Microsoft Entra ID SMS First-Factor Sign-In Retirement

SMS first-factor sign-in retirement

Microsoft is retiring SMS first-factor sign-in for Entra ID Free tenants.

From August 11, 2026, users in Microsoft Entra ID Free tenants can no longer sign in using only a registered phone number and an SMS OTP.

This change targets SMS first-factor/passwordless sign-in, not SMS-based MFA.

Here’s the distinction:

πŸ”΄ SMS first-factor sign-in
Phone number β†’ SMS OTP β†’ Sign-in
Retired

🟒 SMS as MFA
Username/password β†’ SMS OTP β†’ Sign-in
Not affected

The reason is security. An authentication flow that relies entirely on a phone number and SMS code is more exposed to risks such as SIM swapping, number takeover, and SMS interception than stronger authentication methods.

How to Prepare for Microsoft Entra ID SMS Sign-In Retirement

  • Identify users currently relying on SMS first-factor sign-in.
    Ensure they have another authentication method registered before the retirement.
    Review authentication method policies for dependencies on SMS first-factor sign-in.
    Prefer passkeys and other phishing-resistant authentication methods where possible.
    Communicate the change to affected users to avoid sign-in disruption.

One important point: This retirement does not mean SMS-based MFA is being removed.

Users can still use SMS as an additional authentication factor after completing their primary authentication.

If your tenant still has users depending solely on SMS first-factor sign-in, this is a change worth checking now.

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to Newsletter

Subscribe to our email newsletter to get the latest posts delivered right to your email.
Powered by Amail.