codes for MFA and SSPR will continue to work.
  • Other authentication methods, including password-based sign-in, are not affected.

[Action required and recommendations]

Review your Microsoft Entra authentication methods policy to determine whether SMS first-factor sign-in is intentionally enabled and still required.

Before rollout begins, we recommend that you:

  • Review SMS first-factor sign-in activity from the previous 30 days.
  • Identify users who currently rely on SMS first-factor sign-in.
  • Investigate unsuccessful SMS first-factor sign-in attempts.
  • Ensure affected users have at least one alternate sign-in method registered.
  • Communicate this change to affected users before rollout.
  • Migrate users to passkeys or another phishing-resistant authentication method where possible.
  • Disable SMS first-factor sign-in yourself if your organization no longer requires it.

To review or disable SMS first-factor sign-in:

  • Sign in to the Microsoft Entra admin center with an account assigned at least the Authentication Policy Administrator role.
  • Go to Entra ID > Authentication methods > Policies.
  • Select SMS from the list of available authentication methods.
  • Locate Use for sign-in under SMS-based authentication.
  • Clear Use for sign-in to disable SMS first-factor sign-in.
  • Save the policy.

Clearing Use for sign-in stops SMS first-factor sign-in. It does not prevent users from using SMS for MFA or SSPR.

Learn more

[Compliance considerations]

QuestionAnswer
Does this change include an admin control?Yes. Administrators can control SMS first-factor sign-in through Microsoft Entra authentication method policies. Administrators can review, enable, or disable the Use for sign-in setting for SMS-based authentication.

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.