[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7apW73EEMAqFKKNyAf7T3i2VsNfb2mNUiH0Ltcfwn2g":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"3176192a-de63-4163-812b-eaea3a874668","sms-based-mfa-retirement-demands-urgent-migration-to-phishing-resistant-auth","f70c98e1-1a34-4f09-afeb-acebe1f79110","SMS-Based MFA Retirement Demands Urgent Migration to Phishing-Resistant Auth","Microsoft is retiring SMS and voice as first-factor authentication options in Entra ID by February 2027, reflecting the well-established weakness of SMS-based authentication against SIM-swapping, phishing, and interception attacks. Organizations that delay migration risk a sudden loss of access for affected users or continued exposure to account compromise if non-compliant methods persist. The root issue is that many organizations defaulted to SMS-based MFA as a convenient option without planning a long-term migration path to stronger alternatives. This matters because phishing-resistant methods like passkeys and FIDO2 keys eliminate the credential-theft vectors that attackers routinely exploit against SMS-based systems.","**Immediate actions:**\n- Run Microsoft's Entra SMS\u002FVoice Policy Scanner PowerShell script to identify all users still relying on SMS or voice authentication.\n- Begin enrolling users in phishing-resistant alternatives such as passkeys, FIDO2 security keys, or the Microsoft Authenticator app before the February 2027 deadline.\n\n**Long-term improvements:**\n- Establish a formal Identity and Access Management (IAM) policy that mandates phishing-resistant MFA for all workforce accounts.\n- Implement Conditional Access policies in Entra ID that enforce strong authentication methods and block legacy, weak authentication options.\n- Maintain an ongoing authentication method inventory and review it quarterly to catch any regressions or newly onboarded users using weak methods.\n\n**Detection & monitoring measures:**\n- Configure Entra ID sign-in logs and alerts to flag authentication events using SMS or voice methods so stragglers are caught early.\n- Track MFA registration campaigns through Entra ID's Authentication Methods Activity dashboard to measure migration progress over time.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 6.3 – Require MFA for externally-exposed applications","CIS Control 6.5 – Require MFA for administrative access","NIST SP 800-63B – Authentication and Lifecycle Management (AAL2\u002FAAL3)","NIST AC-2 – Account Management","NIST IA-5 – Authenticator Management","NIST IA-8 – Identification and Authentication (Non-Organizational Users)","ISO\u002FIEC 27001:2022 – A.8.5 Secure Authentication","GDPR Article 32 – Security of Processing (appropriate technical measures)","Microsoft Secure Score – Identity improvement actions","ITIL Service Transition – Change Management for authentication infrastructure","published","2026-09-21T14:20:28.500624+00:00","2026-09-21T14:20:26.775+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fmicrosoft\u002Fmicrosoft-reminds-admins-to-migrate-entra-id-users-to-passkeys\u002F","microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys-4eca08","Microsoft reminds admins to migrate Entra ID users to passkeys",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]