MC1474104 - Microsoft Entra ID: Follow-up on SMS first-factor sign-in retirement and upcoming changes

Microsoft 365 Message Center announcement MC1474104.

MS Message Center's Summary

Microsoft is retiring SMS first factor sign in for workforce tenants on February 1 2027 to improve account security. Administrators must identify any users relying on this method, update authentication policies, and migrate personnel to alternative options such as passkeys or security keys before the retirement date to prevent sign in disruption.

Administrator impact
Administrators must identify users relying on SMS first factor sign in and ensure they register alternative authentication methods before February 1 2027.
End user impact
Affected users must use an alternative authentication method to sign in after February 1 2027.
Importance
8/10: This change causes a permanent retirement of an authentication feature which will block user access if alternative methods are not configured before the deadline.

Choose Your Own Telephony Provider

SMS based user sign in for Microsoft Entra ID

Microsoft Summary

Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide starting February 1, 2027, to enhance security. Organizations must identify affected users, migrate them to phishing-resistant methods like passkeys, and update policies to avoid sign-in disruptions and comply with new requirements.

Message Center ID
MC1474104
Category
plan For Change
Severity
normal
Services
Microsoft Entra
Tags
User impact, Admin impact, Retirement
Published
2026-09-18
Last updated
2026-09-18
Expires
2027-03-02
Action required by
2027-02-01

[What and why] To improve security and reduce reliance on vulnerable authentication methods, Microsoft is continuing the retirement of SMS first-factor sign-in in Microsoft Entra ID. Microsoft recommends phishing-resistant authentication methods, such as passkeys, as the preferred sign-in experience because they help reduce the risk of phishing, fraud, and account compromise associated with phone-based authentication. Microsoft previously retired SMS first-factor sign-in for Microsoft Entra ID Free tenants and stopped enabling SMS sign-in for newly created tenants. This communication provides an update on the next phase of the retirement effort and actions organizations should take to prepare. Microsoft has announced previous retirement actions in Message Center posts MC1426371, MC1448374 , and MC1449181 . This retirement applies only to Microsoft Entra ID workforce tenant authentication scenarios. It does not apply to Azure AD B2C or Microsoft Entra External ID customer identity scenarios. [Rollout schedule] Worldwide and GCC: Beginning February 1, 2027 , SMS first-factor sign-in will be retired for Microsoft Entra ID tenants. [Impact on your organization] Who is affected Organizations that: Allow users to sign in using SMS first-factor authentication. Rely on SMS first-factor sign-in as a primary authentication method. Platforms and services Microsoft Entra ID SMS first-factor passwordless sign-in (SignInNoPassword) What will happen After February 1, 2027: Users will no longer be able to authenticate by using their phone number and an SMS one-time passcode as a primary sign-in method. Existing SMS first-factor sign-in configurations will no longer be honored. Management and configuration experiences for SMS first-factor sign-in will be removed from Microsoft administration experiences. Attempts to sign in by using a registered phone number and SMS one-time passcode will be blocked. Users who have another registered authentication method can continue signing in. Organizations that do not migrate affected users before the retirement date may experience sign-in disruptions. [Action required and recommendations] If your organization uses SMS first-factor sign-in, complete the following actions before February 1, 2027: Identify users currently using SMS first-factor sign-in. Ensure affected users register an alternative authentication method before February 1, 2027. Communicate this change to affected users to prevent sign-in disruptions. Migrate users to passkeys or other phishing-resistant authentication methods. Review authentication method policies and remove dependencies on SMS first-factor sign-in. Review available authentication alternatives and migration guidance. The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method. If your organization currently uses SMS sign-in for first-factor authentication, migrate users to supported alternatives based on their scenarios. Alternatives include passkeys, QR code authentication, FIDO2 security keys, and other authentication methods supported by Microsoft Entra ID. Learn more SMS-based user sign-in for Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn [Compliance considerations] Question Answer Does this change modify how users access Microsoft 365 resources or services? Users who currently rely on SMS first-factor authentication must use another registered authentication method after February 1, 2027. Does this change require admin action to maintain user access? Administrators should identify affected users and ensure alternative authentication methods are registered before the retirement date. Does this change affect Conditional Access policies? Organizations may need to review authentication-related policies and dependencies that currently rely on SMS first-factor sign-in. Does this change alter how admins can monitor, report on, or demonstrate compliance activities? Management and configuration experiences for SMS first-factor sign-in will be removed from Microsoft Entra administration experiences. Does the change include an admin control and can it be controlled through Entra ID group membership? Existing SMS first-factor sign-in configurations will no longer be honored after the retirement date, requiring administrators to transition users to supported authentication methods.