Microsoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027
Brief
Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires organizations to migrate affected users before February 1, 2027.
The security-focused change will prevent employees from using a registered telephone number and SMS one-time passcode as their primary sign-in method, potentially disrupting Microsoft 365 and other Entra-protected services if administrators fail to prepare.
SMS first-factor authentication, internally identified as SignInNoPassword, allows a user to enter a registered phone number instead of a username and password. Microsoft Entra ID then sends a six-digit SMS code that completes authentication.
Although Microsoft initially intended it to simplify access for frontline workers, it now advises organizations to move those users to modern, phishing-resistant authentication.
