Microsoft Sets February 2027 Deadline to Replace Entra ID SMS, Voice MFA
Synopsis
The company will retire Microsoft-provided SMS and voice authentication across Entra ID, with users who rely exclusively on those methods required to register a passkey before accessing their accounts.
Key Highlights
- Microsoft will stop SMS and voice authentication for Entra ID from 1 February 2027.
- Users will need to use passkeys to sign in.
- More than 720,000 businesses use Entra ID.
Microsoft is set to end SMS and voice authentication for millions of users accessing its Entra ID service, with the change taking effect on 1 February 2027.
Entra ID, formerly known as Azure Active Directory, manages user identities and access to cloud services. More than 720,000 businesses use the platform, which also provides single sign-on for services such as Microsoft 365.
Five-Month Transition to Passkeys
Microsoft will begin a five-month transition away from SMS and voice authentication on 1 September, moving users towards passkeys.
Users who currently rely on SMS or voice authentication will be set up for passkey sign-in and prompted to register a passkey the next time they log in.
Microsoft said SMS and voice authentication are no longer considered sufficiently secure and that users should move away from methods that can be exploited through scams.
Businesses that have specific reasons for requiring SMS verification will be able to use another telecommunications messaging service. Microsoft is expected to provide further details about this option on 18 September.
Passkeys Become Mandatory
The change follows Microsoft’s decision last year to remove password support from Microsoft Authenticator and encourage greater adoption of passkeys. Entra ID is a major target for cybercriminals because it controls access to cloud systems used by businesses.
The Australian Cyber Security Centre and other Five Eyes security agencies warned in 2024 about common techniques used to target corporate Active Directory systems. Verizon’s latest Data Breach Investigations Report found that credential abuse was responsible for initial access in 13% of data breaches.
The FIDO Alliance said more than 5 billion passkeys are now being used worldwide, while 68% of companies are either using or deploying passkeys for employee sign-ins. From 1 February 2027, Microsoft says users will need to register a passkey to continue signing into their accounts, with no option to opt out.
Source: Information Age
At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.
You Might Also Like
Understanding ETFs: The Beginner’s Guide to Exchange-Traded Funds
Cultural Adaptation and Global Branding: How to Balance Local Preferences with Global Appeal