Microsoft has announced its decision to phase out SMS first-factor sign-in for Microsoft Entra ID workforce tenants globally by February 1, 2027. The transition requires organizations to shift affected users to more secure authentication methods before the deadline.
Reasons Behind the Transition
The move aims to enhance security by eliminating the use of registered phone numbers and SMS one-time passcodes as primary sign-in methods. This change could affect access to Microsoft 365 and other Entra-protected services if not properly managed by administrators.
The existing system, known as SignInNoPassword, allows users to authenticate using a phone number and a six-digit SMS code instead of a traditional username and password. Originally created to aid frontline workers, Microsoft now advises a shift to modern, phishing-resistant authentication methods.
Impact on Current Users
Beginning in February 2027, attempts to authenticate using a phone number and SMS code as the primary factor will be blocked. This change applies to worldwide and US Government Community Cloud tenants but excludes Azure AD B2C or Microsoft Entra External ID scenarios.
Users with alternative authentication methods can continue accessing their accounts. However, accounts solely dependent on SMS sign-in face potential access issues. Microsoft is moving away from SMS-based authentication due to vulnerabilities such as phishing, SIM-swapping, and interception risks.
Recommended Actions for Organizations
Organizations should treat the February 2027 deadline as an identity migration project. This involves transitioning from SMS-based methods to secure alternatives like passkeys, which use FIDO standards and origin-bound public-key cryptography, offering resistance to phishing attacks.
Administrators should first identify users relying on SMS sign-in and check for available alternative methods. It is crucial to address shared-device environments and users without corporate smartphones. Recommended alternatives include passkeys, Windows Hello, and FIDO2 security keys.
Implementing a staged migration with comprehensive user communication and support will help mitigate last-minute issues. By acting now, organizations can prevent access disruptions and enhance their security posture.
The February 2027 deadline represents a significant shift towards increased security. By adopting phishing-resistant credentials and eliminating SMS dependencies, organizations can avoid lockouts and strengthen their Microsoft Entra ID security framework.
