Microsoft 365 Message Center item MC1469555
MC1469555 - Microsoft Entra: Optimized passkey registration campaign experience
Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoption. Eligible users will be automatically prompted based on qualifying passkey profiles. Rollout begins early September 2026. Administrators should review campaign configurations and user assignments before rollout.
- Message Center ID
- MC1469555
- Category
- plan For Change
- Severity
- normal
- Services
- Microsoft Entra
- Tags
- Feature update, User impact, Admin impact
- Published
- 2026-09-09
- Last updated
- 2026-09-09
- Expires
- 2026-10-18
[What and why]Following earlier announcements regarding passkey registration campaigns and targeting logic (MC1279092 and MC1440968), we're continuing to refine how Microsoft Entra identifies and guides eligible users toward passkey registration. These changes help increase adoption of phishing-resistant authentication while maintaining alignment with administrator-configured passkey policies. We're introducing enhancements to the Microsoft Entra registration campaign to help organizations increase passkey registration and adoption.With this change, users who are eligible to register a passkey will receive an optimized registration experience. We're also expanding the Microsoft managed registration campaign experience so that users assigned to qualifying passkey profiles can be automatically prompted to register a passkey.These updates help organizations accelerate adoption of phishing-resistant authentication while continuing to honor configured passkey policies and administrative controls.A passkey profile qualifies when it meets one of the following criteria:Passkey profile configurationQualification criteriaUnrestrictedNo passkey profile restrictions are configured.Synced-onlyOnly synced passkeys are allowed and no key restrictions are configured.Device-bound-onlyOnly device-bound passkeys are allowed and no key restrictions are configured.AAGUID-restrictedThe allow list contains at least one AAGUID for iCloud Keychain, Google Password Manager (GPM), Microsoft Authenticator passkey, or Microsoft Entra passkey on Windows.Device-bound with attestation enforcedThe profile qualifies regardless of key restrictions. Key restrictions are not evaluated.[Rollout schedule]General Availability (Worldwide, GCC): Beginning in early September 2026 and expected to complete by mid-September 2026[Impact on your organization]Who is affectedAdministrators who manage Microsoft Entra registration campaigns and passkey authentication method policiesUsers who are in scope for a registration campaign and are permitted to register passkeysPlatforms and servicesMicrosoft Entra registration campaignMicrosoft Entra authentication methods policyPasskey registration experienceWhat will happenEligible users will receive an optimized passkey registration experience.When a registration campaign is in the Microsoft managed state, Microsoft will evaluate each in-scope user's passkey profile at sign-in.Users assigned to at least one qualifying passkey profile may be prompted to register a passkey.When a registration campaign is in the Enabled state, qualifying profile checks do not apply. All in-scope users who are allowed to register passkeys may be prompted to register a passkey.Existing registration campaign scope and authentication method policies continue to determine which users are eligible to register passkeys.Note: If your registration campaign is in the Microsoft managed state and in-scope users meet one or more of the new qualifying passkey profile criteria, Microsoft managed logic may automatically update campaign targeting to include passkeys. As a result, eligible users may begin receiving passkey registration prompts after rollout.[Action required and recommendations]Review your registration campaign configuration before rollout.Recommended actions:Review users and groups that are currently in scope for your registration campaign.Review passkey profiles assigned to in-scope users.Determine whether in-scope users are assigned to qualifying passkey profiles.If you do not want Microsoft managed dynamic targeting, change the registration campaign state and directly configure targeted authentication methods.Verify that intended users are enabled for passkeys through your authentication methods policy.Learn moreConfigure the Microsoft Entra registration campaign - Enable and support passkeys in Authenticator for Microsoft Entra ID - Microsoft Entra ID | Microsoft LearnRun a Registration Campaign to Set Up a Passkey or Microsoft Authenticator - Microsoft Entra ID | Microsoft Learn[Compliance considerations]The registration campaign does not override configured passkey authentication method policies.Users can only be prompted to register passkeys permitted by their assigned passkey profiles.In the Microsoft managed state, Microsoft uses dynamic logic to determine passkey targeting and may automatically update targeted authentication methods.Administrators retain control over registration campaign scope, registration campaign state, and authentication method policies.