News

Microsoft Blocks SMS Authentication in Entra ID by 2027 Due to AI Phishing Risks

4 min read Editorial

Microsoft has officially announced the retirement of SMS and voice-based authentication for Microsoft Entra ID, marking a significant shift in how organizations secure their digital identities. The tech giant confirmed that these legacy methods will be fully blocked for Entra users starting February 1, 2027, due to escalating security threats fueled by artificial intelligence.

This decision comes after Microsoft observed a sharp increase in AI-assisted phishing campaigns that successfully trick users into handing over credentials and multi-factor authentication codes. The company noted that these AI-driven attacks now boast higher click-through rates than traditional phishing attempts, making SMS-based one-time passwords a primary target for cybercriminals.

Why Microsoft Is Killing SMS Authentication

The move to eliminate SMS authentication is driven by the realization that these methods offer significantly weaker protection against modern threats compared to phishing-resistant alternatives like passkeys. Microsoft highlighted that AI has made it considerably easier for attackers to manipulate SMS and voice communication channels, even with limited resources.

Advertisement

One of the most pressing concerns is the rise in SIM-swap attacks. With AI tools, attackers can more easily deceive mobile carriers into transferring a victim’s phone number to a SIM card they control. Once the number is transferred, the attacker can intercept SMS-based authentication codes and gain unauthorized access to accounts. Microsoft emphasized that while AI does not give attackers superpowers to directly access a device or SIM, it has drastically lowered the barrier for deceiving users and intercepting credentials.

The Enforcement Timeline

Microsoft has outlined a clear timeline for this transition, ensuring organizations have ample time to adapt their security policies.

  • September 1, 2026: Microsoft will begin forcing passkey registration for Entra users who currently rely on SMS or voice authentication. When users attempt to sign in using multi-factor authentication, they will be prompted to set up a passkey. Those not ready to adopt passkeys must proactively disable SMS or voice methods before this date.
  • February 1, 2027: SMS and voice authentication will be fully retired in Entra ID. All tenants will be required to use stronger authentication methods, with no opt-out available.

This enforcement applies to all Entra ID tenants, signaling that Microsoft is committed to raising the security baseline across its enterprise ecosystem. The company stated in a notification to IT administrators that “the AI era demands stronger, phishing-resistant authentication,” underscoring the urgency of the transition.

Impact on Personal Microsoft Accounts

While the immediate deadline targets enterprise users, personal Microsoft account holders should also expect changes. Microsoft has confirmed that SMS-based authentication and account recovery will eventually be phased out for personal accounts as well, though no specific cutoff date has been announced yet.

In a support document, Microsoft stated, “Microsoft is committed to advancing security standards, and as such, we will start phasing out SMS as a method of authentication and account recovery for personal Microsoft accounts.” The company added that the future of authentication is “passwordless, secure, and user-friendly,” aligning with its broader push toward passkey adoption across Windows 11, Xbox, and Outlook.

What This Means for You

For IT administrators, the September 2026 deadline requires immediate action. You will need to audit your organization’s multi-factor authentication policies and ensure that all users have access to passkeys or alternative phishing-resistant methods. Failure to comply by February 2027 will result in locked accounts, as SMS and voice authentication will no longer be available.

For personal users, this is a strong signal to start transitioning away from SMS-based two-factor authentication. While there is no immediate deadline, waiting until Microsoft enforces the change could leave you scrambling to secure your account. Consider setting up a passkey now or using the Microsoft Authenticator app, which offers a more secure and convenient experience than SMS codes.

How to Get It

To prepare for this transition, Microsoft recommends the following steps:

  • For Entra ID Admins: Review your organization’s authentication policies and enable passkey registration. Use the September 2026 deadline as a hard stop to ensure all users have migrated to stronger methods.
  • For Personal Users: Navigate to your Microsoft account security settings and set up a passkey or download the Microsoft Authenticator app. This will provide a more secure and streamlined sign-in experience across all Microsoft services.

As AI continues to evolve, Microsoft’s decision to retire SMS authentication highlights the growing need for robust, phishing-resistant security measures. By moving to passkeys, both enterprises and individuals can better protect themselves against the sophisticated threats of the modern digital landscape.

Source: Windows Latest

Over to you: Are you planning to switch to passkeys before the September deadline, or will you wait until SMS authentication is fully retired?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement