Introduction
Starting October 2027 and ending November 2027, we will retire the isAttestationEnforced and keyRestrictionsproperties from the existing fido2AuthenticationMethodConfiguration API schema. This change aligns with the latest update to the passkey policy API schema, which introduces support for granular group-based configurations with passkey profiles.
During the retirement period, isAttestationEnforced and keyRestrictions will remain in sync with their counterparts attestationEnforcement and keyRestrictions within the Default passkey profile.
When this will happen
Retirement begins in mid-October 2027 and is expected to complete by early November 2027.
How this affects your organization:
You are receiving this message because our reporting indicates your organization may be using this feature.
Who is affected: Admins managing FIDO2 authentication configurations and any custom automations or third-party integrations using these properties.
What will happen
isAttestationEnforcedandkeyRestrictionsproperties will be retired.- New properties are available in the updated passkey policy API schema.
- Existing properties will sync with new ones during the transition period.
- Automations or integrations using retired properties will stop working after the change.
What you can do to prepare
- Review your current configuration.
- Update any custom automations and third-party integrations to support the new schema.
- Notify your admins and update internal documentation.
Screenshot – The read arrows indicate the properties to be retired:
![Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy [MC1188230] 6 user settings](https://cxcs.microsoft.net/static/public/messagecenter/neutral/65c62f67-4892-44ab-bf96-5faf5aee8b82/a6b6140797dc388d8500339a8f389c62566d3321.png)
Learn more: fido2AuthenticationMethodConfiguration resource type | Microsoft Graph | Microsoft Learn
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.
Source: Microsoft
Latest Posts
- Amazon S3 now supports attribute-based access control

- App-only certificate-based authentication now available in SharePoint Online Management Shell [MC1188595]
![App-only certificate-based authentication now available in SharePoint Online Management Shell [MC1188595] 3 pexels bess hamiti 83687 36487](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Updates available for Microsoft 365 Apps for Current Channel [MC1188610]
![Updates available for Microsoft 365 Apps for Current Channel [MC1188610] 4 pexels steve 14003554](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft 365: Modern Access Request and Access Denied web page [MC1188599]
![Microsoft 365: Modern Access Request and Access Denied web page [MC1188599] 5 pexels cottonbro 7429474](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
![Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy [MC1188230] 1 Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy [MC1188230]](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-pixabay-56030-1024x683.webp)

![App-only certificate-based authentication now available in SharePoint Online Management Shell [MC1188595] 3 pexels bess hamiti 83687 36487](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-bess-hamiti-83687-36487-150x150.webp)
![Updates available for Microsoft 365 Apps for Current Channel [MC1188610] 4 pexels steve 14003554](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-steve-14003554-150x150.webp)
![Microsoft 365: Modern Access Request and Access Denied web page [MC1188599] 5 pexels cottonbro 7429474](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-cottonbro-7429474-150x150.webp)
![Microsoft 365 Copilot: Use Copilot with OneDrive files in macOS activity center [MC1187835] 8 Microsoft 365 Copilot: Use Copilot with OneDrive files in macOS activity center [MC1187835]](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-freestockpro-1003851-96x96.webp)