HomeIntelligenceBrief
BREACH BRIEF 🟠 High Advisory

Microsoft retires SMS first‑factor sign‑in for Entra ID, pushes passkey migration to avoid disruption

Microsoft will disable SMS and voice as first‑factor authentication for Entra ID workforce tenants on 1 Feb 2027, requiring admins to migrate users to phishing‑resistant methods such as passkeys. The shift creates a control‑evidence requirement for identity‑based access assurance and audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Microsoft retires SMS first‑factor sign‑in for Entra ID, urging passkey migration

What Happened — Microsoft announced that, effective 1 February 2027, SMS and voice will no longer be available as a first‑factor authentication method for Entra ID workforce tenants. Administrators must move users to phishing‑resistant options such as passkeys, QR‑code authentication, or FIDO2 security keys. The change already rolled out as the default authentication experience for many enterprises.

Why It Matters for Trust & Control Assurance

  • Continuous control‑assurance programs rely on documented, phishing‑resistant authentication methods; the SMS retirement forces a gap‑closure that must be evidenced for audit readiness.
  • Migrating to passkeys generates verifiable proof (e.g., credential issuance logs) that can be mapped to a single control objective across multiple frameworks (identity‑based access control).
  • The transition highlights the need for automated discovery (PowerShell scanner) and policy enforcement, core capabilities of our ACCESS_CONTROLS offering.

Who Is Affected — Organizations of any size that use Microsoft Entra ID for workforce authentication, especially cloud‑first enterprises and SaaS providers.

Recommended Actions

  1. Run the Entra SMS/Voice Policy Scanner to identify accounts still using SMS or voice MFA.
  2. Develop a phased migration plan to passkeys, QR codes, or FIDO2 keys, prioritizing high‑privilege accounts.
  3. Update authentication policies and document the change in your control‑evidence repository for audit purposes.
  4. If phone‑based MFA is required, configure a third‑party telecom provider via the Microsoft Security Store.

Source: BleepingComputer

Technical Notes

  • SMS first‑factor sign‑in was retired for Entra ID Free tenants in August 2026 and will be removed for all workforce tenants in February 2027.
  • Passkeys are now the default authentication method; users will be prompted to register one during their next MFA flow.
  • The change does not affect Azure AD B2C or Entra External ID scenarios.

Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →