Entra ID stops delivering SMS and voice codes on February 1, and global admins go last
From February 1, 2027, Microsoft stops providing SMS and voice authentication in Entra ID, and users with no other method must register a passkey to keep signing in. Global Administrators and external users get until July 1. Keeping SMS means buying it from a telephony provider.
Microsoft reminded administrators this week that Microsoft Entra ID is retiring the SMS and voice authentication it delivers itself. Passkeys became the default on September 1, when users enabled for SMS or voice were automatically enabled for passkeys and nudged to register one. From February 1, 2027, Microsoft-provided SMS and voice delivery ends for all users except Global Administrators and external users, whose date is July 1, 2027. After the cutoff, anyone whose only MFA method is SMS or voice must register a passkey during sign-in; the prompt blocks sign-in and has no opt-out. Organizations that still need SMS or voice must contract a telephony provider through Microsoft Security Store, with Soprano and Telesign first, configurable from October 30, 2026, and pay the telecom costs themselves. Microsoft's retirement guide links a PowerShell analyzer for finding affected users.
Why it matters
Read the dates in the opposite order to how Microsoft wrote them. Global Administrators get five more months on SMS than everyone else, which gives the most privileged accounts in the tenant the longest runway on the weakest factor. There are sensible operational reasons for that, since nobody wants the break-glass path to fail first, but the right move is to migrate administrators first and on purpose, with hardware keys, rather than last by default. External users on the July date are the other group to watch, because they are the ones you have least influence over.
The cost change is the quieter shift. SMS is now a line item you buy from a third party, which makes the business case for dropping it easier to write; the UK government put its SMS saving at close to 600 pounds a day after its passkey rollout. And a blocking passkey prompt at sign-in is exactly the moment a vishing caller wants: attackers were already phoning staff about passkey enrollment. Tell users now how IT will and will not contact them. Background in our July coverage of the passkey default and phishing-resistant MFA.
Source: BleepingComputer
Related on Start with Identity
- BlogGoogle Workspace puts FIDO2 keys into the Windows login, days after Entra makes passkeys default
Google began rolling out FIDO2 security keys as a second factor at Windows sign-in for all Workspace customers on 13 July. Microsoft is making passkeys the defa
- BlogMalware can drive a Windows Hello key for Entra ID persistence without a PIN prompt
Dirk-jan Mollema showed that code running in a signed-in Windows session can use the victim's TPM-bound Windows Hello for Business key as a FIDO2 credential, sa
- BlogRSA brings passwordless authentication to Linux servers, closing its last password-only gap
RSA ID Plus now covers Linux servers, developer workstations, and critical infrastructure with FIDO-based passwordless sign-in, closing the gap where organizati
- GlossaryVishing (Voice Phishing)
Vishing, short for voice phishing, is social engineering carried out over a phone call, in which an attacker impersonates a trusted party to get the target to r
- CVEZimbra ZCS chained with CVE-2025-48700 to steal MFA backup codes
Zimbra Collaboration Suite, chained with CVE-2025-48700, was used to steal MFA backup codes and app passwords (CERT-UA UAC-0233). Added to CISA KEV in mid-March
- GlossaryAuthenticator Assurance Level (AAL)
NIST 800-63B levels describing authentication strength. AAL1: single factor. AAL2: multi-factor. AAL3: multi-factor with phishing-resistant cryptographic authen