MC1474104: Microsoft Entra ID Retires SMS First-Factor Sign-In and Requires Migration to Phishing-Resistant Methods

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
64
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSecurity TeamsCompliance TeamsAzure AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
The announcement updates the timeline and clarifies that SMS first-factor sign-in will retire on 1 February 2027. Admins must identify dependent users, migrate them to phishing-resistant options, update authentication policies and communicate changes to prevent login failures. This affects authentication governance and requires policy reviews, user outreach and alternative method registration. User disruption will occur if changes are not implemented before the deadline.
80
🛡️ Admin Impact
55
👥 User Impact
45
Urgency
75
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Microsoft will retire SMS first-factor sign-in in Entra ID from February 2027. Plan to move users to stronger authentication methods to avoid sign-in issues.
👥

END USERS

Users relying on SMS to sign in will need another registered authentication method before February 2027.
🛡️

IT ADMINS

Identify affected users, migrate them to supported methods, and update authentication policies before the retirement date.
📅

ROLLOUT TIMELINE

Upcoming:
February 2027

📢 Official Microsoft Message Center Announcement


Microsoft Entra ID: Follow-up on SMS first-factor sign-in retirement and upcoming changes
Message ID: MC1474104

[What and why]

To improve security and reduce reliance on vulnerable authentication methods, Microsoft is continuing the retirement of SMS first-factor sign-in in Microsoft Entra ID. Microsoft recommends phishing-resistant authentication methods, such as passkeys, as the preferred sign-in experience because they help reduce the risk of phishing, fraud, and account compromise associated with phone-based authentication.

Microsoft previously retired SMS first-factor sign-in for Microsoft Entra ID Free tenants and stopped enabling SMS sign-in for newly created tenants. This communication provides an update on the next phase of the retirement effort and actions organizations should take to prepare. Microsoft has announced previous retirement actions in Message Center posts MC1426371, MC1448374, and MC1449181.

This retirement applies only to Microsoft Entra ID workforce tenant authentication scenarios. It does not apply to Azure AD B2C or Microsoft Entra External ID customer identity scenarios.

[Rollout schedule]

  • Worldwide and GCC: Beginning February 1, 2027, SMS first-factor sign-in will be retired for Microsoft Entra ID tenants.

[Impact on your organization]

Who is affected

Organizations that:

  • Allow users to sign in using SMS first-factor authentication.
  • Rely on SMS first-factor sign-in as a primary authentication method.

Platforms and services

  • Microsoft Entra ID
  • SMS first-factor passwordless sign-in (SignInNoPassword)

What will happen

After February 1, 2027:

  • Users will no longer be able to authenticate by using their phone number and an SMS one-time passcode as a primary sign-in method.
  • Existing SMS first-factor sign-in configurations will no longer be honored.
  • Management and configuration experiences for SMS first-factor sign-in will be removed from Microsoft administration experiences.
  • Attempts to sign in by using a registered phone number and SMS one-time passcode will be blocked.
  • Users who have another registered authentication method can continue signing in.
  • Organizations that do not migrate affected users before the retirement date may experience sign-in disruptions.

[Action required and recommendations]

If your organization uses SMS first-factor sign-in, complete the following actions before February 1, 2027:

  • Identify users currently using SMS first-factor sign-in.
  • Ensure affected users register an alternative authentication method before February 1, 2027.
  • Communicate this change to affected users to prevent sign-in disruptions.
  • Migrate users to passkeys or other phishing-resistant authentication methods.
  • Review authentication method policies and remove dependencies on SMS first-factor sign-in.
  • Review available authentication alternatives and migration guidance.

The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method. If your organization currently uses SMS sign-in for first-factor authentication, migrate users to supported alternatives based on their scenarios. Alternatives include passkeys, QR code authentication, FIDO2 security keys, and other authentication methods supported by Microsoft Entra ID.

Learn more

[Compliance considerations]

QuestionAnswer
Does this change modify how users access Microsoft 365 resources or services?Users who currently rely on SMS first-factor authentication must use another registered authentication method after February 1, 2027.
Does this change require admin action to maintain user access?Administrators should identify affected users and ensure alternative authentication methods are registered before the retirement date.
Does this change affect Conditional Access policies?Organizations may need to review authentication-related policies and dependencies that currently rely on SMS first-factor sign-in.
Does this change alter how admins can monitor, report on, or demonstrate compliance activities?Management and configuration experiences for SMS first-factor sign-in will be removed from Microsoft Entra administration experiences.
Does the change include an admin control and can it be controlled through Entra ID group membership?Existing SMS first-factor sign-in configurations will no longer be honored after the retirement date, requiring administrators to transition users to supported authentication methods.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update