Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1253746

Microsoft Entra: Passkeys in Microsoft registration campaigns

Informational

Message ID

MC1253746
View in Admin Center

Services

Microsoft Entra

Summary

Starting April 2026, Microsoft Registration Campaigns will support Passkeys (FIDO2) as an additional authentication method, enabling phishing-resistant credentials. Eligible Microsoft 365 tenants can opt users into Passkey registration nudges during sign-in. Changes will roll out gradually, affecting MFA-capable users with specific policy settings.

Details

Introduction

As previously announced in MC1221452, Microsoft Registration Campaigns will support Passkeys (FIDO2) as an additional authentication method starting in early April 2026. This update helps organizations accelerate adoption of phishing‑resistant credentials by allowing administrators to opt users into Passkeys and deliver Passkey registration nudges during sign‑in.


When this will happen 

General Availability (Worldwide): We will begin rolling out in early April 2026 and expect to complete in late May 2026.


How this affects your organization

Who is affected

  • Microsoft 365 tenants using Microsoft Registration Campaigns
  • Tenants configured in either Microsoft‑managed or Enabled states
  • Users who are MFA‑capable and eligible for Passkeys (FIDO2)

What will happen

Microsoft‑managed state

Your tenant will be impacted when all of the following conditions are met:

  • The Passkeys (FIDO2) authentication method policy is enabled.
  • Allow self‑service setup is enabled.
  • Target specific AAGUIDs is not selected (no AAGUID restrictions configured).
  • The Authentication Methods Registration Campaign state is set to Microsoft‑managed.

When these conditions are met, the following settings will update automatically:

  • The targeted authentication method will change from Microsoft Authenticator to Passkeys (FIDO2).
  • Days allowed to snooze will change from three days to one day. (This setting will no longer be configurable.)
  • Limit number of snoozes will be disabled. (This setting will no longer be configurable.)
  • Targeting will expand to all MFA‑capable users. (This setting will no longer be configurable.)
  • Default user targeting will change from voice call or text message users to all multifactor authentication (MFA)–capable users.

Affected users will receive Passkey registration nudges at sign‑in after completing MFA.

We will roll out these changes incrementally over time to in‑scope tenants.


Enabled state

Passkey (FIDO2) can be selected as the Targeted Authentication Method when Microsoft Registration Campaigns are in the Enabled state. 

Note: Registration Campaigns support targeting only one authentication method at a time—either Microsoft Authenticator or Passkeys (FIDO2), but not both simultaneously.


What you can do to prepare

Opting into Passkey Registration Nudges:

You can opt into Passkeys and switch your users to receive a Passkey registration nudge. However, the nudge will only appear for the user if all of the following conditions are met: 
  • The user is MFA‑capable
    • They have at least one registered MFA method
    • They can successfully complete MFA at sign‑in
  • Under Authentication methods > Policies, the user is in scope for Passkeys (FIDO2)
  • Under Authentication methods > Policies > Passkeys (FIDO2) > Configure, make sure you have Allow self-service set up checked. 

Important Guidance:

Microsoft Managed State:

We will roll out these changes incrementally to in-scope tenants starting in early April. This rollout will take time, and even if your tenant meets the eligibility criteria, you may not see the changes immediately. 

Enabled State 

Over time, we will incrementally refine the logic for Passkeys nudges in Microsoft Registration Campaigns to guide users toward the appropriate passkey registration experience based on their passkey profile scope. Initially, the logic may not account for every edge‑case scenario, but we are actively expanding and improving it on an ongoing basis. When users have passkey profile restrictions (for example, AAGUID restrictions), the registration experience triggered by the nudge may not be optimal.   

Using Passkeys Despite Restrictions

You can still set Passkeys as the target authentication method in Microsoft Registration Campaigns. However, users may encounter a poor or confusing experience if they have passkey profile restrictions.

Example: 

If a user is scoped into specific AAGUID synced passkeys only, they may see a Passkey nudge at sign‑in. If they attempt to register a device‑bound passkey, the registration will fail because they are not in scope for that passkey type. 

Recommended next steps

    • Review your Registration Campaign state by early April 2026.
    • Communicate this change to helpdesk or support teams.
    • Update internal documentation on authentication method enrollment.
    • If you prefer to continue targeting Microsoft Authenticator, verify this configuration before rollout.

    Learn more: How to enable passkey (FIDO2) profiles in Microsoft Entra ID (preview) | Authentication | Microsoft Entra ID | Microsoft Entra | Microsoft Learn

    Timeline

    Published
    Mar 16, 2026
    Message published to Message Center
    Updated
    Mar 16, 2026
    Message content updated
    End Date
    Jul 1, 2026
    Message timeline ends

    Tags

    #New feature#User impact#Admin impact

    Category

    Stay Informed

    Related Messages

    Similar updates

    MC1247893

    Microsoft Entra passkeys on Windows now support phishing-resistant sign-in

    Mar 9, 2026
    MC1198077

    Microsoft Entra: Cross-tenant security group synchronization

    Dec 16, 2025
    MC1221452â—Ź

    (Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants

    Jan 23, 2026
    MC1187672

    Get ready for security agents: Microsoft Security Copilot will be included in Microsoft 365 E5

    Nov 18, 2025
    MC1183299

    Microsoft Entra: Soft deletion and restoration for cloud security groups

    Nov 6, 2025