This article outlines the steps for deactivating SMS.
- Multi-Factor Authentication (MFA)
- SMS factor
To deactivate a factor (SMS) from the tenant, please remove the factor requirements from every policy (for example, ASOP, GSOP, Enrollment) before continuing with the factor deactivation.
Okta Classic orgs
Go to Admin Console > Security > Multifactor > Factor Types > SMS authentication > Deactivate.
Okta Identity Engine (OIE) tenants
Go to Admin Console > Security > Authenticators > Setup > Phone > Action > Delete.
When SMS is removed as an authentication factor, users who were previously enrolled with SMS will need to re-register with another available MFA method. If SMS were the only registered factor, they would be prompted to choose a different method or register one during their next login attempt.
If SMS is removed as an MFA option for user enrollment, users who previously registered with SMS will still have their SMS profile on their device; however, they will not be able to use it for new enrollments or to satisfy MFA challenges unless it is explicitly re-enabled.
