MC1469555: Microsoft Entra Expands Managed Campaigns and Optimizes Passkey Registration Experience

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
61
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSecurity TeamsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
The update introduces an optimized passkey registration experience and expands Microsoft managed campaign logic, affecting admins who control Entra registration campaigns and authentication policies. Admins need to review campaign configurations, qualifying passkey profiles, and dynamic targeting behaviour to prevent unintended enrolment changes. Users in scope will see new or more frequent prompts for registration, but core workflows remain functional; disruption is mainly limited to setup prompts. The change is rolling out now, and although optional configuration adjustments reduce risk, organisations should act promptly to validate targeting.
68
🛡️ Admin Impact
40
👥 User Impact
65
Urgency
60
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Microsoft Entra is improving passkey registration campaigns with better targeting and prompts to increase phishing-resistant authentication adoption.
👥

END USERS

Eligible users may see new prompts to register a passkey during sign-in.
🛡️

IT ADMINS

Review registration campaign settings and confirm passkey profiles and authentication method policies before rollout.
📅

ROLLOUT TIMELINE

Start:
Early September 2026

📢 Official Microsoft Message Center Announcement


Microsoft Entra: Optimized passkey registration campaign experience
Message ID: MC1469555

[What and why]

Following earlier announcements regarding passkey registration campaigns and targeting logic (MC1279092 and MC1440968), we’re continuing to refine how Microsoft Entra identifies and guides eligible users toward passkey registration. These changes help increase adoption of phishing-resistant authentication while maintaining alignment with administrator-configured passkey policies.

We’re introducing enhancements to the Microsoft Entra registration campaign to help organizations increase passkey registration and adoption.

With this change, users who are eligible to register a passkey will receive an optimized registration experience. We’re also expanding the Microsoft managed registration campaign experience so that users assigned to qualifying passkey profiles can be automatically prompted to register a passkey.

These updates help organizations accelerate adoption of phishing-resistant authentication while continuing to honor configured passkey policies and administrative controls.

A passkey profile qualifies when it meets one of the following criteria:

Passkey profile configurationQualification criteria
UnrestrictedNo passkey profile restrictions are configured.
Synced-onlyOnly synced passkeys are allowed and no key restrictions are configured.
Device-bound-onlyOnly device-bound passkeys are allowed and no key restrictions are configured.
AAGUID-restrictedThe allow list contains at least one AAGUID for iCloud Keychain, Google Password Manager (GPM), Microsoft Authenticator passkey, or Microsoft Entra passkey on Windows.
Device-bound with attestation enforcedThe profile qualifies regardless of key restrictions. Key restrictions are not evaluated.

[Rollout schedule]

  1. General Availability (Worldwide, GCC): Beginning in early September 2026 and expected to complete by mid-September 2026

[Impact on your organization]

Who is affected

  1. Administrators who manage Microsoft Entra registration campaigns and passkey authentication method policies
  2. Users who are in scope for a registration campaign and are permitted to register passkeys

Platforms and services

  1. Microsoft Entra registration campaign
  2. Microsoft Entra authentication methods policy
  3. Passkey registration experience

What will happen

  1. Eligible users will receive an optimized passkey registration experience.
  2. When a registration campaign is in the Microsoft managed state, Microsoft will evaluate each in-scope user’s passkey profile at sign-in.
  3. Users assigned to at least one qualifying passkey profile may be prompted to register a passkey.
  4. When a registration campaign is in the Enabled state, qualifying profile checks do not apply. All in-scope users who are allowed to register passkeys may be prompted to register a passkey.
  5. Existing registration campaign scope and authentication method policies continue to determine which users are eligible to register passkeys.

Note: If your registration campaign is in the Microsoft managed state and in-scope users meet one or more of the new qualifying passkey profile criteria, Microsoft managed logic may automatically update campaign targeting to include passkeys. As a result, eligible users may begin receiving passkey registration prompts after rollout.

[Action required and recommendations]

Review your registration campaign configuration before rollout.

Recommended actions:

  1. Review users and groups that are currently in scope for your registration campaign.
  2. Review passkey profiles assigned to in-scope users.
  3. Determine whether in-scope users are assigned to qualifying passkey profiles.
  4. If you do not want Microsoft managed dynamic targeting, change the registration campaign state and directly configure targeted authentication methods.
  5. Verify that intended users are enabled for passkeys through your authentication methods policy.

Learn more

  1. Configure the Microsoft Entra registration campaign – Enable and support passkeys in Authenticator for Microsoft Entra ID – Microsoft Entra ID | Microsoft Learn
  2. Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator – Microsoft Entra ID | Microsoft Learn

[Compliance considerations]

  1. The registration campaign does not override configured passkey authentication method policies.
  2. Users can only be prompted to register passkeys permitted by their assigned passkey profiles.
  3. In the Microsoft managed state, Microsoft uses dynamic logic to determine passkey targeting and may automatically update targeted authentication methods.
  4. Administrators retain control over registration campaign scope, registration campaign state, and authentication method policies.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update