Microsoft to Retire SMS and Voice MFA for Entra ID, Prompting Shift to Stronger Authentication
What Happened — Microsoft announced that SMS‑based and voice‑call multi‑factor authentication (MFA) for Entra ID will be disabled, with the final cut‑off slated for October 2024. Organizations must migrate users to password‑less options such as Microsoft Authenticator, FIDO2 keys, or passkeys before the deadline.
Why It Matters for Compliance & Audit Readiness
- SMS and voice MFA are flagged as “weak” under SOC 2 CC6.1 (Logical Access) and can undermine the evidentiary trail auditors expect for strong authentication controls.
- Removing these insecure factors reduces the likelihood of credential‑theft attacks (e.g., SIM‑swap, voice‑phishing), helping you maintain a defensible continuous‑compliance posture.
- The transition forces a review of access‑control policies, evidence collection, and user‑training programs—core elements of Verisq’s SOC 2 Access Controls capability.
Who Is Affected — Any enterprise, government agency, or SaaS provider that relies on Microsoft Entra ID (Azure AD) for identity and access management, across all industry verticals.
Recommended Actions
- Map your current MFA methods to SOC 2 CC6.1 requirements and document the gap.
- Deploy Microsoft Authenticator, FIDO2 keys, or passkey solutions for all users before the deprecation date.
- Update your IAM policies, capture configuration screenshots, and archive change‑management tickets as audit evidence.
- Conduct a brief security‑awareness session highlighting the risks of SMS/voice MFA and the benefits of password‑less authentication.
Source: TechRepublic – Microsoft Entra ID SMS/Voice Authentication Phase‑out
Technical Notes — SMS MFA is vulnerable to SIM‑swap and SS7 attacks; voice MFA can be intercepted via social engineering. Microsoft recommends moving to passkeys (WebAuthn/FIDO2) or the Authenticator app, both of which provide cryptographic proof of possession and are considered “strong” MFA by NIST SP 800‑63B.