Microsoft will stop supporting SMS-based two-factor authentication for Microsoft Entra ID accounts starting Feb. 1, a move driven by the rising capability of AI to power sophisticated phishing attacks. The change pushes IT administrators toward passkeys, a login method the company considers significantly more secure.

What You Need to Know

The deadline applies to all IT administrators who use SMS codes to log into Microsoft Entra ID. Passkeys, which rely on cryptographic keys stored on hardware tokens or devices, are more resistant to phishing and interception. The shift reflects a broader industry trend away from password-based systems as AI-driven attacks become more common.

Organizations must prepare to deploy alternative authentication methods before the cutoff to avoid service disruptions.

Why Microsoft Is Phasing Out SMS Codes

SMS-based authentication has long been considered a weak link in security. Attackers can intercept codes through SIM swapping or exploit vulnerabilities in telecom networks. The emergence of AI has amplified these risks, allowing attackers to automate phishing campaigns that trick users into revealing their credentials and SMS codes simultaneously.

Microsoft has identified AI-enhanced phishing as a key reason for accelerating the retirement of SMS codes. The company advocates for passkeys, which require physical possession of a device and cannot be easily phished.

  • SIM Swapping: Attackers trick carriers into transferring a phone number to a new SIM, then intercept SMS codes.
  • Phishing Automation: AI tools generate convincing fake login pages that harvest both passwords and SMS codes at scale.
  • Interception Risks: Vulnerabilities in SS7 signaling protocols allow attackers to redirect SMS messages to their own devices.

Why This Matters

For organizations, this change represents a mandatory shift in authentication strategy. IT admins must deploy passkeys, authenticator apps or hardware security keys before the deadline. Late adopters risk losing access to administrative portals and facing operational disruptions.

The move also signals that Microsoft and other major technology companies view passwordless authentication as the new standard. This transition will reshape identity management practices across industries, forcing enterprises to invest in secure alternatives and reduce reliance on legacy phone-based verification.

What the Transition Means for IT Administrators

Admins should evaluate options such as the Microsoft Authenticator app, FIDO2 security keys or Windows Hello for Business. Updating authentication policies and educating users about passkeys will be critical before the Feb. 1 deadline. Microsoft has outlined documentation to guide the migration.

This policy aligns with Microsoft's broader roadmap to eliminate passwords entirely. For now, IT administrators who rely on SMS codes must act quickly to ensure continued access to Entra ID management tools.