Continue supporting SMS-based MFA for workflows that still require it with a secure, managed External MFA solution — seamlessly integrated with Microsoft Entra and ready to deploy in less than 30 minutes.
Starting September 1, 2026, passkeys become the default authentication experience for users enabled for SMS or voice. Starting February 1, 2027, Microsoft-provided telecom delivery for SMS and voice will be retired. For many organizations, this is an opportunity to move more users toward phishing-resistant authentication. However, some environments may still depend on SMS for specific users, applications, operational processes, or regulatory workflows. Organizations that need to preserve those use cases require a secure way to continue SMS-based verification without replacing Microsoft Entra or creating a separate identity platform.
Credenti SMS integrates with Microsoft Entra as an External MFA method. Users continue to authenticate through Microsoft Entra. When additional authentication is required and Credenti SMS is available to the user, they can select it as their MFA method. Microsoft Entra securely redirects the authentication session to Credenti. During the authentication transaction, Credenti dynamically retrieves the user's phone number from Microsoft Entra and sends a time-limited one-time passcode by SMS. The user enters the code with Credenti. After successful verification, Credenti returns the authentication result to Microsoft Entra, which continues evaluating access policies and completes the sign-in. Microsoft Entra remains the identity authority and source of truth for the user's phone number. Credenti handles the SMS verification experience.

Continue supporting applications and processes that still depend on SMS verification.
Maintain SMS for selected users who cannot immediately move to phishing-resistant authentication.
Support defined workflows where telecommunications-based verification remains necessary.
Move most users toward stronger authentication while gradually reducing legacy SMS dependencies.
Credenti participates directly in the Microsoft Entra authentication flow using Microsoft’s External MFA architecture.
Configure and enable Credenti SMS in less than 30 minutes for a fast path to continued SMS authentication.
Microsoft Entra continues to control identity, primary authentication, Conditional Access, application access, and authorization decisions.
Credenti dynamically retrieves the required phone number from Microsoft Entra during authentication without storing it within Credenti.
There is no separate phone directory to populate, synchronize, or maintain within Credenti. Microsoft Entra remains the source of truth.
Users do not need to register or maintain a second phone number in Credenti for SMS delivery.
Credenti manages the SMS verification experience, including OTP generation, delivery, and validation.
Keep SMS available for the users and workflows that require it while moving others toward passkeys and phishing-resistant authentication.

Credenti SMS Gateway can typically be configured and enabled in less than 30 minutes.The integration is designed for rapid deployment using Microsoft Entra External MFA and an Entra Enterprise Application, without requiring changes to applications already relying on Entra for authentication.
No. Microsoft Entra remains the identity provider and continues to manage user identities, primary authentication, Conditional Access, applications, and access decisions. Credenti participates only when the external SMS MFA method is selected.
Credenti SMS integrates using Microsoft's External MFA architecture and an Entra Enterprise Application. When additional authentication is required, Microsoft Entra redirects the user to Credenti to complete the SMS verification challenge. After successful verification, Credenti securely returns the authentication result to Microsoft Entra.
The user first authenticates with Microsoft Entra. When MFA is required, the user selects Credenti SMS from the available authentication methods. The user is redirected to Credenti, receives a one-time passcode by SMS, enters the code, and is returned to Microsoft Entra after successful verification.
No. Credenti does not store user's phone numbers. When a user selects Credenti SMS during authentication, the user's phone number is dynamically retrieved from Microsoft Entra through the authorized integration. Credenti uses the phone number to deliver the SMS one-time passcode for that authentication transaction. The phone number remains managed in Microsoft Entra, eliminating the need to synchronize or maintain phone numbers within Credenti. Microsoft Entra remains the source of truth for the user's phone number.
No. There is no phone-number synchronization process between Microsoft Entra and Credenti. Credenti dynamically retrieves the user's applicable phone number from Entra when the authentication transaction occurs.
Passkeys should be used wherever they are practical and appropriate. Credenti SMS is intended for workflows, user populations, or operational requirements where SMS authentication still needs to remain available. It allows organizations to continue modernizing authentication without forcing every SMS-dependent workflow to change at the same time.
No. The user's phone information remains managed in Microsoft Entra. Credenti dynamically retrieves the required phone number during authentication, eliminating a separate Credenti phone-number enrollment process.
Yes. Credenti SMS is intended to support controlled deployment so organizations can retain SMS for appropriate users and workflows while using stronger authentication methods elsewhere. The applicable user population can be aligned with the organization's Microsoft Entra authentication andaccess strategy.
No. Microsoft Entra continues to control access to applications and evaluates the organization's Conditional Access and authentication policies. Credenti provides the successful SMS verification result required to complete the external MFA step.
Quickly transition your SMS delivery with no downtime, no coding, and no operational hassle — all while maintaining authentication continuity at scale.