Microsoft Retires SMS and Voice Authentication for Entra ID

Microsoft Retires SMS and Voice Authentication for Entra ID

First seen 7 Sep 2026, 10:55 UTC Forkast.Newslearn.microsoft.com 45.0

Article Content

Browse articles
ThreatCluster

As of September 7, 2026, Microsoft has enforced the retirement of unregistered directory data for self-service password reset (SSPR) in Entra ID. This change affects users who relied on SMS, voice, or unregistered secondary emails for authentication, locking them out of recovery options. The transition to passkeys as the default authentication method began on September 1, 2026, with a mandatory registration prompt for users still using SMS or voice set for February 1, 2027. Microsoft cites a significant increase in identity attacks, with over 600 million daily incidents. The move aligns with NIST guidelines that classify SMS as a restricted authenticator. Organizations must now prioritize migrating to phishing-resistant methods to enhance security. The FIDO Alliance reports 5 billion active passkeys, indicating high infrastructure readiness for this transition.

Key Points: • Microsoft Entra ID has retired SMS and voice authentication methods. • Users relying on unregistered data for SSPR are now locked out of recovery. • Passkeys are now the default authentication method, with mandatory registration by February 2027.

Ask AI about this cluster

Timeline

2026-09-01
Passkeys become default authentication
Microsoft Entra ID transitioned to passkeys as the default sign-in method, enhancing security against phishing.
learn.microsoft.com
2026-09-07
SSPR retirement enforced
Unregistered directory data for SSPR is no longer usable, locking out users relying on SMS or voice for recovery.
Forkast.News
2027-02-01
Full retirement of SMS and voice authentication
Microsoft will completely retire SMS and voice authentication, requiring all users to register passkeys.
learn.microsoft.com