The Deadline
Microsoft has reminded Entra ID administrators that SMS first-factor authentication is being retired effective February 1, 2027. Any tenant still relying on SMS as a primary sign-in method needs to have users migrated to a phishing-resistant alternative before that date to avoid sign-in disruptions. Free-tier Entra ID tenants already lost SMS first-factor sign-in back in August 2026 — this reminder applies to the broader workforce tenant population still on the standard retirement timeline.
Why Microsoft Is Doing This
Microsoft's stated rationale centers on the well-documented weaknesses of SMS as an authentication factor: susceptibility to phishing, fraud, and account compromise through SIM-swapping and interception. SMS-based auth has been considered a weaker MFA option for years across the industry; this is Microsoft formally sunsetting it as a first-factor option rather than just discouraging its use.
What to Migrate To
Microsoft is directing admins toward several phishing-resistant alternatives, with passkeys now set as the default authentication experience for Entra ID:
- Passkeys (FIDO2-based, now default)
- FIDO2 security keys (hardware-based)
- QR code authentication
- Third-party telecom providers, available through the Microsoft Security Store
Guidance for Admins
Microsoft recommends a specific migration path rather than a flag-day cutover:
- Run the Entra SMS/Voice Policy Scanner PowerShell script to identify which users are still authenticating via SMS or voice
- Enable passkeys automatically for users currently on SMS/voice authentication
- Complete the transition well before the February 2027 deadline to avoid last-minute lockouts
Note that this change applies specifically to workforce tenant scenarios — it does not affect Azure AD B2C or other external identity configurations.
Why This Matters
SMS-based MFA has been on borrowed time across the industry for a while, but a hard platform-level retirement date changes the calculus for IT teams that have been treating "migrate to passkeys" as a someday project. With roughly four and a half months of runway from this reminder, admins supporting Entra ID tenants should run the policy scanner now, identify their SMS-dependent user population, and start the passkey rollout rather than waiting for the deadline to force emergency migrations.