MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-21 · via BleepingComputer

Microsoft pushes Entra ID admins to switch to passkeys ahead of SMS sign-in shutdown

Image via BleepingComputer
Image via BleepingComputer

Microsoft is retiring SMS first-factor authentication for Entra ID workforce tenants starting February 2027, urging administrators to move users to phishing-resistant methods such as passkeys, FIDO2 keys, or QR code authentication. The company has already disabled SMS sign-in for new tenants and will stop offering native SMS and voice authentication after the cutoff. Passkeys are now rolling out as the default authentication experience for Entra ID, and affected users will be prompted to register one during their next multifactor authentication.

Expanded Detail

The transition timeline gives organizations roughly five months from the September 2026 passkey rollout to the February 2027 cutoff. Microsoft has already disabled SMS sign-in for newly created tenants and retired it for Free tier tenants in August. The change specifically targets workforce tenant authentication, leaving Azure AD B2C and External ID customer scenarios unaffected.

Administrators can identify affected users through a PowerShell scanner script, which requires Global Reader, Authentication Policy Administrator, or Security Reader roles. Organizations with legitimate phone-based authentication needs must contract third-party telecom providers through the Microsoft Security Store, as Microsoft will no longer offer native SMS or voice capabilities after the deadline.

Context

This shift could create friction for organizations with users who lack smartphones or technical comfort, potentially disrupting access to essential systems. However, it may also meaningfully reduce phishing and SIM-swapping attacks that have long exploited phone-based verification. Enterprises will need to budget for hardware keys or enrollment campaigns, and smaller organizations may feel the pressure most acutely as they adapt to new authentication workflows before the 2027 deadline.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Microsoft reminds admins to migrate Entra ID users to passkeys.” Browse more stories.