Microsoft Entra ID: Review and disable SMS first-factor sign-in if it is not needed

🚨 The Signal: Microsoft is urging tenants to disable SMS first-factor sign-in due to high fraud risk. This method allows login with only a phone number and SMS OTP, bypassing stronger authentication and MFA, making it a significant vulnerability.

The Impact

Organizations with SMS first-factor sign-in enabled face a critical security risk from phishable authentication.

  • Frontline workers using SMS first-factor sign-in are at high risk of account compromise.
  • Organizations with SMS first-factor enabled are vulnerable to significant fraud spikes.
  • Tenants not disabling this feature may have Microsoft block it due to detected fraud.
  • Users relying solely on SMS first-factor will lose their sign-in method.

The Action

  1. Review current authentication methods in Microsoft Entra ID to identify SMS first-factor usage.
  2. Navigate to Microsoft Entra admin center > Protection > Authentication methods > Policies.
  3. Select 'SMS' and ensure 'Enable for users' is set to 'No' or scoped to 'None'.
  4. Communicate changes to affected users and assist with transitioning to stronger authentication methods (e.g., Microsoft Authenticator).
  5. Monitor sign-in logs for any residual SMS first-factor attempts post-disabling.

Domain: Entra · Impact: high · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907