Microsoft has warned administrators to stop using SMS- and voice-based authentication in Microsoft Entra ID, saying the methods are too vulnerable to phishing, SIM-swapping, replay attacks, and increasingly effective AI-assisted social engineering. The company will begin prompting Entra users who still rely on phone-based verification to register a passkey starting September 1, with Microsoft positioning passkeys and Microsoft Authenticator as phishing-resistant, passwordless alternatives.
Microsoft plans to permanently disable SMS and voice verification for all Entra ID accounts on February 1, 2027, with no tenant opt-out reported. The company is also moving to phase out text-based verification and account recovery for personal Microsoft accounts, though it has not announced a final consumer cutoff date. The shift is expected to force organizations to update onboarding and recovery processes, support users on older devices, and reduce the risk of account compromise tied to phone-based authentication.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft said it will permanently disable SMS and voice verification for all Entra ID accounts on February 1, 2027. After that, affected users will need to use stronger authentication methods such as passkeys.
Starting September 1, Microsoft said Entra users who still rely on SMS or voice authentication will be prompted during sign-in to register a passkey. The move is part of Microsoft's push toward phishing-resistant authentication.
Microsoft notified Microsoft Entra ID tenants of an authentication security change, warning administrators that SMS- and voice-based authentication are too vulnerable to phishing, SIM-swapping, replay attacks, and AI-assisted social engineering. The notice said there would be no opt-out for tenants.
Microsoft published support documentation stating that it has begun phasing out SMS-based authentication and account recovery for personal Microsoft accounts, describing SMS as a leading source of fraud. No final consumer cutoff date was announced.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcewindowslatest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.