Microsoft kills SMS auth for Entra ID by Feb 2027
Microsoft Entra ID will block SMS/voice logins in 6 months—here’s what admins must do now
Microsoft is forcing all Entra ID users to abandon SMS and voice authentication in favor of passkeys by February 1, 2027. The company’s administrator notice, reported by Windows Latest, frames this as a critical security upgrade to combat AI-driven phishing attacks, SIM-swapping, and replay attacks. Starting September 1, 2026, users logging in with phone-based methods will be prompted to register a passkey, which relies on device-level biometrics or modern authenticator apps. There will be no opt-outs, and the change applies to all tenants—corporate and personal Microsoft accounts alike.
The transition is mandatory but introduces friction. SMS logins work universally across devices, while passkeys require compatible hardware and user setup. Organizations must audit recovery options and onboard staff before the deadline, or risk permanent account lockouts if users lose access to their primary authentication device. While the move enhances security, it shifts the burden of friction management from telcos to IT teams and end users.
- Microsoft Entra ID will block SMS/voice authentication by Feb 1, 2027, replacing them with passkeys
- Starting Sept 1, 2026, users must register passkeys to continue logging in with SMS/voice
- The change eliminates phishing risks but may cause account lockouts for users without passkeys
Why It Matters
Forces enterprises to adopt passkeys, reducing phishing risks but increasing operational complexity for IT teams and users.