Cut-paper illustration of a blue paper smartphone showing an SMS bubble with a six-digit code, red paper scissors snipping the bubble in half, beside a paper shield badge holding a brass key.

Microsoft used its Message Center this week to remind admins of something with a hard date on it: SMS first-factor sign-in for Entra ID workforce tenants retires on February 1, 2027. After that, Entra stops honoring phone-number-and-code as a primary sign-in method, and the related controls disappear from the admin portals.

This isn't a "consider migrating" nudge. It's a retirement with a blocking prompt at the end: users who still depend on Microsoft-delivered SMS or voice and have no other method registered will hit a wall at sign-in. The fix is a migration project, and the unglamorous first step is finding out who still signs in with SMS.

What's actually retiring (it's two things)

Microsoft is ending two related but distinct things, and conflating them causes bad planning:

  1. SMS as a first-factor sign-in method. Signing in with just a phone number plus a texted code — the thing originally built for frontline workers without passwords. Retires February 1, 2027 for workforce tenants.
  2. Microsoft-provided telecom delivery for SMS and voice. Microsoft stops being your SMS/voice carrier. This retires in stages: February 1, 2027 for most users, July 1, 2027 for Global Admins and external users. If you genuinely must keep SMS/voice, you can bring your own telephony provider through the Microsoft Security Store (configuration experience available from October 30, 2026) — and you pay the carrier bill.

Already done: SMS first-factor was retired for Entra ID Free tenants back in August, and new tenants don't get it enabled at all. This deadline just finishes the job for existing paid workforce tenants.

Date What happens
Sep 1, 2026 Passkeys become the default auth experience; SMS/voice users auto-enabled for passkeys and nudged to register
Oct 30, 2026 Bring-your-own telephony provider configuration opens in Entra
Feb 1, 2027 SMS first-factor sign-in retires; Microsoft-delivered SMS/voice ends for most users
Jul 1, 2027 Microsoft-delivered SMS/voice ends for Global Admins and external users

Scope note: this covers Entra ID workforce tenants (worldwide and US Government Community Cloud). It does not touch Azure AD B2C or Entra External ID customer-facing scenarios.

Why SMS finally lost

No hype needed here — the reasons are mechanical. SMS codes can be phished and replayed in real time, SIM swapping and number reassignment keep working, and telecom interception never went away. Microsoft's threat intel has been blunt that AI-assisted phishing made the phishable methods untenable. Passkeys, by contrast, are origin-bound public-key cryptography: the private credential never leaves the device, and there's nothing to replay. That's the whole argument, and it's a good one.

The migration checklist

Treat this as an identity migration, not a policy toggle. Here's the order I'd do it in:

  1. Inventory who still depends on SMS. Use Entra sign-in logs filtered by authentication method, the authentication methods usage reports, and Microsoft's own PowerShell script for identifying SMS/voice users. Export the list. This is your migration backlog.
  2. Segment the list. Frontline/shared-device workers, standard knowledge workers, executives, admins, and service-adjacent accounts each get a different replacement. Don't assign one method to everyone.
  3. Pick the replacement per segment. Passkeys for most users (device-bound where you manage the device, synced where you don't). Windows Hello for Business where it's already deployed. FIDO2 security keys for admins and high-risk accounts. QR code + PIN for frontline or shared-device scenarios.
  4. Pilot with authentication strengths. Build a Conditional Access authentication strength that requires phishing-resistant methods, apply it to the pilot group, and watch the sign-in logs for a week before widening.
  5. Run the registration campaign. Since September 1, 2026, users enabled for SMS/voice are auto-enabled for passkeys and get Microsoft-managed nudges at MFA sign-in. Ride that wave instead of fighting it — but track registration completion per segment, because nudges don't reach everyone.
  6. Decide on BYO telephony deliberately. If some population truly can't move off SMS/voice, price out a customer-managed provider via the Security Store before October's config window. "We'll figure it out in January" is how you end up paying emergency telecom rates.
  7. Remove SMS from the Authentication Methods policy before the deadline. Then verify with the same reports from step 1. The goal is zero SMS-dependent accounts before February, not a scramble during it.

Gotchas that bite MSPs

  • Shared devices and frontline workers are where SMS sign-in lived. QR code auth exists for exactly this population — evaluate it before declaring the migration "done except for…"
  • Users without corporate smartphones can't do device-bound passkeys on hardware they don't have. FIDO2 keys are cheap; budget for them early.
  • Recovery flows tied to phone numbers break silently. Audit your SSPR and helpdesk verification procedures for SMS assumptions.
  • Conditional Access policies that assume SMS need rewriting, not just the auth methods policy.
  • Intune-managed registration: if you push Authenticator or manage device enrollment, coordinate the app assignments with the registration campaign so users aren't prompted for something not yet deployed.

The boring truth

There's nothing novel about this migration. It's inventory, segmentation, piloting, and verification — the same shape as every decommission project. The only thing special is the deadline is real and the blocking behavior at the end is not negotiable. Start with the sign-in logs this week, and February is a non-event. Start in January, and it's an incident.

Sources