Review and Disable SMS First-Factor Sign-In If It Is Not Needed
If your organization still allows users to sign in using only an SMS code, it’s time to review and likely disable that capability. Microsoft is actively retiring SMS-based authentication in Entra ID due to well-documented security weaknesses, and SMS first-factor sign-in for Entra ID Free tenants was retired on August 11, 2026.
Why SMS First-Factor Sign-In Is a Risk
SMS first-factor sign-in lets a user authenticate using just a phone number and a one-time passcode (OTP) delivered by text—no username or password required. This design is inherently weaker than modern, phishing-resistant methods because it:
- Relies on the public telecom network, which is vulnerable to SIM-swapping, message interception, and number reassignment attacks.
- Provides significantly weaker protection against phishing and account compromise than passkeys or the Microsoft Authenticator app.
- Has been shown to be materially less effective at repelling compromise (Microsoft reported SMS was ~40% less effective than the Authenticator app in 2024).
Because of rising fraud and AI-assisted phishing, Microsoft has positioned SMS and voice as legacy methods and is making passkeys the default authentication experience.
Microsoft's Retirement Timeline (What's Changing)
Two related but distinct changes are underway:
- SMS first-factor sign-in (Free tenants): Retired on August 11, 2026 due to fraud risks. SMS used for multifactor authentication (MFA) remains unaffected by this specific change.
- Microsoft-provided SMS and voice for MFA: Starting September 1, 2026, passkeys become the default; on February 1, 2027, Microsoft-provided SMS and voice delivery is fully retired. Users whose only MFA method is SMS or voice will face a blocking passkey registration prompt at sign-in.
Note: Only Microsoft-provided SMS/voice delivery is being retired. Organizations that still require telephony-based MFA can configure customer-managed telecom providers via the Microsoft Security Store.
When You Should Disable SMS First-Factor Sign-In
Disable SMS first-factor sign-in if:
- You don’t have a business need for passwordless SMS-only sign-in (most organizations don’t).
- You’re enforcing stronger authentication (Authenticator, passkeys, FIDO2, Windows Hello) via Conditional Access.
- You want to reduce account takeover risk and align with Microsoft’s security defaults and industry best practices.
If you do rely on SMS for MFA (not first-factor), plan to migrate users to passkeys or Authenticator before February 1, 2027, or arrange a customer-managed telecom provider.
How to Review and Disable SMS First-Factor Sign-In
1) Identify who is using SMS-based sign-in
In the Entra admin center:
- Go to Protection > Authentication methods and review usage/analytics for SMS and Voice.
- Check Users > All users and inspect individual users’ Authentication methods to see if SMS is registered as a primary or sole method.
- For broader reporting, use Microsoft Graph (e.g., list authenticationMethods per user) to find accounts where SMS is the only MFA method.
2) Disable SMS first-factor sign-in (tenant setting)
Microsoft’s retirement of SMS first-factor sign-in for Free tenants is enforced by the service, but you should ensure your tenant isn’t enabling legacy SMS-only flows elsewhere.
- In Entra admin center, navigate to Protection > Authentication methods > Policies.
- Review the SMS policy and any legacy passwordless phone sign-in settings; disable SMS as a standalone first-factor where possible.
- Ensure Security defaults or your Conditional Access policies require phishing-resistant methods for high-risk sign-ins.
3) Remove SMS as a user’s sign-in method (if needed)
For users who still have SMS registered:
- Have them visit myaccount.microsoft.com (or your organization’s self-service portal), go to Security info, change their Default sign-in method to Microsoft Authenticator or Passkey, then delete Phone/Alternate Phone/Voice entries.
- Admins can remove SMS methods via Microsoft Graph PowerShell using the Identity.SignIns module (e.g., disabling SMS sign-in for specific phone authentication method IDs).
4) Enforce stronger authentication with Conditional Access
To prevent fallback to weak methods:
- Use Conditional Access > Authentication strength to require Phishing-resistant MFA (passkeys, FIDO2, Windows Hello) for admins and sensitive apps.
- Require Microsoft Authenticator with Number Matching as a minimum baseline for all employees, and mandate FIDO2 for privileged roles.
Migration Playbook: Move Users Off SMS Quickly
A practical migration path:
- Enable passkeys tenant-wide (they’re becoming the default in Entra ID).
- Communicate the change and provide simple steps for users to register passkeys or the Authenticator app.
- Identify affected users whose only MFA method is SMS/voice and prioritize them for migration.
- Suppress nudges temporarily if needed while you roll out training, but keep the enforcement date in mind (Feb 1, 2027 for Microsoft-provided SMS/voice MFA).
- Validate with pilot groups, then expand to all users.
What to Do If You Must Keep SMS for MFA
If business constraints require SMS for MFA:
- Configure a customer-managed telecom provider via the Microsoft Security Store before February 1, 2027.
- Treat SMS as a temporary fallback, not a primary method, and continue migrating to passkeys or FIDO2.
Bottom Line
SMS first-factor sign-in is a high-risk, legacy capability that Microsoft is actively retiring. For most organizations, the right move is to review usage, disable SMS-only sign-in, and migrate users to passkeys or the Microsoft Authenticator app—ideally enforced through Conditional Access policies.
Our Microsoft office 365 Implementation services team are here if you have any questions or require support on this change.
