Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Microsoft Entra: Optimized passkey registration campaign experience

Message ID
MC1469555
View in Message Center
Service
Microsoft Entra
Category
Plan for Change
Tags
Feature updateUser impactAdmin impact
Rollout
September 2026

Summary

Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoption. Eligible users will be automatically prompted based on qualifying passkey profiles. Rollout begins early September 2026. Administrators should review campaign configurations and user assignments before rollout.

Details

[What and why]

Following earlier announcements regarding passkey registration campaigns and targeting logic (MC1279092 and MC1440968), we're continuing to refine how Microsoft Entra identifies and guides eligible users toward passkey registration. These changes help increase adoption of phishing-resistant authentication while maintaining alignment with administrator-configured passkey policies.

We're introducing enhancements to the Microsoft Entra registration campaign to help organizations increase passkey registration and adoption.

With this change, users who are eligible to register a passkey will receive an optimized registration experience. We're also expanding the Microsoft managed registration campaign experience so that users assigned to qualifying passkey profiles can be automatically prompted to register a passkey.

These updates help organizations accelerate adoption of phishing-resistant authentication while continuing to honor configured passkey policies and administrative controls.

A passkey profile qualifies when it meets one of the following criteria:

Passkey profile configurationQualification criteria
UnrestrictedNo passkey profile restrictions are configured.
Synced-onlyOnly synced passkeys are allowed and no key restrictions are configured.
Device-bound-onlyOnly device-bound passkeys are allowed and no key restrictions are configured.
AAGUID-restrictedThe allow list contains at least one AAGUID for iCloud Keychain, Google Password Manager (GPM), Microsoft Authenticator passkey, or Microsoft Entra passkey on Windows.
Device-bound with attestation enforcedThe profile qualifies regardless of key restrictions. Key restrictions are not evaluated.

[Rollout schedule]

  1. General Availability (Worldwide, GCC): Beginning in early September 2026 and expected to complete by mid-September 2026

[Impact on your organization]

Who is affected

  1. Administrators who manage Microsoft Entra registration campaigns and passkey authentication method policies
  2. Users who are in scope for a registration campaign and are permitted to register passkeys

Platforms and services

  1. Microsoft Entra registration campaign
  2. Microsoft Entra authentication methods policy
  3. Passkey registration experience

What will happen

  1. Eligible users will receive an optimized passkey registration experience.
  2. When a registration campaign is in the Microsoft managed state, Microsoft will evaluate each in-scope user's passkey profile at sign-in.
  3. Users assigned to at least one qualifying passkey profile may be prompted to register a passkey.
  4. When a registration campaign is in the Enabled state, qualifying profile checks do not apply. All in-scope users who are allowed to register passkeys may be prompted to register a passkey.
  5. Existing registration campaign scope and authentication method policies continue to determine which users are eligible to register passkeys.

Note: If your registration campaign is in the Microsoft managed state and in-scope users meet one or more of the new qualifying passkey profile criteria, Microsoft managed logic may automatically update campaign targeting to include passkeys. As a result, eligible users may begin receiving passkey registration prompts after rollout.

[Action required and recommendations]

Review your registration campaign configuration before rollout.

Recommended actions:

  1. Review users and groups that are currently in scope for your registration campaign.
  2. Review passkey profiles assigned to in-scope users.
  3. Determine whether in-scope users are assigned to qualifying passkey profiles.
  4. If you do not want Microsoft managed dynamic targeting, change the registration campaign state and directly configure targeted authentication methods.
  5. Verify that intended users are enabled for passkeys through your authentication methods policy.

Learn more

  1. Configure the Microsoft Entra registration campaign - Enable and support passkeys in Authenticator for Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn
  2. Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator - Microsoft Entra ID | Microsoft Learn

[Compliance considerations]

  1. The registration campaign does not override configured passkey authentication method policies.
  2. Users can only be prompted to register passkeys permitted by their assigned passkey profiles.
  3. In the Microsoft managed state, Microsoft uses dynamic logic to determine passkey targeting and may automatically update targeted authentication methods.
  4. Administrators retain control over registration campaign scope, registration campaign state, and authentication method policies.

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.