As reported by BleepingComputer, Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16, 2026, and has already stopped pushing them through Microsoft 365 Apps updates. The advisory also carries a second, arguably more security-relevant reminder: Entra ID SMS first-factor sign-in is being retired in February 2027, and admins should move users to phishing-resistant methods now.

Cloud Security Alert: The advisory also carries a second, arguably more security-relevant reminder: Entra ID SMS first-factor sign-in is being retired in February 2027, and admins should move users to phishing-resistant methods now.

Why This Matters Beyond Housekeeping

At face value, this is an end-of-life notice for three taskbar-integrated productivity apps. But two threads here deserve defender attention, and neither is about user convenience.

1. Auto-installed, auto-launching apps are an inventory problem

Microsoft pushed these companion apps automatically to Windows 11 enterprise devices running the Microsoft 365 desktop client. They launch at startup by default. That means for the better part of a year, many environments have been running three additional signed binaries with taskbar integration, local file indexing behavior, and Entra-bound authentication tokens — without an explicit procurement or deployment decision by the customer's security team.

This is the pattern defenders should worry about: vendor-driven silent sprawl. Every auto-installed app is another process that:
Why This Matters Beyond Housekeeping
Loads at boot and maintains a persistent presence
Has access to calendar, contact, and file metadata
Can become a dependency for detection rules, EDR baselines, and software inventory
May interact with Entra tokens and conditional access in ways security teams never reviewed

Retirement is the right moment to verify they're actually gone — not just unsupported.

2. The SMS MFA sunset is the real security action item

Buried in the same advisory is a February 2027 deadline: Microsoft is retiring SMS as a first-factor sign-in method for Entra ID. SMS-based authentication is vulnerable to SIM swapping, MFA fatigue via SMS bombing, and SS7 interception. This sunset is overdue, and the four-month window between December and February is not enough time to migrate a large tenant if you haven't started.

The companion app retirement is a December task. The SMS MFA migration is a strategic priority that should already be underway. Don't let the noisy item overshadow the critical one.

Who Is Most Affected

  • Mid-to-large enterprises on Windows 11 with Microsoft 365 Apps for Enterprise — the automatic deployment target
  • Regulated industries (finance, healthcare, public sector) where SMS MFA may violate emerging authentication mandates
  • Tenants with legacy conditional access policies that still permit SMS as a primary or backup factor

Shield53 Recommendations

Immediate Actions:

  • Inventory: Query your EDR or Intune inventory for the three companion app binaries. Confirm how many endpoints are running them and whether auto-launch is still enabled.
  • Deploy removal: Use Intune or Group Policy to uninstall the apps across managed devices before December 16. Do not rely on end-user self-removal.
  • Audit persistence: After removal, verify startup items and scheduled tasks are clean. Disabled apps that still load at boot are a common blind spot.
  • Entra ID MFA audit: Pull your authentication methods report from Entra ID. Identify every user still registered with SMS as a factor.
  • Migrate to phishing-resistant MFA: Prioritize passkeys (FIDO2 security keys or platform authenticators like Windows Hello for Business). QR code + number matching is an interim option but not a final state.
  • Update conditional access: Block legacy authentication and require phishing-resistant MFA for high-risk sign-ins. Don't leave SMS as a fallback.
  • Communicate the change: Users will notice the apps disappearing. Send a concise notice. Don't let the retirement become a helpdesk surge.

The companion app retirement is routine. The SMS MFA sunset is not. Treat them as two separate workstreams with different timelines — and get the phishing-resistant migration moving now, not in January.