Microsoft will retire SMS-based first-factor sign-in for all Microsoft Entra ID workforce tenants worldwide on February 1, 2027, requiring organizations to migrate users to more secure, phishing-resistant authentication methods such as passkeys, Windows Hello for Business, or FIDO2 security keys. This change aims to eliminate vulnerabilities associated with SMS authentication, including interception and SIM swapping, and avoid disruptions in Microsoft 365 and other Entra-protected services by prompting administrators to update authentication policies and user enrollment processes ahead of the deadline.
https://cybersecuritynews.com/entra-id-sms-sign-in-retirement/
