started · updated
Microsoft to end Entra ID SMS and voice authentication by 2027
Microsoft has announced a phased plan to discontinue SMS and voice call authentication for its Entra ID identity platform. The transition aims to move organizations toward more secure, phishing-resistant methods such as passkeys, Windows Hello, and FIDO2 security keys.
The rollout follows a specific timeline: starting September 1, 2026, users currently utilizing SMS or voice credentials will be prompted to register a passkey during the sign-in process. By February 1, 2027, Microsoft will permanently terminate native SMS and voice verification for all Entra ID accounts, with no option to opt out.
Microsoft cited the rise of AI-driven cyber threats as a primary driver for this change. The company noted that artificial intelligence has increased the effectiveness of phishing, social engineering, and SIM-swapping attacks. By shifting to passkeys, which are stored locally on devices rather than transmitted via cellular networks, Microsoft intends to mitigate the risks associated with intercepted one-time codes.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] The enforcement of these changes applies to all Entra ID tenants with no opt-out option. www.techrepublic.com
- [○ 1 SOURCE] Microsoft is also phasing out text verification and account recovery for personal accounts used for Windows 11, Xbox, and Outlook. www.techrepublic.com
- [● 3 SOURCES] SMS and voice authentication are being phased out due to risks from AI-assisted phishing, SIM-swapping, and replay attacks. www.it-boltwise.de · borncity.com · www.techrepublic.com
- [● 3 SOURCES] Microsoft will end support for SMS and voice call authentication in Entra ID on February 1, 2027. www.it-boltwise.de · borncity.com · www.techrepublic.com
- [● 3 SOURCES] A transition phase will begin on September 1, 2026, requiring users to register a passkey during sign-in. www.it-boltwise.de · borncity.com · www.techrepublic.com