Microsoft Entra ID Launches SMS and QR Code Authentication in Public Preview

Close-up of a finger hovering over a glowing QR code displayed on a blurred technological surface, illustrating concepts like digital scanning, data access, or contactless interactions.

Microsoft has expanded its authentication options in Microsoft Entra ID with two new methods currently in public preview: SMS-based authentication and QR code authentication, both aimed at simplifying access for frontline workers. The expansion supports Microsoft’s broader initiative to eliminate traditional passwords by 2025 and transition to more secure authentication methods.

The SMS-based authentication system enables users to sign in using only a registered phone number and a one-time passcode delivered via SMS, eliminating the need for traditional username and password credentials. The streamlined approach is specifically designed for frontline workers rather than information workers, offering a simplified sign-in experience for specific workplace scenarios. The approach matches Microsoft’s recent findings that passwordless authentication methods can deliver up to three times faster login speeds compared to traditional password-based systems.

Organizations implementing SMS authentication are advised to follow established security controls and best practices for workplace access. Microsoft has published a list of compatible applications that support SMS-based sign-in, allowing organizations to verify compatibility with their existing systems. The implementation comes as part of Microsoft’s broader strategy to enforce mandatory multi-factor authentication across its enterprise platforms throughout 2024 and 2025.

Alongside SMS authentication, Microsoft has introduced QR code authentication in public preview. The alternative method addresses security concerns in frontline shared device scenarios. The QR code system offers enhanced security compared to SMS-based authentication, as it is designed to be resistant to phishing attempts. The emphasis on phishing resistance reflects growing concerns from security agencies, with the FBI and CISA recently emphasizing the importance of phishing-resistant authentication methods.

The authentication developments arrive as Microsoft Entra Connect continues to support organizations transitioning from federated authentication to cloud authentication through its staged rollout process. The migration pathway includes capabilities for password hash synchronization and pass-through authentication, implemented through specific PowerShell commands and preparatory procedures. The transition supports Microsoft’s larger initiative to make all new accounts passwordless by default.

Both authentication methods remain in public preview, allowing organizations to evaluate their effectiveness and compatibility with existing systems before full deployment. The measured approach enables businesses to assess these new authentication methods while maintaining their current security standards and preparing for Microsoft’s planned complete transition to passwordless authentication.

Sources: Microsoft Learn – SMS Authentication, Microsoft Learn – Staged Rollout