Microsoft Announces Retirement of SMS-Based First-Factor Sign-in for Entra ID
Admins urged to migrate to phishing-resistant methods like passkeys before February 2027

Key Takeaways
- Microsoft will retire SMS first-factor sign-in for Entra ID starting in February 2027.
- Administrators must migrate users to phishing-resistant methods such as passkeys or FIDO2 security keys.
- Organizations relying on SMS-based 2FA will face sign-in disruptions if migration is not completed.
- No patch is available; this is a policy retirement requiring administrative action.
Related Security News

NeedyMantis Malware Used for Long-Term Persistence in Targeted Intrusions
Microsoft has identified a malware family named NeedyMantis being used by threat actors to maintain long-term, unauthorized access to already-breached networks. The malware has been observed in targeted intrusions across a range of sectors, including telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Activity has been tracked since at least 2023 and remains ongoing.




