Starting February 1, 2027, Microsoft will disable the use of SMS one-time passcodes as the sole method for signing in to Microsoft Entra ID for workforce (employee) accounts. Administrators globally must migrate any users relying exclusively on phone-based SMS as a first-factor before that deadline to avoid access disruptions across Microsoft 365 and other services secured by Entra ID.
What’s being removed and who’s affected
SMS first-factor authentication—also known internally as “SignInNoPassword”—lets employees enter a registered phone number instead of a username/password and receive a six-digit code via SMS to complete login. As of the enforcement date, this method will no longer be accepted. Any existing settings enabling it will be ignored or hidden from management tools.
The change encompasses all workforce tenants worldwide, including US Government Community Cloud ones. It does not apply to Microsoft Entra External ID (customer identity) or Azure AD B2C usage. Only workers (employees) under Entra ID need to take action.
Why Microsoft is making this change
The decision reflects long-standing security concerns over SMS authentication. Risks include phishing, SIM swapping, number reassignment, and interception of messages. Attackers who trick users into giving up SMS codes or intercept them can reuse them, making SMS far less secure than cryptographic or token-based methods.
To protect against these threats, Microsoft advises using phishing-resistant alternatives such as passkeys (built to FIDO standards), Windows Hello for Business, FIDO2 security keys, or QR code + PIN mechanisms, especially in shared devices or frontline worker settings.
How organizations should prepare
Admins should begin by identifying which users are currently set up for SMS first-factor only. Key places to check include authentication method reports, sign-in logs, and conditional access policies. Special attention is needed for teams relying on shared devices or without corporate-issued smartphones.
After identifying at-risk accounts, deploy alternative authentication methods and ensure support procedures, help-desk workflows, enrollment instructions, and break-glass scenarios are updated. Running a staged rollout or pilot migration helps catch compatibility issues ahead of time.
This isn’t just a policy tweak—it’s an operational deadline with real consequences. After February 1, accounts that still rely solely on first-factor SMS may be locked out. Administrators need to act now not just to comply, but to reduce potential identity security vulnerabilities.
What this means: Microsoft’s move is part of a larger industry trend away from passwordless, phishing-resistant authentication. SMS codes, once seen as handy for frontline or remote workers, are now widely viewed as an insecure weak point. This shift underscores a broader push toward stronger identity security postures, especially for cloud-based platforms.