← Back to feed
PhishingEmerging1 sourceSep 21, 2026 · 14:40via Cyber Security News

Microsoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027

Brief

Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires organizations to migrate affected users before February 1, 2027.

The security-focused change will prevent employees from using a registered telephone number and SMS one-time passcode as their primary sign-in method, potentially disrupting Microsoft 365 and other Entra-protected services if administrators fail to prepare.

SMS first-factor authentication, internally identified as SignInNoPassword, allows a user to enter a registered phone number instead of a username and password. Microsoft Entra ID then sends a six-digit SMS code that completes authentication.

Although Microsoft initially intended it to simplify access for frontline workers, it now advises organizations to move those users to modern, phishing-resistant authentication.

Read more on Cyber Security News→