Microsoft has issued a reminder to administrators that SMS first-factor sign-in for Entra ID is being retired, with a cutoff date of February 2027. The company is steering organizations toward phishing-resistant authentication methods, such as passkeys, to keep user sign-ins working smoothly after the retirement takes effect.
Admins who delay the migration risk facing sign-in disruptions once the older method is switched off. Microsoft's guidance frames the move as a necessary step to modernize authentication and reduce reliance on SMS, which is more vulnerable to phishing and interception than passkey-based approaches.
For now, the timeline gives organizations roughly two years to plan and execute the transition. The reminder does not introduce new technical requirements, but it signals that SMS first-factor will no longer be a supported fallback for Entra ID users after February 2027.