Microsoft Is Killing SMS Logins for Entra ID
Microsoft is putting an expiration date on one of the most common ways employees verify their identity. The company has started warning Entra ID customers that built-in SMS and voice authentication will be retired on February 1, 2027, with passkeys becoming the preferred replacement.

The transition starts much earlier. From September 1, 2026, Entra ID will begin automatically enabling passkey registration for users who currently rely on SMS or voice codes. Microsoft will prompt those users to set up a passkey when they sign in. And eventually, the prompts become impossible to ignore. Anyone who still hasn’t registered a passkey or another phishing-resistant authentication method by February 1 will hit a non-bypassable sign-in block until they complete the setup.
Microsoft’s reasoning is straightforward: SMS codes are increasingly easy for attackers to defeat through SIM swapping and adversary-in-the-middle phishing. Passkeys use public-key cryptography instead, with authentication tied to a trusted device, biometric method, or PIN.
Organizations that genuinely need SMS or voice authentication for compliance won’t be completely abandoned. They will have to use a customer-managed telecom provider through Microsoft’s Security Store, with pricing expected from September 18 and configuration becoming available October 30.
For administrators, this isn’t something to leave until January. Microsoft recommends checking the Authentication Methods Policy now, identifying users dependent on SMS or voice, and moving them to Microsoft Authenticator or hardware security keys before the September prompts begin.
