Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Microsoft Entra ID: Follow-up on SMS first-factor sign-in retirement and upcoming changes

Message ID
MC1474104
View in Message Center
Service
Microsoft Entra
Category
Plan for Change
Tags
Major Change User impactAdmin impactRetirement
Act By
February 1, 2027
Rollout
February 2027September 2026

Summary

Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide starting February 1, 2027, to enhance security. Organizations must identify affected users, migrate them to phishing-resistant methods like passkeys, and update policies to avoid sign-in disruptions and comply with new requirements.

Details

[What and why]

To improve security and reduce reliance on vulnerable authentication methods, Microsoft is continuing the retirement of SMS first-factor sign-in in Microsoft Entra ID. Microsoft recommends phishing-resistant authentication methods, such as passkeys, as the preferred sign-in experience because they help reduce the risk of phishing, fraud, and account compromise associated with phone-based authentication.

Microsoft previously retired SMS first-factor sign-in for Microsoft Entra ID Free tenants and stopped enabling SMS sign-in for newly created tenants. This communication provides an update on the next phase of the retirement effort and actions organizations should take to prepare. Microsoft has announced previous retirement actions in Message Center posts MC1426371, MC1448374, and MC1449181.

This retirement applies only to Microsoft Entra ID workforce tenant authentication scenarios. It does not apply to Azure AD B2C or Microsoft Entra External ID customer identity scenarios.

[Rollout schedule]

  • Worldwide and GCC: Beginning February 1, 2027, SMS first-factor sign-in will be retired for Microsoft Entra ID tenants.

[Impact on your organization]

Who is affected

Organizations that:

  • Allow users to sign in using SMS first-factor authentication.
  • Rely on SMS first-factor sign-in as a primary authentication method.

Platforms and services

  • Microsoft Entra ID
  • SMS first-factor passwordless sign-in (SignInNoPassword)

What will happen

After February 1, 2027:

  • Users will no longer be able to authenticate by using their phone number and an SMS one-time passcode as a primary sign-in method.
  • Existing SMS first-factor sign-in configurations will no longer be honored.
  • Management and configuration experiences for SMS first-factor sign-in will be removed from Microsoft administration experiences.
  • Attempts to sign in by using a registered phone number and SMS one-time passcode will be blocked.
  • Users who have another registered authentication method can continue signing in.
  • Organizations that do not migrate affected users before the retirement date may experience sign-in disruptions.

[Action required and recommendations]

If your organization uses SMS first-factor sign-in, complete the following actions before February 1, 2027:

  • Identify users currently using SMS first-factor sign-in.
  • Ensure affected users register an alternative authentication method before February 1, 2027.
  • Communicate this change to affected users to prevent sign-in disruptions.
  • Migrate users to passkeys or other phishing-resistant authentication methods.
  • Review authentication method policies and remove dependencies on SMS first-factor sign-in.
  • Review available authentication alternatives and migration guidance.

The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method. If your organization currently uses SMS sign-in for first-factor authentication, migrate users to supported alternatives based on their scenarios. Alternatives include passkeys, QR code authentication, FIDO2 security keys, and other authentication methods supported by Microsoft Entra ID.

Learn more

[Compliance considerations]

QuestionAnswer
Does this change modify how users access Microsoft 365 resources or services?Users who currently rely on SMS first-factor authentication must use another registered authentication method after February 1, 2027.
Does this change require admin action to maintain user access?Administrators should identify affected users and ensure alternative authentication methods are registered before the retirement date.
Does this change affect Conditional Access policies?Organizations may need to review authentication-related policies and dependencies that currently rely on SMS first-factor sign-in.
Does this change alter how admins can monitor, report on, or demonstrate compliance activities?Management and configuration experiences for SMS first-factor sign-in will be removed from Microsoft Entra administration experiences.
Does the change include an admin control and can it be controlled through Entra ID group membership?Existing SMS first-factor sign-in configurations will no longer be honored after the retirement date, requiring administrators to transition users to supported authentication methods.

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.