What and why
Following earlier announcements regarding passkey registration campaigns and targeting logic (MC1279092 and MC1440968), we're continuing to refine how Microsoft Entra identifies and guides eligible users toward passkey registration. These changes help increase adoption of phishing-resistant authentication while maintaining alignment with administrator-configured passkey policies.
We're introducing enhancements to the Microsoft Entra registration campaign to help organizations increase passkey registration and adoption.
With this change, users who are eligible to register a passkey will receive an optimized registration experience. We're also expanding the Microsoft managed registration campaign experience so that users assigned to qualifying passkey profiles can be automatically prompted to register a passkey.
These updates help organizations accelerate adoption of phishing-resistant authentication while continuing to honor configured passkey policies and administrative controls.
A passkey profile qualifies when it meets one of the following criteria:
| Passkey profile configuration | Qualification criteria |
| Unrestricted | No passkey profile restrictions are configured. |
| Synced-only | Only synced passkeys are allowed and no key restrictions are configured. |
| Device-bound-only | Only device-bound passkeys are allowed and no key restrictions are configured. |
| AAGUID-restricted | The allow list contains at least one AAGUID for iCloud Keychain, Google Password Manager (GPM), Microsoft Authenticator passkey, or Microsoft Entra passkey on Windows. |
| Device-bound with attestation enforced | The profile qualifies regardless of key restrictions. Key restrictions are not evaluated. |
Rollout schedule
- General Availability (Worldwide, GCC): Beginning in early September 2026 and expected to complete by mid-September 2026
Impact on your organization
Who is affected
- Administrators who manage Microsoft Entra registration campaigns and passkey authentication method policies
- Users who are in scope for a registration campaign and are permitted to register passkeys
Platforms and services
- Microsoft Entra registration campaign
- Microsoft Entra authentication methods policy
- Passkey registration experience
What will happen
- Eligible users will receive an optimized passkey registration experience.
- When a registration campaign is in the Microsoft managed state, Microsoft will evaluate each in-scope user's passkey profile at sign-in.
- Users assigned to at least one qualifying passkey profile may be prompted to register a passkey.
- When a registration campaign is in the Enabled state, qualifying profile checks do not apply. All in-scope users who are allowed to register passkeys may be prompted to register a passkey.
- Existing registration campaign scope and authentication method policies continue to determine which users are eligible to register passkeys.
Note: If your registration campaign is in the Microsoft managed state and in-scope users meet one or more of the new qualifying passkey profile criteria, Microsoft managed logic may automatically update campaign targeting to include passkeys. As a result, eligible users may begin receiving passkey registration prompts after rollout.
Action required and recommendations
Review your registration campaign configuration before rollout.
Recommended actions:
- Review users and groups that are currently in scope for your registration campaign.
- Review passkey profiles assigned to in-scope users.
- Determine whether in-scope users are assigned to qualifying passkey profiles.
- If you do not want Microsoft managed dynamic targeting, change the registration campaign state and directly configure targeted authentication methods.
- Verify that intended users are enabled for passkeys through your authentication methods policy.
Learn more
- Configure the Microsoft Entra registration campaign - Enable and support passkeys in Authenticator for Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn
- Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator - Microsoft Entra ID | Microsoft Learn
Compliance considerations
- The registration campaign does not override configured passkey authentication method policies.
- Users can only be prompted to register passkeys permitted by their assigned passkey profiles.
- In the Microsoft managed state, Microsoft uses dynamic logic to determine passkey targeting and may automatically update targeted authentication methods.
- Administrators retain control over registration campaign scope, registration campaign state, and authentication method policies.