HomeSecurityMicrosoft Entra ID: No more SMS - Switch to passkeys

Microsoft Entra ID: No more SMS – Switch to passkeys

Microsoft is warning administrators of organizations using Microsoft Entra ID to start transitioning users to more secure, phishing-resistant authentication methods early. The company has already planned significant changes to how accounts are signed in, with SMS and voice calls being retired as native phone authentication methods starting February 1, 2027.

Microsoft Login ID

The change primarily affects Entra ID workforce tenants and means organizations that still rely on phone numbers for initial user identification should prepare immediately. Microsoft’s goal is to transition to technologies that offer greater resilience against modern phishing and credential theft techniques.

See also: NCSC recommends passkeys as default authentication method

Why SMS is no longer considered secure enough

SMS has been an easy way to verify a user's identity for years. However, the technology now has several vulnerabilities, as attackers can leverage phishing, social engineering, and SIM swapping to gain access to verification codes.

The problem becomes even greater when a phone number is used as a primary entry point to corporate accounts. A successful attack can allow an attacker to bypass a critical layer of protection and gain access to corporate data, applications, and services.

For this reason, Microsoft promotes methods that do not rely on passwords that can be intercepted or tricked into sending a phishing message.

Passkeys at the heart of the transition

One of the main alternatives proposed by Microsoft is passkeys, which allow for identification without the traditional use of passwords.

Instead of a user typing in a password that can be stolen, the process relies on cryptographic keys and a check performed on their device. This approach makes phishing attacks significantly, as there is no password that the user can reveal on a fake page.

Microsoft has already started rolling out passkeys as the default authentication option in Entra ID. As the process expands to organizations, users using SMS or voice calling may be prompted to enter a passkey during the next multi-factor authentication process.

Multi-factor authentication and passkeys

Passkeys are not the only solution

Organizations are not limited to a single option. Entra ID also supports FIDO2 security keys, QR code authentication, and other methods, depending on each organization's needs and infrastructure.

FIDO2 security keys can be a particularly useful solution for corporate environments where strong access control is required, while other methods can be utilized in different work scenarios.

See also: Microsoft fixes critical flaw in Entra ID

Choosing the right technology shouldn't be based solely on security. Administrators also need to consider device compatibility, employee experience, and the ability of IT to support the new process.

What should administrators do now?

Microsoft recommends that organizations identify users who still rely on SMS or voice calls and migrate them to supported alternatives.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

For this purpose, there are control tools, including the PowerShell script "Entra SMS/Voice Policy Scanner", which can be used by administrators with specific roles, such as Global Reader, Authentication Policy Administrator or Security Reader.

This control is important because in a large organization there may be dozens or thousands of accounts still relying on legacy methods. Transitioning is not just about enabling a new setting, but also about informing users so they know how to connect in the future.

What changes from February 2027

Microsoft has made it clear that it will stop providing its own telecommunications services for SMS and voice authentication in Entra ID as of February 1, 2027. This means that organizations will no longer be able to rely on these methods as native options for the service.

The change applies even to organizations using the Choose Your Own Telephony Providerwhen it comes to using SMS or voice as the first sign-in factor. However, organizations that are required to use phone authentication can consider third-party solutions through the Microsoft Security Store.

See also: Microsoft Teams: More control over dangerous files

Microsoft Entra ID: No more SMS - Switch to passkeys

A broader shift in corporate security

The removal of SMS is not just a configuration change in Entra ID. It reflects the overall shift in corporate security towards passwordless and phishing-resistant authentication.

For businesses, the period until February 2027 offers time for testing, training, and a gradual transition. The earlier accounts that rely on SMS and voice are identified, the lower the risk of access issues when the old methods are no longer supported.

The change is therefore an opportunity for organizations to completely rethink their identification policy and reduce reliance on methods that are now considered more vulnerable to modern phishing attacks.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS