Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

(Updated) Microsoft Entra ID: Optimizations for passkey registration experience

Message ID
MC1440968
View in Message Center
Service
Microsoft Entra
Category
Stay Informed
Tags
New featureUser impactAdmin impact
Rollout
August 2026September 2026

Summary

Microsoft Entra ID is optimizing passkey registration to better align with administrator policies, prioritize local device passkeys, and improve successful registrations without UI changes. The rollout begins late August 2026, completing by mid-September. No action is required; organizations should continue promoting passkey adoption.

Details

Updated September 4, 2026: We have updated the timeline. Thank you for your patience.

[What and why]

We're rolling out optimizations to passkey registration across Microsoft Entra ID. These changes improve how passkey registration is handled through Registration Campaign, Authentication Strengths, and My Sign-Ins.

The updated registration logic will more consistently:

  • Guide users to register passkey types that comply with administrator configured passkey profile restrictions, reducing unsuccessful or non-compliant registration attempts.
  • Prioritize registration of a passkey that is local to the user's current device when permitted by policy.

These improvements are designed to increase successful passkey registrations, reduce registration friction, and help organizations strengthen adoption of phishing resistant authentication methods.

There are no user interface changes associated with this update.

[Rollout schedule]

  • General Availability (Worldwide and GCC): Beginning in late August 2026 and expected to complete by mid-September 2026 (previously late August)

[Impact on your organization]

Who is affected

  • Users who register passkeys through Registration Campaign, Authentication Strengths, or My Sign-Ins
  • Organizations using passkey profiles, including Synced-only, Device-bound-only, Attestation Enforced, and AAGUID-restricted configurations
  • Organizations using AAGUID-restricted passkey profiles will benefit from these registration optimizations. The greatest benefit is expected for Microsoft-supported passkey experiences. Other AAGUID-restricted providers continue to be supported and can be configured as before.

Platforms and services

  • Microsoft Entra ID Registration Campaign
  • Authentication Strengths
  • My Sign-Ins self-service passkey registration
  • Microsoft-supported passkey experiences for AAGUID-restricted profiles:
    • Entra passkey on Windows
    • Microsoft Authenticator passkey
    • iCloud Keychain passkey
    • Google Password Manager passkey

What will happen

  • Users will continue to register passkeys through the same registration screens and entry points they use today.
  • Registration will more consistently align with administrator configured passkey profile requirements.
  • When permitted by policy, registration will prioritize a passkey native to the user's current device to improve the sign-in experience.

[Action required and recommendations]

No action is required.

Organizations should continue driving passkey adoption through Registration Campaign and Authentication Strengths. These optimizations are intended to improve the likelihood of successful passkey registration while helping users remain compliant with organizational passkey policies.

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Change History

Show
September 4, 2026 at 6:30 PM Updated
Title
Previous
Microsoft Entra ID: Optimizations for passkey registration experience
New
(Updated) Microsoft Entra ID: Optimizations for passkey registration experience
Summary
Previous
Microsoft Entra ID is optimizing passkey registration via Registration Campaign, Authentication Strengths, and My Sign-Ins to improve compliance with passkey policies and prioritize local device passkeys. These changes, rolling out in late August 2026, require no user interface changes or action from organizations.
New
Microsoft Entra ID is optimizing passkey registration to better align with administrator policies, prioritize local device passkeys, and improve successful registrations without UI changes. The rollout begins late August 2026, completing by mid-September. No action is required; organizations should continue promoting passkey adoption.
Last Updated Date
Previous
2026-07-27T22:53:36.710Z
New
2026-09-04T16:33:45.320Z
Tags
Previous
New feature,User impact,Admin impact
New
Updated message,New feature,User impact,Admin impact
Body Content
Previous
<p><b>[What and why]</b></p><p>We're rolling out optimizations to passkey registration across Microsoft Entra ID. These changes improve how passkey registration is handled through <b>Registration Campaign</b>, <b>Authentication Strengths</b>, and <b>My Sign-Ins</b>.</p><p>The updated registration logic will more consistently:</p><ul><li>Guide users to register passkey types that comply with administrator configured passkey profile restrictions, reducing unsuccessful or non-compliant registration attempts.</li><li><b>Prioritize registration of a passkey that is local&nbsp;</b>to the user's current device when permitted by policy.</li></ul><p>These improvements are designed to increase successful passkey registrations, reduce registration friction, and help organizations strengthen adoption of phishing resistant authentication methods.</p><p>There are <b>no user interface changes</b> associated with this update.</p><p><b>[Rollout schedule]</b></p><ul><li><b>General Availability (Worldwide and GCC):</b>&nbsp;Beginning in <b>late August 2026</b> and expected to complete in <b>late August 2026</b></li></ul><p><b>[Impact on your organization]</b></p><p><i>Who is affected</i></p><ul><li>Users who register passkeys through Registration Campaign, Authentication Strengths, or My Sign-Ins</li><li>Organizations using passkey profiles, including Synced-only, Device-bound-only, Attestation Enforced, and AAGUID-restricted configurations</li><li>Organizations using AAGUID-restricted passkey profiles will benefit from these registration optimizations. The greatest benefit is expected for Microsoft-supported passkey experiences. Other AAGUID-restricted providers continue to be supported and can be configured as before.</li></ul><p><i>Platforms and services</i></p><ul><li>Microsoft Entra ID Registration Campaign</li><li>Authentication Strengths</li><li>My Sign-Ins self-service passkey registration</li><li>Microsoft-supported passkey experiences for AAGUID-restricted profiles:<ul><li>Entra passkey on Windows</li><li>Microsoft Authenticator passkey</li><li>iCloud Keychain passkey</li><li>Google Password Manager passkey</li></ul></li></ul><p><i>What will happen</i></p><ul><li>Users will continue to register passkeys through the same registration screens and entry points they use today.</li><li>Registration will more consistently align with administrator configured passkey profile requirements.</li><li>When permitted by policy, registration will prioritize a passkey native to the user's current device to improve the sign-in experience.</li></ul><p><b>[Action required and recommendations]</b></p><p>No action is required.</p><p>Organizations should continue driving passkey adoption through Registration Campaign and Authentication Strengths. These optimizations are intended to improve the likelihood of successful passkey registration while helping users remain compliant with organizational passkey policies.</p><p><b>[Compliance considerations]</b></p><p>No compliance considerations identified. Review as appropriate for your organization.</p>
New
<p>Updated September 4, 2026: We have updated the timeline. Thank you for your patience. </p><p><b>[What and why]</b></p><p>We're rolling out optimizations to passkey registration across Microsoft Entra ID. These changes improve how passkey registration is handled through <b>Registration Campaign</b>, <b>Authentication Strengths</b>, and <b>My Sign-Ins</b>.</p><p>The updated registration logic will more consistently:</p><ul><li>Guide users to register passkey types that comply with administrator configured passkey profile restrictions, reducing unsuccessful or non-compliant registration attempts.</li><li><b>Prioritize registration of a passkey that is local&nbsp;</b>to the user's current device when permitted by policy.</li></ul><p>These improvements are designed to increase successful passkey registrations, reduce registration friction, and help organizations strengthen adoption of phishing resistant authentication methods.</p><p>There are <b>no user interface changes</b> associated with this update.</p><p><b>[Rollout schedule]</b></p><ul><li><b>General Availability (Worldwide and GCC):</b>&nbsp;Beginning in <b>late August 2026</b> and expected to complete by <b>mid-September 2026</b> (previously late August)</li></ul><p><b>[Impact on your organization]</b></p><p><i>Who is affected</i></p><ul><li>Users who register passkeys through Registration Campaign, Authentication Strengths, or My Sign-Ins</li><li>Organizations using passkey profiles, including Synced-only, Device-bound-only, Attestation Enforced, and AAGUID-restricted configurations</li><li>Organizations using AAGUID-restricted passkey profiles will benefit from these registration optimizations. The greatest benefit is expected for Microsoft-supported passkey experiences. Other AAGUID-restricted providers continue to be supported and can be configured as before.</li></ul><p><i>Platforms and services</i></p><ul><li>Microsoft Entra ID Registration Campaign</li><li>Authentication Strengths</li><li>My Sign-Ins self-service passkey registration</li><li>Microsoft-supported passkey experiences for AAGUID-restricted profiles:<ul><li>Entra passkey on Windows</li><li>Microsoft Authenticator passkey</li><li>iCloud Keychain passkey</li><li>Google Password Manager passkey</li></ul></li></ul><p><i>What will happen</i></p><ul><li>Users will continue to register passkeys through the same registration screens and entry points they use today.</li><li>Registration will more consistently align with administrator configured passkey profile requirements.</li><li>When permitted by policy, registration will prioritize a passkey native to the user's current device to improve the sign-in experience.</li></ul><p><b>[Action required and recommendations]</b></p><p>No action is required.</p><p>Organizations should continue driving passkey adoption through Registration Campaign and Authentication Strengths. These optimizations are intended to improve the likelihood of successful passkey registration while helping users remain compliant with organizational passkey policies.</p><p><b>[Compliance considerations]</b></p><p>No compliance considerations identified. Review as appropriate for your organization.</p>

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.