Back to Feed
Identity & AccessSep 21, 2026

Microsoft reminds admins to migrate Entra ID users to passkeys

Microsoft to retire SMS first-factor sign-in for Entra ID in Feb 2027.

Summary

Microsoft is reminding administrators to migrate Entra ID users away from SMS-based authentication methods to phishing-resistant alternatives like passkeys before February 2027. After this date, SMS and voice authentication will be retired as first-factor authentication options for Entra ID workforce tenants, aiming to mitigate risks of phishing, fraud, and account compromise. Organizations are advised to use tools like the Entra SMS/Voice Policy Scanner PowerShell script to identify affected users and guide them to supported alternatives.

Full text

Microsoft reminds admins to migrate Entra ID users to passkeys By Sergiu Gatlan September 21, 2026 09:16 AM 0 Microsoft has reminded administrators to migrate Entra ID users to phishing-resistant methods, such as passkeys, to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. Admins also have alternatives, including QR code authentication, FIDO2 security keys, and other Entra ID-supported authentication methods. Before this date, organizations should ensure all users use a phishing-resistant method because they will no longer be able to use SMS or voice to complete multifactor authentication and sign in to their accounts. "The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method," Microsoft said in a Microsoft 365 Message Center update on Friday. "If your organization currently uses SMS sign-in for first-factor authentication, migrate users to supported alternatives based on their scenarios." Microsoft retired SMS first-factor sign-in for Microsoft Entra ID Free tenants in August due to phishing, fraud, and account compromise risks and no longer enables SMS sign-in for newly created tenants. The retirement process applies only to Microsoft Entra ID workforce tenant authentication scenarios and not to Azure AD B2C or Microsoft Entra External ID customer identity scenarios. Microsoft has shared detailed guidance on deploying and managing phishing-resistant passwordless authentication in Entra ID on this dedicated documentation page. Passkeys now default Entra ID authentication method In July, Microsoft also announced that passkeys will start rolling out as the default authentication experience for the Entra ID enterprise identity service starting this month. "As the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they'll be prompted to register a passkey," Microsoft said. "Following this transition, on February 1, 2027, Microsoft will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability" Admins with Global Reader, Authentication Policy Administrator, or Security Reader roles can find SMS or voice auth users by running the Entra SMS/Voice Policy Scanner PowerShell script. Organizations that must use phone-based authentication have to configure third-party telecom providers through the Microsoft Security Store. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Microsoft patches max severity code execution, privilege escalation flawsMicrosoft: September updates break File History backup featureMicrosoft fixes broken copy and paste for Excel 2016 usersMicrosoft Teams will let admins block custom file extensionsMicrosoft Teams to get efficiency mode on PCs with limited resources

Entities

Entra ID (product)Microsoft (vendor)passkeys (technology)SMS authentication (technology)