Microsoft reminds admins to migrate Entra ID users to passkeys

A critical deadline is looming for organizations that rely on Microsoft Entra ID for user authentication. In a stark reminder, Microsoft has emphasized the need to migrate users to phishing-resistant methods, such as passkeys, by February 2027. This change will leave SMS and voice-based sign-in options unavailable, potentially disrupting services.

The retirement of SMS first-factor sign-in is not new; it was initially rolled out for free tenants in August due to increased risks of phishing, fraud, and account compromise. However, this latest warning serves as a timely reminder that the deadline for all organizations stands at February 2027. Those who fail to act will see their users unable to complete multifactor authentication or sign in using SMS or voice.

So what’s driving this change? Microsoft has been pushing the adoption of phishing-resistant methods like passkeys, which offer significant security benefits over traditional password-based systems. In fact, passkeys are now set to become the default authentication experience for Entra ID enterprise identity service users. As part of this shift, Microsoft is automatically enabling passkey registration for users who still rely on SMS or voice.

To help administrators prepare for this change, Microsoft has provided detailed guidance on deploying and managing phishing-resistant passwordless authentication in Entra ID. Admins can find more information on the dedicated documentation page shared by Microsoft. For those with access to PowerShell scripts, there’s an additional tool available: the Entra SMS/Voice Policy Scanner script.

However, for organizations that still rely heavily on phone-based authentication, a different solution is required. In these cases, administrators will need to configure third-party telecom providers through the Microsoft Security Store. This change may seem daunting, but it’s essential to future-proof against increasingly sophisticated attacks.

As we navigate this transition, one thing is clear: migrating to phishing-resistant methods like passkeys should be top priority for organizations using Entra ID. With only a few months left until the deadline, administrators must act swiftly to avoid potential disruptions and ensure their users can continue to sign in securely.

Practically speaking, if you’re an administrator responsible for user authentication, now is the time to prioritize migration to passkeys or alternative phishing-resistant methods. Microsoft has made it clear that SMS and voice-based sign-in options will no longer be available after February 2027. By taking proactive steps to update your security posture, you’ll not only future-proof your organization but also safeguard against the evolving threats landscape.


Source: Bleeping Computer — 2026-09-21