Start with Identity
News

Entra ID stops delivering SMS and voice codes on February 1, and global admins go last

From February 1, 2027, Microsoft stops providing SMS and voice authentication in Entra ID, and users with no other method must register a passkey to keep signing in. Global Administrators and external users get until July 1. Keeping SMS means buying it from a telephony provider.

By SWI Community TeamSep 21, 2026

Microsoft reminded administrators this week that Microsoft Entra ID is retiring the SMS and voice authentication it delivers itself. Passkeys became the default on September 1, when users enabled for SMS or voice were automatically enabled for passkeys and nudged to register one. From February 1, 2027, Microsoft-provided SMS and voice delivery ends for all users except Global Administrators and external users, whose date is July 1, 2027. After the cutoff, anyone whose only MFA method is SMS or voice must register a passkey during sign-in; the prompt blocks sign-in and has no opt-out. Organizations that still need SMS or voice must contract a telephony provider through Microsoft Security Store, with Soprano and Telesign first, configurable from October 30, 2026, and pay the telecom costs themselves. Microsoft's retirement guide links a PowerShell analyzer for finding affected users.

Why it matters

Read the dates in the opposite order to how Microsoft wrote them. Global Administrators get five more months on SMS than everyone else, which gives the most privileged accounts in the tenant the longest runway on the weakest factor. There are sensible operational reasons for that, since nobody wants the break-glass path to fail first, but the right move is to migrate administrators first and on purpose, with hardware keys, rather than last by default. External users on the July date are the other group to watch, because they are the ones you have least influence over.

The cost change is the quieter shift. SMS is now a line item you buy from a third party, which makes the business case for dropping it easier to write; the UK government put its SMS saving at close to 600 pounds a day after its passkey rollout. And a blocking passkey prompt at sign-in is exactly the moment a vishing caller wants: attackers were already phoning staff about passkey enrollment. Tell users now how IT will and will not contact them. Background in our July coverage of the passkey default and phishing-resistant MFA.

Source: BleepingComputer

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.