Microsoft Warns Admins: Migrate Users to Passkeys Before February 2027
Microsoft is reminding administrators to migrate Entra ID users to phishing-resistant methods such as passkeys by February 2027. The company announced that it will retire SMS first-factor sign-in due to phishing, fraud, and account compromise risks.
The retirement process applies only to Microsoft Entra ID workforce tenant authentication scenarios and not to Azure AD B2C or Microsoft Entra External ID customer identity scenarios.
Microsoft has shared detailed guidance on deploying and managing phishing-resistant passwordless authentication in Entra ID. The company also announced that passkeys will start rolling out as the default authentication experience for Entra ID enterprise identity service starting this month.