Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2964+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Microsoft Reminds Admins to Migrate Entra ID Users to Passkeys Before SMS Retirement
Microsoft Reminds Admins to Migrate Entra ID Users to Passkeys Before SMS Retirement
NEWS

Microsoft Reminds Admins to Migrate Entra ID Users to Passkeys Before SMS Retirement

Microsoft is retiring SMS first-factor sign-in for Entra ID on February 1, 2027, and is urging admins to move users to passkeys now.

Dylan H.

News Desk

September 21, 2026
2 min read

The Deadline

Microsoft has reminded Entra ID administrators that SMS first-factor authentication is being retired effective February 1, 2027. Any tenant still relying on SMS as a primary sign-in method needs to have users migrated to a phishing-resistant alternative before that date to avoid sign-in disruptions. Free-tier Entra ID tenants already lost SMS first-factor sign-in back in August 2026 — this reminder applies to the broader workforce tenant population still on the standard retirement timeline.


Why Microsoft Is Doing This

Microsoft's stated rationale centers on the well-documented weaknesses of SMS as an authentication factor: susceptibility to phishing, fraud, and account compromise through SIM-swapping and interception. SMS-based auth has been considered a weaker MFA option for years across the industry; this is Microsoft formally sunsetting it as a first-factor option rather than just discouraging its use.


What to Migrate To

Microsoft is directing admins toward several phishing-resistant alternatives, with passkeys now set as the default authentication experience for Entra ID:

  • Passkeys (FIDO2-based, now default)
  • FIDO2 security keys (hardware-based)
  • QR code authentication
  • Third-party telecom providers, available through the Microsoft Security Store

Guidance for Admins

Microsoft recommends a specific migration path rather than a flag-day cutover:

  • Run the Entra SMS/Voice Policy Scanner PowerShell script to identify which users are still authenticating via SMS or voice
  • Enable passkeys automatically for users currently on SMS/voice authentication
  • Complete the transition well before the February 2027 deadline to avoid last-minute lockouts

Note that this change applies specifically to workforce tenant scenarios — it does not affect Azure AD B2C or other external identity configurations.


Why This Matters

SMS-based MFA has been on borrowed time across the industry for a while, but a hard platform-level retirement date changes the calculus for IT teams that have been treating "migrate to passkeys" as a someday project. With roughly four and a half months of runway from this reminder, admins supporting Entra ID tenants should run the policy scanner now, identify their SMS-dependent user population, and start the passkey rollout rather than waiting for the deadline to force emergency migrations.


References

  • BleepingComputer — Microsoft Reminds Admins to Migrate Entra ID Users to Passkeys

Related Reading

  • Microsoft to Roll Out Entra Passkeys on Windows in Late April
#Microsoft#Entra ID#Passkeys#MFA#Identity

Related Articles

Microsoft to Roll Out Entra Passkeys on Windows in Late

Microsoft is rolling out passkey support for phishing-resistant passwordless authentication to Microsoft Entra-protected resources from Windows devices...

5 min read

Conditional Access Policies: Zero Trust with Entra ID

Implement Zero Trust security with Microsoft Entra ID Conditional Access. Covers named locations, device compliance, risk-based policies, and...

12 min read

Microsoft Entra ID CVSS 10.0 Flaw Exploited in Wild, Allows Remote Code Execution

Microsoft warns of a CVSS 10.0 RCE flaw in Entra ID (CVE-2026-69836) exploited in the wild. No customer action required — Microsoft patched it server-side.

3 min read
Back to all News