Summary
Details
[What and why]
We're rolling out optimizations to passkey registration across Microsoft Entra ID. These changes improve how passkey registration is handled through Registration Campaign, Authentication Strengths, and My Sign-Ins.
The updated registration logic will more consistently:
- Guide users to register passkey types that comply with administrator configured passkey profile restrictions, reducing unsuccessful or non-compliant registration attempts.
- Prioritize registration of a passkey that is local to the user's current device when permitted by policy.
These improvements are designed to increase successful passkey registrations, reduce registration friction, and help organizations strengthen adoption of phishing resistant authentication methods.
There are no user interface changes associated with this update.
[Rollout schedule]
- General Availability (Worldwide and GCC): Beginning in late August 2026 and expected to complete in late August 2026
[Impact on your organization]
Who is affected
- Users who register passkeys through Registration Campaign, Authentication Strengths, or My Sign-Ins
- Organizations using passkey profiles, including Synced-only, Device-bound-only, Attestation Enforced, and AAGUID-restricted configurations
- Organizations using AAGUID-restricted passkey profiles will benefit from these registration optimizations. The greatest benefit is expected for Microsoft-supported passkey experiences. Other AAGUID-restricted providers continue to be supported and can be configured as before.
Platforms and services
- Microsoft Entra ID Registration Campaign
- Authentication Strengths
- My Sign-Ins self-service passkey registration
- Microsoft-supported passkey experiences for AAGUID-restricted profiles:
- Entra passkey on Windows
- Microsoft Authenticator passkey
- iCloud Keychain passkey
- Google Password Manager passkey
What will happen
- Users will continue to register passkeys through the same registration screens and entry points they use today.
- Registration will more consistently align with administrator configured passkey profile requirements.
- When permitted by policy, registration will prioritize a passkey native to the user's current device to improve the sign-in experience.
[Action required and recommendations]
No action is required.
Organizations should continue driving passkey adoption through Registration Campaign and Authentication Strengths. These optimizations are intended to improve the likelihood of successful passkey registration while helping users remain compliant with organizational passkey policies.
[Compliance considerations]
No compliance considerations identified. Review as appropriate for your organization.
Change History
Never Miss a Microsoft 365 Update
Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.