Microsoft Sets February 2027 Deadline to Replace Entra ID SMS, Voice MFA

Microsoft Sets February 2027 Deadline to Replace Entra ID SMS, Voice MFA

Shivangi
Aug 11, 2026 2:41 PM IST
Category Technology

Synopsis

The company will retire Microsoft-provided SMS and voice authentication across Entra ID, with users who rely exclusively on those methods required to register a passkey before accessing their accounts.

01
Chapter one

Key Highlights

  • Microsoft will stop SMS and voice authentication for Entra ID from 1 February 2027.
  • Users will need to use passkeys to sign in.
  • More than 720,000 businesses use Entra ID.

Microsoft is set to end SMS and voice authentication for millions of users accessing its Entra ID service, with the change taking effect on 1 February 2027.

Entra ID, formerly known as Azure Active Directory, manages user identities and access to cloud services. More than 720,000 businesses use the platform, which also provides single sign-on for services such as Microsoft 365.

02
Chapter two

Five-Month Transition to Passkeys

Microsoft will begin a five-month transition away from SMS and voice authentication on 1 September, moving users towards passkeys.

Users who currently rely on SMS or voice authentication will be set up for passkey sign-in and prompted to register a passkey the next time they log in.

Microsoft said SMS and voice authentication are no longer considered sufficiently secure and that users should move away from methods that can be exploited through scams.

Businesses that have specific reasons for requiring SMS verification will be able to use another telecommunications messaging service. Microsoft is expected to provide further details about this option on 18 September.

03
Chapter three

Passkeys Become Mandatory

The change follows Microsoft’s decision last year to remove password support from Microsoft Authenticator and encourage greater adoption of passkeys. Entra ID is a major target for cybercriminals because it controls access to cloud systems used by businesses.

The Australian Cyber Security Centre and other Five Eyes security agencies warned in 2024 about common techniques used to target corporate Active Directory systems. Verizon’s latest Data Breach Investigations Report found that credential abuse was responsible for initial access in 13% of data breaches.

The FIDO Alliance said more than 5 billion passkeys are now being used worldwide, while 68% of companies are either using or deploying passkeys for employee sign-ins. From 1 February 2027, Microsoft says users will need to register a passkey to continue signing into their accounts, with no option to opt out.

Source: Information Age 

Written by Shivangi

At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.