← Back to Feed

Microsoft reminds admins to migrate Entra ID users to passkeys

September 21, 2026 · BleepingComputer · Severity: MEDIUM

Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.

Key Takeaways

  • Microsoft will retire SMS first-factor sign-in for Entra ID starting in February 2027, requiring migration to phishing-resistant authentication methods.
  • Admins must migrate Entra ID users to passkeys or other phishing-resistant methods before the deadline to avoid sign-in disruptions.
  • The move is part of Microsoft's broader effort to eliminate SMS-based authentication due to its vulnerability to phishing and SIM-swapping attacks.
☕ Buy a Coffee