MC1448374: Microsoft Entra ID Retires SMS First-Factor Sign-In for Free Tenants

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
75
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSecurity TeamsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
SMS first-factor sign-in will be retired for Entra ID Free tenants on August 11, 2026, meaning affected admins must identify users reliant on this method and migrate them to other options. This is a mandatory change to authentication policy with potential sign-in disruption if unmanaged. Urgency remains high since the deadline has just passed, and admins need immediate action if users are blocked. Implementation includes auditing, updating policies, and user communication.
80
🛡️ Admin Impact
65
👥 User Impact
75
Urgency
70
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

SMS first-factor sign-in is retired for Entra ID Free tenants from 11 August 2026. Users must switch to another authentication method to keep access.
👥

END USERS

Users cannot sign in using SMS only and need another method set up.
🛡️

IT ADMINS

Identify affected users, communicate the change, and ensure alternative sign-in methods are registered before retirement.
📅

ROLLOUT TIMELINE

Start:
11 August 2026

📢 Official Microsoft Message Center Announcement


(Updated) Microsoft Entra ID: Retirement of SMS first-factor sign-in for Entra ID Free tenants
Message ID: MC1448374

Updated August 10, 2026: We have updated the timeline. We apologize for any inconvenience. 

[What and why]

Microsoft will retire SMS first-factor sign-in for Microsoft Entra ID Free tenants on August 11, 2026, due to increased fraudulent activity targeting this authentication method.

SMS first-factor sign-in allows users to sign in using only a registered phone number and a one-time passcode (OTP) sent by SMS, without entering a username or password. Because this sign-in method relies solely on a registered phone number and SMS-delivered passcode, it is more susceptible to abuse and account compromise than phishing-resistant authentication methods. 

This change applies only to SMS first-factor sign-in. SMS used as a multifactor authentication (MFA) method is not affected. Users can continue receiving SMS verification codes as an additional authentication factor after completing their primary sign-in.

[Rollout schedule]

  • Beginning August 11, 2026, SMS first-factor sign-in will no longer be supported for Microsoft Entra ID Free tenants.

[Impact on your organization]

Who is affected

  • Microsoft Entra ID Free tenants with SMS first-factor sign-in enabled
  • Users who rely exclusively on SMS first-factor sign-in

Platforms and services

  • Microsoft Entra ID
  • SMS first-factor passwordless sign-in (SignInNoPassword)

What will happen

  • Users in Microsoft Entra ID Free tenants will no longer be able to use SMS as a first-factor sign-in method.
  • Attempts to sign in using only a registered phone number and SMS one-time passcode will be blocked.
  • Users who have another registered authentication method can continue signing in using that method.
  • SMS as a multifactor authentication method is not affected.
  • All other registered authentication methods remain available.
  • Users who rely exclusively on SMS first-factor sign-in must register and use another authentication method before the retirement date.

[Action required and recommendations]

If your organization has users relying on SMS first-factor sign-in, we recommend that you:

  • Identify users currently using SMS first-factor sign-in.
  • Ensure affected users register an alternative authentication method before August 11, 2026.
  • Communicate this change to affected users to help prevent sign-in disruptions.
  • Migrate users to passkeys or other phishing-resistant authentication methods where possible.
  • Review authentication method policies and remove dependencies on SMS first-factor sign-in.

Learn more

[Compliance considerations]

QuestionAnswer
Does this change modify how users access Microsoft 365 resources or services?Yes. Users in affected Microsoft Entra ID Free tenants will no longer be able to sign in using SMS as their first-factor authentication method and must use another registered sign-in method.
Does this change require admin action to maintain user access?Yes. Administrators should identify users who rely on SMS first-factor sign-in and ensure those users register an alternative authentication method before the retirement date to avoid sign-in disruptions.
Does this change affect authentication or access management policies?Yes. Organizations that currently depend on SMS first-factor sign-in may need to review and update their authentication policies to remove dependencies on this retired authentication method.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update