Microsoft reminds admins to migrate Entra ID users to passkeys

Microsoft’s Phasing Out SMS-Based Authentication: What You Need to Know

As of February 2027, Microsoft will retire SMS-based sign-in for its Entra ID service, a move that affects administrators who use this method as a first-factor authentication. To avoid disruptions, admins must migrate users to alternative phishing-resistant methods, such as passkeys, which are now the default authentication experience for Entra ID.

Microsoft has been preparing its customers for this change by announcing the retirement of SMS sign-in in July and providing detailed guidance on deploying and managing phishing-resistant passwordless authentication. The company’s reasoning behind this decision is clear: SMS-based sign-in poses significant risks due to phishing, fraud, and account compromise threats. By phasing out this method, Microsoft aims to improve security for its users.

Admins with Entra ID workforce tenants need to act quickly as the retirement process only applies to these scenarios, not Azure AD B2C or External ID customer identity scenarios. To identify users who still rely on SMS-based sign-in, admins can run a PowerShell script provided by Microsoft. Organizations that must use phone-based authentication will have to configure third-party telecom providers through the Security Store.

The transition to passkeys is already underway, with users enabled for SMS or voice authentication automatically being switched over as the rollout reaches each organization. When they next perform multifactor authentication, users will be prompted to register a passkey, which will become their default method of signing in. This change marks a significant shift towards passwordless authentication and phishing-resistant methods.

As Entra ID admins begin this migration process, it’s essential to remember that SMS sign-in will no longer be an option after February 2027. To ensure seamless continuity, administrators should prioritize migrating users to supported alternatives based on their specific scenarios. Microsoft’s decision to phase out SMS-based authentication is a proactive measure aimed at enhancing security for its users and promoting more robust passwordless solutions.

To avoid disruptions in your organization, it’s crucial to take immediate action and migrate users to phishing-resistant methods like passkeys or other Entra ID-supported authentication options. This will not only ensure compliance with Microsoft’s new policies but also provide an added layer of protection against potential threats.


Source: Bleeping Computer — 2026-09-21