TechSignal.news
Cybersecurity

Microsoft Kills SMS MFA in Entra ID by February 2027, Forces Passkey Migration

Microsoft will retire native SMS and voice MFA in Entra ID on February 1, 2027, with mandatory passkey enrollment starting September 1, 2026. Enterprises must budget for FIDO2 infrastructure or migrate to third-party telecom providers.

TechSignal.news AI4 min read

Microsoft enforces non-optional passkey transition in 17 months

Microsoft is retiring SMS and voice-based multi-factor authentication in Entra ID effective February 1, 2027. Starting September 1, 2026, tenants still using phone-based MFA will see automatic passkey registration prompts with no ability to dismiss them permanently. Organizations that refuse to adopt passkeys must migrate to customer-managed telecom providers through Microsoft's Security Store, with configuration windows opening October 30, 2026. The change affects budget, timelines, and risk posture for every Entra ID customer still relying on phone-based authentication.

The move eliminates Microsoft-managed SMS and voice as default authentication paths because both remain vulnerable to SIM swapping, call interception, and phishing. Microsoft is treating phone-based factors as non-compliant at scale. The IAM market is responding: identity and access management spending is forecast to grow from $13.5 billion in 2024 to $27.5 billion in 2029, a 15.3% compound annual growth rate driven partly by forced modernization of authentication infrastructure.

Budget impact: new line items for passkeys or third-party telecom

Enterprises face three options, each with different cost structures. First, adopt passkeys directly through Entra ID's native flows, which requires budget for FIDO2 hardware keys, endpoint enablement for platform passkeys, and user onboarding programs. Second, shift to authenticator apps with push-based MFA, which avoids hardware costs but requires app deployment and support overhead. Third, migrate to customer-managed SMS and voice providers available through Microsoft's Security Store starting September 18, 2026. This third path preserves phone-based MFA but adds new vendor relationships, telecom integration costs, and per-message fees that Microsoft previously absorbed.

The timeline is aggressive. Entra tenants need procurement decisions finalized by Q4 2026 to avoid forced, unplanned transitions in early 2027. September 1, 2026 marks the start of auto-enrollment prompts. October 30, 2026 opens configuration for customer-managed telecom. February 1, 2027 is the hard cutoff: after this date, users attempting to authenticate with SMS or voice MFA hit a non-optional passkey registration prompt. There is no extension, no opt-out, and no grandfather clause.

Competitive pressure on Okta, Ping, and CyberArk

Microsoft's move pressures competing cloud identity providers — Okta, Ping Identity, CyberArk Identity, ForgeRock — that still offer SMS and voice as standard MFA paths. Microsoft is signaling that phishable factors are unacceptable in enterprise identity infrastructure. The shift aligns with OpenAI's requirement that Trusted Access for Cyber accounts use hardware passkeys to access advanced AI models starting September 1, 2026, suggesting a broader industry ratchet toward phishing-resistant authentication.

Downstream, vendors benefit. FIDO2 hardware key manufacturers, authenticator app providers, and telecom integrators entering Microsoft's Security Store ecosystem gain new enterprise demand. The question for buyers is whether to follow Microsoft's passwordless mandate or invest in preserving phone-based MFA through third-party providers. The latter delays migration but does not avoid it — the industry direction is clear.

Ping Identity adds runtime controls for AI agents

Separately, Ping Identity introduced Enterprise Personal Agent Access, a capability to govern autonomous AI assistants that connect to APIs, code repositories, databases, and cloud infrastructure. The feature uses PingOne Privilege to discover shadow AI tools, log their activities, require human approvals for sensitive actions, and revoke access in real time. This addresses a gap in identity governance: traditional IAM systems were not built to handle non-human identities operating with partial autonomy.

The capability positions Ping against privileged access vendors like CyberArk, BeyondTrust, and Delinea, as well as cloud infrastructure entitlement management players like Wiz and Ermetic. IAM leaders at the ETCISO IAM Summit 2026 argued that identity governance must now unify Identity Governance and Administration, Privileged Access Management, Cloud Infrastructure Entitlement Management, and Identity Threat Detection and Response to handle AI-driven access risks. Ping's approach is runtime enforcement: it does not prevent AI agents from existing but controls what they can touch and when.

What to watch

Watch for Entra ID migration announcements from enterprises in regulated industries — financial services, healthcare, government — where phone-based MFA remains common and migration timelines are constrained by compliance cycles. Watch for customer-managed SMS provider pricing and SLAs published through Microsoft's Security Store in September 2026; this will determine whether preserving phone-based MFA is economically viable or a temporary stopgap. Watch for competitive responses from Okta and Ping on their own SMS and voice MFA roadmaps; silence signals acceptance of Microsoft's framing that phishable factors are obsolete.

For buyers, the decision is whether to front-load passkey infrastructure investment now or defer to 2027 and accept the risk of a forced, compressed migration. The latter is cheaper in the short term and riskier operationally. Microsoft has removed the ability to wait indefinitely.

identity-and-access-managementmulti-factor-authenticationmicrosoft-entra-idpasskeysprivileged-access-management

Technology decisions, clearly explained.

Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.

More in Cybersecurity