Microsoft Sets 2027 Deadline for SMS Authentication Retirement in Entra ID
AI-generated from multiple sources. Verify before acting on this reporting.
REDMOND, Wash. (Sept. 21) — Microsoft has issued a formal directive to enterprise administrators requiring the migration of Entra ID users to phishing-resistant authentication methods before the company retires SMS as a first-factor sign-in option in February 2027.
The technology giant announced on Sunday that organizations must transition away from text message-based verification, which relies on phone numbers, to more secure alternatives such as passkeys. The move is designed to eliminate vulnerabilities associated with SIM swapping, social engineering, and other fraud tactics that have increasingly targeted legacy authentication protocols.
Microsoft stated that the retirement of SMS first-factor authentication is a necessary step to mitigate the rising risks of account compromise and phishing attacks. As cybercriminals have refined methods to intercept or bypass text-based codes, the software maker determined that continuing to support SMS as a primary login mechanism poses an unacceptable security threat to enterprise environments.
Administrators are urged to begin the migration process immediately to ensure continuity of service. The company warned that failure to adopt phishing-resistant methods prior to the February 2027 cutoff could result in significant sign-in disruptions for affected users. Once the deadline passes, accounts relying solely on SMS for initial authentication will be unable to access Entra ID-protected resources until a new method is provisioned.
Passkeys, which utilize biometric data or device-specific hardware keys, are being positioned as the primary replacement. Unlike SMS codes, passkeys do not transmit sensitive credentials over cellular networks and are cryptographically bound to the user's specific device, rendering them immune to interception via phone number theft or network spoofing.
The announcement underscores a broader industry shift toward stronger identity verification standards. While Microsoft has set the 2027 timeline for its own ecosystem, the deadline places significant pressure on IT departments to audit their current authentication stacks and train users on new login procedures well in advance of the changeover.
Microsoft emphasized that the transition is not merely a technical upgrade but a critical security imperative. The company noted that SMS-based authentication has become a primary vector for business email compromise and unauthorized access incidents over the past several years.
As the February 2027 deadline approaches, questions remain regarding the readiness of smaller organizations with limited IT resources to execute the migration without service interruption. Additionally, it is unclear how Microsoft will handle legacy systems or third-party applications that may still depend on SMS integration for identity verification. Administrators are advised to review their tenant configurations and begin planning the transition to ensure all users are protected before the retirement date takes effect.