Microsoft has issued a stark reminder to administrators: the era of using standard SMS messages as a primary login factor for Entra ID is ending. The company confirmed it will retire SMS as a first-factor authentication method starting in February 2027, pushing organizations to adopt more secure, phishing-resistant alternatives like passkeys.

This move, reported by BleepingComputer on 21 September 2026, addresses a long-known security vulnerability. SMS-based authentication, while widely adopted, is susceptible to sophisticated attacks including real-time phishing kits, SIM-swapping fraud, and exploits targeting the underlying SS7 telephony protocol. By removing it as a primary method, Microsoft is enforcing a higher security baseline for its identity platform.

The Deadline and the Imperative

The February 2027 deadline is firm. After this date, users will be unable to use a phone number to receive an SMS code as their initial step to sign into cloud applications, websites, or devices using Entra ID. This will cause direct sign-in failures for any workflow, service, or integration still relying on that flow.

For IT teams with complex user bases including frontline staff, contractors, and international travelers, this represents a significant infrastructure and change management project. The transition is not optional and requires proactive, multi-year planning.

A Four-Phase Migration Path

Industry experts and Microsoft's own guidance point to a clear, phased approach for administrators to tackle this migration:

  1. Audit and Assess: The first critical step is to inventory all Entra ID tenants. Teams must identify every user and application flow currently using SMS as the primary factor. This audit will reveal the scale of the project and highlight high-risk areas, such as privileged accounts or legacy systems.

  2. Pilot and Deploy Passkeys: Begin a controlled rollout of FIDO2 passkeys. These are cryptographic credentials stored on devices like laptops, smartphones, or dedicated security keys. Prioritize high-value targets like IT administrators, finance, and executives. This pilot phase will help troubleshoot technical challenges and gather user feedback.

  3. Communicate and Train: User adoption is the linchpin of success. A proactive communication and training program is essential. This should explain the "why" behind the security upgrade and provide clear, simple instructions for setting up and using passkeys on their managed or personal devices.

  4. Budget and Plan for Scale: Secure budget and resources. This may include procuring hardware FIDO2 security keys for users without suitable devices (e.g., some frontline workers) and allocating project management hours for the rollout.

Broader Industry Alignment

Microsoft's decision is not occurring in a vacuum. It aligns with a global shift away from SMS and towards phishing-resistant credentials. The U.S. National Institute of Standards and Technology (NIST) has previously deprecated SMS for high-assurance use cases. Furthermore, the FIDO Alliance, which includes Microsoft, Apple, and Google, has been championing passkeys as a foundational technology to eliminate password-based attacks across the ecosystem.

The reminder from Microsoft serves as a final call to action. With approximately 17 months remaining before the cutoff, the planning window for a smooth, non-disruptive migration is closing. For IT administrators, the message is clear: project timelines for Entra ID authentication should be reviewed and accelerated immediately to meet this new security mandate.


微軟向管理員發出嚴正提醒:將標準短訊(SMS)作為Entra ID主要登入因素的時代即將結束。該公司確認將於2027年2月起逐步淘汰SMS作為首要身份驗證方法,敦促機構採用更安全、具防釣魚能力的替代方案,如通行密鑰(Passkeys)。

此舉據BleepingComputer於2026年9月21日報導,旨在解決一個長期存在的安全漏洞。基於SMS的身份驗證雖然廣泛採用,但易受精密攻擊影響,包括實時釣魚工具、SIM卡換號詐騙以及針對底層SS7電話協議的漏洞利用。微軟透過移除此方法作為主要驗證方式,旨在提升其身份平台的安全基線。

截止日期與必要性

2027年2月的截止日期已成定局。屆時,用戶將無法透過電話號碼接收SMS驗證碼作為登入雲端應用程式、網站或使用Entra ID設備的首要步驟。任何仍依賴此流程的工作流程、服務或整合將直接導致登入失敗。

對於擁有複雜用戶群體(包括前線員工、承包商和國際差旅人員)的IT團隊而言,這將構成一項重大的基礎設施及變革管理項目。此過渡並非可選,而是需要主動進行、歷時數年的規劃。

四階段遷移路徑

業界專家與微軟自身指引為管理員提供了清晰的分階段遷移方法:

  1. 審計與評估:首要關鍵步驟是清點所有Entra ID租戶。團隊必須識別目前所有將SMS作為首要驗證因素的用戶及應用程式流程。此審計將揭示項目規模並突顯高風險領域,如特權帳戶或遺留系統。

  2. 試點部署通行密鑰:開始有限度地推出FIDO2通行密鑰。這些是存儲在手提電腦、智能手機或專用安全金鑰等設備上的加密憑證。應優先考慮高價值目標,如IT管理員、財務部門及高管。此試點階段有助於排除技術難題並收集用戶反饋。

  3. 溝通與培訓:用戶採納是成功的關鍵。主動的溝通和培訓計劃至關重要。應解釋安全升級背後的「原因」,並提供清晰簡單的說明,指導用戶在其託管或個人設備上設定及使用通行密鑰。

  4. 預算與規模化規劃:確保預算及資源。這可能包括為缺乏合適設備的用戶(例如某些前線員工)採購硬件FIDO2安全金鑰,以及為全面推出分配項目管理工時。

更廣泛的產業一致性

微軟的決定並非孤立事件。它契合了全球從SMS轉向防釣魚憑證的趨勢。美國國家標準與技術研究院(NIST)先前已在高保證使用場景中棄用SMS。此外,由微軟、蘋果和Google組成的FIDO聯盟,一直致力於推廣通行密鑰作為消除整個生態系統中基於密碼攻擊的基礎技術。

微軟的提醒可視為最終行動號召。距離截止期限僅剩約17個月,進行順暢、無干擾遷移的規劃窗口正在關閉。對IT管理員而言,訊息明確:應立即審查並加快Entra ID身份驗證的項目時間表,以符合此項新的安全要求。

新聞來源 / Original News Source