"The retirement of SMS sign-in as a first-factor authentication method applies even when you use Choose Your Own Telephony Provider to continue using SMS or voice as multifactor authentication method," Microsoft said in a Microsoft 365 Message Center update on Friday.
February 1, 2027: a fixed cutover for Microsoft-provided SMS and voice
Microsoft is giving administrators a clear deadline: on February 1, 2027 it will retire Microsoft-provided telecom delivery for SMS and voice authentication and will no longer offer SMS and voice as a native Microsoft Entra capability. After that date, users will not be able to use SMS or voice to complete multifactor authentication and sign in to their accounts when relying on Microsoft’s built-in telephony delivery.
The company has already removed SMS first-factor sign-in for Microsoft Entra ID Free tenants in August and no longer enables SMS sign-in for newly created tenants. The retirement applies to Microsoft Entra ID workforce tenant authentication scenarios only; it does not affect Azure AD B2C or Microsoft Entra External ID customer identity scenarios.
Passkeys: the new default for Entra ID
In July, Microsoft announced that passkeys will start rolling out as the default authentication experience for the Entra ID enterprise identity service "starting this month." According to Microsoft, "as the rollout reaches each organization, users enabled for SMS or voice authentication will automatically be enabled for passkeys, and the next time they perform multifactor authentication, they'll be prompted to register a passkey."
That automatic enabling is designed to accelerate conversion away from SMS and voice to phishing-resistant authentication. Microsoft has published detailed guidance on deploying and managing phishing-resistant passwordless authentication on a dedicated documentation page for Entra ID.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildSupported alternatives: QR codes, FIDO2, passkeys, and third-party telecom
Administrators are asked to migrate Entra ID users to phishing‑resistant methods to avoid sign‑in disruptions. Microsoft lists passkeys among the supported defaults and cites alternatives including QR code authentication, FIDO2 security keys, and other Entra ID–supported authentication methods.
For organizations that must retain phone-based authentication, Microsoft requires configuration of third‑party telecom providers through the Microsoft Security Store. The company emphasizes that even if an organization uses the Choose Your Own Telephony Provider option, the retirement of SMS as a first‑factor remains in effect.
Admin tools: finding who still uses SMS or voice
Microsoft has provided tooling to help operators locate accounts still tied to SMS or voice authentication. Administrators who hold the Global Reader, Authentication Policy Administrator, or Security Reader roles can run the Entra SMS/Voice Policy Scanner PowerShell script to identify users configured for SMS or voice authentication.
That step is positioned as a practical first move: find the accounts, assess the scenarios where phone-based verification remains in use, and then plan migration to an alternative supported by Entra ID or to a third‑party telephony provider when phone delivery cannot be avoided.
How technologists, procurement leaders, and end users should respond
- Technologists and security teams: Use the Entra documentation and the PowerShell scanner to inventory SMS/voice dependencies now and prioritize conversion to passkeys, QR codes, or FIDO2 where possible to maintain phishing resistance and uninterrupted sign‑in.
- Procurement and telecom decision makers: If your environment requires phone-based factors, prepare to configure a third‑party telecom provider via the Microsoft Security Store; Microsoft will stop offering its own SMS/voice delivery on February 1, 2027.
- End users and help desks: Expect a prompt to register a passkey the next time you perform multifactor authentication once your organization’s rollout reaches you; after February 1, 2027, SMS and voice will no longer work as a native Microsoft Entra option for workforce tenants.
Microsoft’s timeline and defaults place a clear operational burden on administrators: inventory who still relies on SMS or voice, choose and deploy phishing‑resistant alternatives, and, where necessary, engage third‑party telecom providers before the 2027 deadline. The company has bundled guidance and a scanning tool to help; the remaining question is how quickly large, diverse tenant estates can complete the migration without disrupting user access.
Source: Microsoft reminds admins to migrate Entra ID users to passkeys — BleepingComputer




