As reported by BleepingComputer, Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16, 2026, and has already stopped pushing them through Microsoft 365 Apps updates. The advisory also carries a second, arguably more security-relevant reminder: Entra ID SMS first-factor sign-in is being retired in February 2027, and admins should move users to phishing-resistant methods now.
Why This Matters Beyond Housekeeping
At face value, this is an end-of-life notice for three taskbar-integrated productivity apps. But two threads here deserve defender attention, and neither is about user convenience.
1. Auto-installed, auto-launching apps are an inventory problem
Microsoft pushed these companion apps automatically to Windows 11 enterprise devices running the Microsoft 365 desktop client. They launch at startup by default. That means for the better part of a year, many environments have been running three additional signed binaries with taskbar integration, local file indexing behavior, and Entra-bound authentication tokens — without an explicit procurement or deployment decision by the customer's security team.
This is the pattern defenders should worry about: vendor-driven silent sprawl. Every auto-installed app is another process that:
Retirement is the right moment to verify they're actually gone — not just unsupported.
2. The SMS MFA sunset is the real security action item
Buried in the same advisory is a February 2027 deadline: Microsoft is retiring SMS as a first-factor sign-in method for Entra ID. SMS-based authentication is vulnerable to SIM swapping, MFA fatigue via SMS bombing, and SS7 interception. This sunset is overdue, and the four-month window between December and February is not enough time to migrate a large tenant if you haven't started.
The companion app retirement is a December task. The SMS MFA migration is a strategic priority that should already be underway. Don't let the noisy item overshadow the critical one.
Who Is Most Affected
- Mid-to-large enterprises on Windows 11 with Microsoft 365 Apps for Enterprise — the automatic deployment target
- Regulated industries (finance, healthcare, public sector) where SMS MFA may violate emerging authentication mandates
- Tenants with legacy conditional access policies that still permit SMS as a primary or backup factor
Shield53 Recommendations
Immediate Actions:
- Inventory: Query your EDR or Intune inventory for the three companion app binaries. Confirm how many endpoints are running them and whether auto-launch is still enabled.
- Deploy removal: Use Intune or Group Policy to uninstall the apps across managed devices before December 16. Do not rely on end-user self-removal.
- Audit persistence: After removal, verify startup items and scheduled tasks are clean. Disabled apps that still load at boot are a common blind spot.
- Entra ID MFA audit: Pull your authentication methods report from Entra ID. Identify every user still registered with SMS as a factor.
- Migrate to phishing-resistant MFA: Prioritize passkeys (FIDO2 security keys or platform authenticators like Windows Hello for Business). QR code + number matching is an interim option but not a final state.
- Update conditional access: Block legacy authentication and require phishing-resistant MFA for high-risk sign-ins. Don't leave SMS as a fallback.
- Communicate the change: Users will notice the apps disappearing. Send a concise notice. Don't let the retirement become a helpdesk surge.
The companion app retirement is routine. The SMS MFA sunset is not. Treat them as two separate workstreams with different timelines — and get the phishing-resistant migration moving now, not in January.