Entra Retires Microsoft-provided SMS and Voice MFA
As I have predicted for years now, the decision to stop native support for SMS/Phone 2FA in Entra has come.
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement
They market it as security, it is 100% a financial cost cutting move, but sure…you can say it was security.
Should executives be using SMS 2FA? No. Do plant workers with a basic/restricted corporate account need passkeys/Microsoft authenticator…no.
I am fully aware of the phishing implications of SMS, but that ALSO applies to almost every other form of 2FA/MFA. Microsoft Authenticator (non-passkey) is just as vulnerable to proxied login pages and credential theft. Sure, SIM swap attacks are possible, but the risk of a generic office employee being SIM swapped is low. I think passkeys/FIDO is cool and I use it all myself. I like that we have developed a standard that does not require everyone to buy a Yubikey (I will still happily buy them…they are fun). Do we still have a long way to go? Yes…
I’m looking forward to future conversations where I explain to employees that Microsoft Authenticator does not let us snoop on their personal device 😑