Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires organizations to migrate affected users before February 1, 2027.
The security-focused change will prevent employees from using a registered telephone number and SMS one-time passcode as their primary sign-in method, potentially disrupting Microsoft 365 and other Entra-protected services if administrators fail to prepare.
SMS first-factor authentication, internally identified as SignInNoPassword, allows a user to enter a registered phone number instead of a username and password. Microsoft Entra ID then sends a six-digit SMS code that completes authentication.
Although Microsoft initially intended it to simplify access for frontline workers, it now advises organizations to move those users to modern, phishing-resistant authentication.
Microsoft Entra ID SMS Sign-In
According to the update notice published by Microsoft, beginning February 1, 2027, Entra ID will block attempts to authenticate with a phone number and SMS one-time passcode as the primary factor.
Existing configurations enabling SMS for sign-in will no longer be honored, while related management and configuration controls will disappear from Microsoft administration experiences.
The retirement applies to worldwide and US Government Community Cloud tenants. It is limited to Microsoft Entra ID workforce authentication and does not extend to Azure AD B2C or Microsoft Entra External ID customer identity scenarios.
Users with another registered and permitted authentication method can still sign in, but accounts that rely exclusively on SMS first-factor authentication face access failures.
Microsoft is steering customers away from phone-based authentication because SMS codes remain vulnerable to phishing, social engineering, SIM-swapping, number reassignment, and telecommunications interception.
An attacker operating a convincing phishing page can capture an SMS code and immediately replay it, making the method less resilient than cryptographic credentials tied to the legitimate website.
Passkeys address this weakness through FIDO standards and origin-bound public-key cryptography. The private credential remains with the user’s device, while the authentication operation is restricted to the service for which the passkey was registered.
This design makes passkeys resistant to conventional credential phishing and prevents attackers from simply replaying intercepted authentication secrets.
Microsoft previously retired SMS as a first-factor sign-in option for Entra ID Free tenants and stopped enabling it for newly created tenants. The February deadline expands that strategy across existing workforce tenants, continuing the company’s broader transition toward passwordless and phishing-resistant authentication.
Any organization allowing employees to use SMS as their primary sign-in method should treat the deadline as an identity migration project rather than a routine policy change.
After enforcement begins, registering a phone number will no longer provide an alternative path into an account, and Conditional Access policies or operational procedures built around SMS sign-in may produce unexpected results.
The change will also affect organizations using Choose Your Own Telephony Provider. Third-party providers can continue delivering SMS or voice challenges for supported multifactor authentication scenarios, but they do not preserve SMS as a first-factor sign-in option.
Microsoft recommends retaining telephony authentication only where a documented business, technical, or regulatory requirement prevents adoption of phishing-resistant methods.
Administrators should first identify users currently enabled for SMS sign-in and determine whether they possess another registered method. Sign-in logs, authentication-method reports, policy assignments, and frontline-worker groups can help identify at-risk accounts.
Pay particular attention to shared-device environments, users without corporate smartphones, and recovery processes that still depend on telephone numbers.
Affected users should then register passkeys, Windows Hello for Business, or FIDO2 security keys. Microsoft also identifies QR code authentication as an alternative for frontline and shared-device scenarios; Entra represents this method as a QR code and PIN combination administered for the user.
Organizations should pilot each option against their device estate, browser requirements, and Conditional Access authentication strengths before broad deployment.
Administrators must also update enrollment instructions, help-desk procedures, break-glass planning and user communications. A staged migration with monitored registration campaigns will reduce last-minute support demand and expose application compatibility problems before enforcement.
February 1, 2027, is therefore a hard operational deadline. Organizations that inventory SMS-dependent accounts now, deploy suitable phishing-resistant credentials, and remove first-factor SMS dependencies can avoid lockouts while materially strengthening their Microsoft Entra ID security posture.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

