← Back to Feed
Microsoft reminds admins to migrate Entra ID users to passkeys
September 21, 2026 · BleepingComputer · Severity: MEDIUM
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.
Key Takeaways
- Microsoft will retire SMS first-factor sign-in for Entra ID starting in February 2027, requiring migration to phishing-resistant authentication methods.
- Admins must migrate Entra ID users to passkeys or other phishing-resistant methods before the deadline to avoid sign-in disruptions.
- The move is part of Microsoft's broader effort to eliminate SMS-based authentication due to its vulnerability to phishing and SIM-swapping attacks.