MikhbarMIKHBAR
Robotics

Microsoft urges Entra ID admins to migrate to passkeys for SMS retirement

Microsoft has issued a warning to administrators that Entra ID users must migrate to phishing‑resistant authentication methods such as passkeys before SMS sign‑in is retired in February 2027. The change will affect all workforce tenant scenarios and requires prompt action to avoid sign‑in disruptions.

Microsoft urges Entra ID admins to migrate to passkeys for SMS retirement

Microsoft warns admins ahead of SMS sign‑in retirement

Microsoft has reminded administrators to migrate Entra ID users to phishing‑resistant methods such as passkeys before the company retires SMS first‑factor sign‑in in February 2027. The warning appears in a Microsoft 365 Message Center update, urging organizations to act now to avoid sign‑in disruptions. The retirement will affect all workforce tenant scenarios, but not Azure AD B2C or Microsoft Entra External ID. [Microsoft 365 Message Center update](https://admin.microsoft.com/#/MessageCenter/:/messages/MC1474104)

Starting in August, SMS first‑factor sign‑in was already disabled for Microsoft Entra ID Free tenants, and new tenants can no longer enable it. The change applies even if an organization uses Choose Your Own Telephony Provider to keep SMS or voice as a multifactor method. Admins should verify that every user is on a phishing‑resistant alternative, such as QR code authentication, FIDO2 security keys, or other supported methods. For detailed deployment guidance, see this dedicated documentation page. [this dedicated documentation page](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

Passkeys become the default for Entra ID

In July, Microsoft announced that passkeys will roll out as the default authentication experience for the Entra ID enterprise identity service beginning this month. As the rollout reaches each organization, users who were previously enabled for SMS or voice authentication will automatically be switched to passkeys, and the next time they perform multifactor authentication they will be prompted to register a passkey. Microsoft said the shift is designed to simplify sign‑in while strengthening security. [Microsoft said](https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/)

The transition sets the stage for the final retirement of Microsoft‑provided telecom delivery for SMS and voice authentication on February 1, 2027. After that date, SMS and voice will no longer be offered as a native Microsoft Entra capability, reinforcing the need for phishing‑resistant passwordless options. Organizations can find step‑by‑step instructions on the dedicated documentation page. [this dedicated documentation page](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

Migration steps and available alternatives

Admins with Global Reader, Authentication Policy Administrator, or Security Reader roles can locate users still relying on SMS or voice authentication by running the Entra SMS/Voice Policy Scanner PowerShell script. This tool helps identify accounts that need migration before the deadline. If your organization currently uses SMS sign‑in for first‑factor authentication, Microsoft advises migrating users to supported alternatives based on their specific scenarios. [the Entra SMS/Voice Policy Scanner PowerShell script](https://github.com/microsoft/entra-sms-voice-usage-analyzer)

Supported alternatives include QR code authentication, FIDO2 security keys, and other Entra ID‑supported methods. All users must be switched to a phishing‑resistant method before February 2027, because SMS and voice will no longer be usable for multifactor authentication. The documentation page provides checklists and best practices for a smooth transition. [this dedicated documentation page](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

Tools and resources for administrators

The Entra SMS/Voice Policy Scanner PowerShell script is available for download and can be executed from the admin console. It scans tenant configurations and reports any active SMS or voice policies, giving admins a clear view of what needs to be changed. Using the script early avoids last‑minute disruptions and ensures compliance with Microsoft’s security roadmap. [the Entra SMS/Voice Policy Scanner PowerShell script](https://github.com/microsoft/entra-sms-voice-usage-analyzer)

For organizations that still require phone‑based authentication, third‑party telecom providers must be configured through the Microsoft Security Store. Meanwhile, security leaders are encouraged to build a security blueprint for AI‑powered attacks. Join Mikko Hyppönen and experts from the NFL, CHANEL, and Atlassian for a two‑hour digital summit on how AI‑speed threats are changing defense strategies. Save your seat via the security blueprint link. [Build your security blueprint for AI-powered attacks](https://hubs.li/Q04x67m50) [Save your seat](https://hubs.li/Q04x67m50)

Broader Microsoft security updates

Microsoft also addressed critical vulnerabilities this week, patching max‑severity code execution and privilege escalation flaws that were being exploited in the wild. The security update reduces the attack surface for Entra ID environments and should be applied promptly. For more details, read Microsoft patches max severity code execution, privilege escalation flaws. [Microsoft patches max severity code execution, privilege escalation flaws](https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/)

In addition, Microsoft announced that Microsoft 365 Companion apps will be retired in December, affecting users who rely on those auxiliary tools. The retirement aligns with the company’s broader effort to streamline its productivity suite and improve security posture. For the full announcement, see Microsoft to retire Microsoft 365 Companion apps in December. [Microsoft to retire Microsoft 365 Companion apps in December](https://www.bleepingcomputer.com/news/microsoft/microsoft-to-retire-microsoft-365-companion-apps-in-december/)

Preparing for the upcoming changes

The timeline for the SMS retirement is clear: Free tenants lost SMS first‑factor support in August, passkeys are now the default, and the final cut‑off for telecom delivery arrives on February 1, 2027. Organizations that have not yet migrated risk service interruptions and reduced security resilience. Acting now ensures a seamless transition and keeps user access secure.

Admins should review the dedicated documentation page, run the Entra SMS/Voice Policy Scanner script, and verify that all users are enrolled in a phishing‑resistant method such as passkeys or FIDO2 keys. Configuring any required third‑party telecom providers through the Microsoft Security Store and staying informed about AI‑driven threats will further harden the environment. The combined steps provide a comprehensive roadmap for compliance and future‑proof security.

Sources