Microsoft Entra ID: Review and disable SMS first-factor sign-in if it is not needed
🚨 The Signal: Microsoft is urging tenants to disable SMS first-factor sign-in due to high fraud risk. This method allows login with only a phone number and SMS OTP, bypassing stronger authentication and MFA, making it a significant vulnerability.
The Impact
Organizations with SMS first-factor sign-in enabled face a critical security risk from phishable authentication.
- Frontline workers using SMS first-factor sign-in are at high risk of account compromise.
- Organizations with SMS first-factor enabled are vulnerable to significant fraud spikes.
- Tenants not disabling this feature may have Microsoft block it due to detected fraud.
- Users relying solely on SMS first-factor will lose their sign-in method.
The Action
- Review current authentication methods in Microsoft Entra ID to identify SMS first-factor usage.
- Navigate to Microsoft Entra admin center > Protection > Authentication methods > Policies.
- Select 'SMS' and ensure 'Enable for users' is set to 'No' or scoped to 'None'.
- Communicate changes to affected users and assist with transitioning to stronger authentication methods (e.g., Microsoft Authenticator).
- Monitor sign-in logs for any residual SMS first-factor attempts post-disabling.
Domain: Entra · Impact: high · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907