SHD / MC Checker

MC1448374 | (Updated) Microsoft Entra ID: Retirement of SMS first-factor sign-in for Entra ID Free tenants



MC1448374 | (Updated) Microsoft Entra ID: Retirement of SMS first-factor sign-in for Entra ID Free tenants

Classification planForChange
Last Updated 08/13/2026 20:30:56
Start Time 08/05/2026 23:15:19
End Time 09/14/2026 07:00:00
Message Content

Updated August 10, 2026: We have updated the timeline. We apologize for any inconvenience. 

[What and why]

Microsoft will retire SMS first-factor sign-in for Microsoft Entra ID Free tenants on August 11, 2026, due to increased fraudulent activity targeting this authentication method.

SMS first-factor sign-in allows users to sign in using only a registered phone number and a one-time passcode (OTP) sent by SMS, without entering a username or password. Because this sign-in method relies solely on a registered phone number and SMS-delivered passcode, it is more susceptible to abuse and account compromise than phishing-resistant authentication methods. 

This change applies only to SMS first-factor sign-in. SMS used as a multifactor authentication (MFA) method is not affected. Users can continue receiving SMS verification codes as an additional authentication factor after completing their primary sign-in.

[Rollout schedule]

  • Beginning August 11, 2026, SMS first-factor sign-in will no longer be supported for Microsoft Entra ID Free tenants.

[Impact on your organization]

Who is affected

  • Microsoft Entra ID Free tenants with SMS first-factor sign-in enabled
  • Users who rely exclusively on SMS first-factor sign-in

Platforms and services

  • Microsoft Entra ID
  • SMS first-factor passwordless sign-in (SignInNoPassword)

What will happen

  • Users in Microsoft Entra ID Free tenants will no longer be able to use SMS as a first-factor sign-in method.
  • Attempts to sign in using only a registered phone number and SMS one-time passcode will be blocked.
  • Users who have another registered authentication method can continue signing in using that method.
  • SMS as a multifactor authentication method is not affected.
  • All other registered authentication methods remain available.
  • Users who rely exclusively on SMS first-factor sign-in must register and use another authentication method before the retirement date.

[Action required and recommendations]

If your organization has users relying on SMS first-factor sign-in, we recommend that you:

  • Identify users currently using SMS first-factor sign-in.
  • Ensure affected users register an alternative authentication method before August 11, 2026.
  • Communicate this change to affected users to help prevent sign-in disruptions.
  • Migrate users to passkeys or other phishing-resistant authentication methods where possible.
  • Review authentication method policies and remove dependencies on SMS first-factor sign-in.

Learn more

[Compliance considerations]

Question Answer
Does this change modify how users access Microsoft 365 resources or services? Yes. Users in affected Microsoft Entra ID Free tenants will no longer be able to sign in using SMS as their first-factor authentication method and must use another registered sign-in method.
Does this change require admin action to maintain user access? Yes. Administrators should identify users who rely on SMS first-factor sign-in and ensure those users register an alternative authentication method before the retirement date to avoid sign-in disruptions.
Does this change affect authentication or access management policies? Yes. Organizations that currently depend on SMS first-factor sign-in may need to review and update their authentication policies to remove dependencies on this retired authentication method.
Machine Translation

2026年8月10日更新:タイムラインを更新しました。ご不便をおかけしたことをお詫び申し上げます。 

[何となぜ]

Microsoftは、この認証方法を標的とした不正行為の増加により、 2026年8月11日にMicrosoft Entra ID Freeテナント向けのSMSファーストファクターサインインを終了します。

SMSファーストファクターサインインは、ユーザーがユーザー名やパスワードを入力せずに、登録済みの電話番号とSMSで送信されるワンタイムパスコード(OTP)のみでサインインできるようにします。このサインイン方法は登録済み電話番号とSMSで配信されたパスコードのみに依存しているため、フィッシング耐性認証方法よりも悪用やアカウント侵害のリスクが高いです。 

この変更はSMSのファーストファクターサインインにのみ適用されます。多要素認証(MFA)方式として使用されるSMSは影響を受けません。ユーザーはプライマリサインインを完了した後も追加の認証ファクターとしてSMS検証コードを受け取ることができます。

[展開スケジュール]

  • 2026年8月11日より、Microsoft Entra ID FreeテナントではSMSのファーストファクターサインインがサポートされなくなります。

[組織への影響]

影響を受ける人物

  • Microsoft Entra ID FreeテナントでSMSファーストファクターサインインが有効
  • SMSのファーストファクターサインインのみに依存するユーザー

ホームとサービス

  • Microsoft Entra ID
  • SMSのファーストファクターパスワードレスサインイン(SignInNoPassword)

何が起こるのか

  • Microsoft Entra ID Freeテナントのユーザーは、SMSをファーストファクターサインイン方式として使用できなくなります。
  • 登録済み電話番号とSMSのワンタイムパスコードのみでのサインインはブロックされます。
  • 他に登録された認証方法を持つユーザーは、その方法でサインインを続けることができます。
  • 多要素認証手段としてのSMSは影響を受けません。
  • その他の登録された認証方法はすべて利用可能です。
  • SMSのファーストファクターサインインのみに依存するユーザーは、退職日前に登録し、別の認証方法を使用する必要があります。

[行動が必要と提言]

もしあなたの組織にSMSのファーストファクターサインインを利用するユーザーがいる場合は、以下のことをお勧めします:

  • 現在SMSのファーストファクターサインインを利用しているユーザーを特定します。
  • 影響を受けるユーザーは 2026年8月11日までに代替認証方法を登録してください。
  • この変更を影響を受けるユーザーに伝え、サインインの妨げを防ぐ助けをしてください。
  • 可能な限り、パスキーやその他のフィッシング耐性認証手段への移行を行ってください。
  • 認証方法のポリシーを見直し、SMSのファーストファクターサインインへの依存を除去してください。

詳しくはこちら

[コンプライアンスの考慮事項]

質問 回答
この変更は、ユーザーのMicrosoft 365リソースやサービスへのアクセス方法に変化をもたらしますか? はい。影響を受けたMicrosoft Entra ID Freeテナントのユーザーは、SMSを第一認証手段としてサインインできなくなり、別の登録サインイン方式を使わなければなりません。
この変更はユーザーアクセスを維持するために管理者の操作が必要ですか? はい。管理者はSMSのファーストファクターサインインに依存するユーザーを特定し、そのユーザーが退職日前に代替認証方法を登録してサインインの妨害を避けるべきです。
この変更は認証やアクセス管理ポリシーに影響しますか? はい。現在SMSのファーストファクターサインインに依存している組織は、この廃止された認証方法への依存を取り除くために認証ポリシーを見直し更新する必要があるかもしれません。