MC1440968 - (Updated) Microsoft Entra ID: Optimizations for passkey registration experience

Microsoft 365 Message Center announcement MC1440968.

Microsoft Summary

Microsoft Entra ID is optimizing passkey registration to better align with administrator policies, prioritize local device passkeys, and improve successful registrations without UI changes. The rollout begins late August 2026, completing by mid-September. No action is required; organizations should continue promoting passkey adoption.

Message Center ID
MC1440968
Category
stay Informed
Severity
normal
Services
Microsoft Entra
Tags
Updated message, New feature, User impact, Admin impact
Published
2026-07-27
Last updated
2026-09-04
Expires
2026-10-19

Updated September 4, 2026: We have updated the timeline. Thank you for your patience. [What and why] We're rolling out optimizations to passkey registration across Microsoft Entra ID. These changes improve how passkey registration is handled through Registration Campaign , Authentication Strengths , and My Sign-Ins . The updated registration logic will more consistently: Guide users to register passkey types that comply with administrator configured passkey profile restrictions, reducing unsuccessful or non-compliant registration attempts. Prioritize registration of a passkey that is local to the user's current device when permitted by policy. These improvements are designed to increase successful passkey registrations, reduce registration friction, and help organizations strengthen adoption of phishing resistant authentication methods. There are no user interface changes associated with this update. [Rollout schedule] General Availability (Worldwide and GCC): Beginning in late August 2026 and expected to complete by mid-September 2026 (previously late August) [Impact on your organization] Who is affected Users who register passkeys through Registration Campaign, Authentication Strengths, or My Sign-Ins Organizations using passkey profiles, including Synced-only, Device-bound-only, Attestation Enforced, and AAGUID-restricted configurations Organizations using AAGUID-restricted passkey profiles will benefit from these registration optimizations. The greatest benefit is expected for Microsoft-supported passkey experiences. Other AAGUID-restricted providers continue to be supported and can be configured as before. Platforms and services Microsoft Entra ID Registration Campaign Authentication Strengths My Sign-Ins self-service passkey registration Microsoft-supported passkey experiences for AAGUID-restricted profiles: Entra passkey on Windows Microsoft Authenticator passkey iCloud Keychain passkey Google Password Manager passkey What will happen Users will continue to register passkeys through the same registration screens and entry points they use today. Registration will more consistently align with administrator configured passkey profile requirements. When permitted by policy, registration will prioritize a passkey native to the user's current device to improve the sign-in experience. [Action required and recommendations] No action is required. Organizations should continue driving passkey adoption through Registration Campaign and Authentication Strengths. These optimizations are intended to improve the likelihood of successful passkey registration while helping users remain compliant with organizational passkey policies. [Compliance considerations] No compliance considerations identified. Review as appropriate for your organization.