Microsoft Entra ID: Follow-up on SMS first-factor sign-in retirement and upcoming changes

🚨 The Signal: Microsoft is retiring SMS first-factor sign-in for Entra ID workforce tenants by February 1, 2027. This change enhances security by removing a vulnerable authentication method, pushing organisations towards phishing-resistant alternatives like passkeys.

The Impact

Organisations using SMS as a primary sign-in method are affected, increasing the risk of account compromise if not migrated to stronger authentication.

  • Security Teams: Risk of account compromise if vulnerable SMS authentication persists.
  • Admins: Effort required to migrate users to phishing-resistant authentication methods.
  • End Users: Will need to adopt new, more secure sign-in methods.
  • Organisations: Improved security posture by eliminating a weak authentication factor.

The Action

  1. Identify users currently configured for SMS first-factor sign-in: Navigate to Entra Admin Center > Protection > Authentication methods > Policies > SMS.
  2. Communicate the change to affected users and provide guidance on adopting stronger authentication methods.
  3. Enable and configure phishing-resistant authentication methods (e.g., FIDO2 Security Keys, Windows Hello for Business, Microsoft Authenticator passwordless) via Entra Admin Center > Protection > Authentication methods > Policies.
  4. Migrate users from SMS first-factor to phishing-resistant authentication methods before February 1, 2027.
  5. Monitor authentication method usage and enforce phishing-resistant methods where possible.

Domain: Entra · Impact: high · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907