Microsoft Entra: Prepare for Microsoft to disable unused or unsuccessful SMS first-factor sign-in
🚨 The Signal: Microsoft will automatically disable SMS first-factor sign-in in Entra tenants with no recent successful usage due to high fraud risk. This enhances security by removing a phishing-susceptible authentication method.
The Impact
Frontline workers and other users relying on SMS first-factor sign-in are at risk of sign-in disruption, but overall tenant security posture is improved.
- Frontline workers: May lose access if SMS first-factor is their only method.
- Admins: Need to verify usage and alternative authentication methods.
- Security teams: Benefit from reduced attack surface and improved authentication strength.
The Action
- Review Entra sign-in logs for SMS first-factor activity: Entra admin center > Identity > Monitoring & health > Sign-in logs, filter by 'Authentication method' = 'SMS'.
- Identify users currently relying on SMS first-factor sign-in.
- Ensure affected users have alternative, stronger authentication methods registered (e.g., Microsoft Authenticator, FIDO2).
- Communicate changes to users who may be impacted by the disablement.
- If SMS first-factor is still required, ensure successful sign-ins occur within 30 days to prevent automatic disablement.
Domain: Entra · Impact: high · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907