Microsoft is switching off text-message logins for work accounts in February 2027

Entra ID admins have 15 months to move staff onto passkeys or hardware keys before SMS sign-in stops working.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge overhead photoreal shot of a modern office desk at dusk, a smartphone displaying a generic passkey biometric prompt glow next to a small
Share

Key points

  • Microsoft will retire SMS and voice calls as a first-factor sign-in for work accounts on Entra ID on 1 February 2027, according to its own passwordless deployment guide.
  • The cut-off applies even to companies that pipe SMS through their own telecom provider, so "bring your own carrier" workarounds won't save you.
  • Free-tier Entra ID tenants already lost SMS first-factor sign-in in August 2025, and new tenants never get it.
  • Passkeys are becoming the default sign-in prompt this month for users currently enrolled in SMS or voice codes.
  • Microsoft's own timing data puts a password sign-in at up to 24 seconds and a synced passkey at around 3 seconds.

Microsoft has set a hard date for killing off text-message logins on Entra ID, the system most large employers use to sign staff into Microsoft 365 and Azure.

From 1 February 2027, staff won't be able to receive a code by SMS or automated phone call as proof of identity on a work account. Companies that miss the deadline will see users locked out.

The reminder came through a Microsoft 365 Message Center note last week and was first reported by BleepingComputer.

What is actually changing?

Microsoft is retiring SMS and voice as a first-factor sign-in method, meaning the step where you type a phone number and get a code. It's also retiring Microsoft-run SMS and voice delivery for multifactor authentication (MFA), the second step after a password.

The shutdown covers organisations using Choose Your Own Telephony Provider, the option that lets a company route codes through its own SMS carrier. Those setups die on the same date. Azure AD B2C and Entra External ID, used for customer logins on public-facing apps, are not affected. Workforce accounts only.

Why is Microsoft doing this?

SMS codes are cheap to intercept. Criminals routinely trick mobile carriers into moving a victim's number to a new SIM card, a technique called SIM swapping, and phishing kits grab one-time codes as users type them into fake login pages. We covered exactly that attack pattern on 17 September in our report on the N0va phishing toolkit, which harvests live session tokens before the victim's browser can.

Microsoft's replacement is the passkey, a login credential stored on your phone or laptop that only works on the real site and can't be read out over the phone or forwarded in a message. FIDO2 hardware keys, the small USB devices you tap or plug in, and QR-code sign-in from a trusted device are the other supported options.

Passkeys will roll out as the default sign-in prompt starting this month. Users currently on SMS or voice will be nudged to register a passkey on next authentication. That rollout and what it means for organisations still running hybrid setups is something we've tracked since our 1 September report on the passkey default.

What should IT teams do now?

Start with a headcount. Admins with Global Reader, Authentication Policy Administrator or Security Reader roles can run Microsoft's Entra SMS/Voice Policy Scanner PowerShell script to see which accounts still depend on phone-based codes.

The failure mode is predictable: shared mailboxes, break-glass admin accounts, field staff on shared devices, contractors whose personal phones were quietly enrolled years ago. Those accounts get locked out on 1 February 2027 unless someone maps them this quarter.

Date What happens
August 2025 SMS first-factor sign-in removed for Entra ID Free tenants
November 2025 Passkeys start rolling out as default sign-in prompt
1 February 2027 SMS and voice retired as first-factor and as Microsoft-delivered MFA

Organisations that genuinely can't move off phone codes, think call centres with shared kiosks, will have to buy a third-party telecom connector through the Microsoft Security Store. That's a paid workaround, not a reprieve.

Run the scanner now. The post-mortem always says the audit happened too late.

© 2026 Threat Vectr