MC1450133: Microsoft Entra ID Adds Passkey and Passwordless Sign-In as First Multifactor Authentication Method

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
59
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
▶ What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Microsoft 365 AdminsSecurity TeamsCompliance TeamsIT ManagersTenant AdminsService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
Microsoft has pushed back the rollout schedule for enabling users to register a passkey or passwordless method as their first multifactor authentication option. This directly affects sign-in onboarding, authentication policy configuration, and related Conditional Access rules. While no immediate action is required, admins should review registration policies and onboarding materials before release. The change improves security posture and reduces registration friction, so preparation and internal guidance updates are advisable.
70
🛡️ Admin Impact
45
👥 User Impact
55
⚡ Urgency
50
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Users can now register a passkey or passwordless sign-in as their first MFA method, removing the need for SMS or voice setup first and helping speed up adoption of stronger sign-in options.
👥

END USERS

Users may register a passkey or passwordless sign-in as their first MFA method.
🛡️

IT ADMINS

Review Conditional Access and authentication method policies before rollout.
📅

ROLLOUT TIMELINE

Start:
October 2026

📢 Official Microsoft Message Center Announcement


Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method
Message ID: MC1450133 (Updated)

Updated October 8, 2026: We have updated the timeline. Thank you for your patience. 

[What and why]

Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method like SMS or Voice before they could add a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey, making it easier to adopt strong authentication from day one. As part of this work, we will also be enabling Authenticator App passwordless sign-in to be a user’s first registered MFA method. 

[Rollout schedule]

This feature will roll out in phases: 

Phase 1: Support for synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys.  

General Availability (Worldwide, GCC): We will begin rolling out in late October 2026 (previously early October) and expect to complete by late November 2026 (previously mid-November). 

Phase 2: Support for Windows Hello for Business, macOS Platform SSO, Authenticator App passkey, and Authenticator App passwordless sign-in. 

General Availability (Worldwide, GCC): We will begin rolling out in early January 2026 and expect to complete by late February 2027. 

[Impact on your organization]

Who is affected

  • Users who have not yet registered a multifactor authentication method
  • Identity and security administrators responsible for authentication onboarding and registration policies

Platforms and services

  • Microsoft Entra ID
  • Passkeys (FIDO2)
  • Windows Hello for Business
  • macOS Platform SSO
  • Microsoft Authenticator passwordless sign-in

What will happen

  • Password-only users will be able to register passkeys or passwordless sign-in as their first MFA method.
  • Users will no longer need to register a method such as SMS or voice before registering a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO, or Authenticator passwordless sign-in.
  • Organizations may see reduced registration friction and increased adoption of phishing-resistant authentication methods.

[Action required and recommendations]

No action is required for this change.

We recommend that administrators:

  • Review Conditional Access policies related to security information registration.
  • Consider requiring MFA to register security information if additional verification is required by your organization.
  • Review onboarding and registration guidance so users know to set up a passkey as their preferred first method.

Learn more 

[Compliance considerations]

QuestionAnswer
Does the change include an admin control?Yes. Administrators can control which authentication methods users are allowed to register through existing Microsoft Entra authentication method policies and Conditional Access policies.
Does the change affect access or authentication controls?Yes. The update changes how users register multifactor authentication methods by allowing eligible users to register supported passkeys or passwordless authentication methods as their first MFA method.
Can administrators govern the feature through existing Microsoft Entra controls?Yes. Administrators retain control over the feature through Microsoft Entra authentication method policies and Conditional Access configurations.

Source: Microsoft Message Center • Analysed by MWPro

<<< [MC1450133] Archive
Tooltip: View earlier revisions of this post

Share This Update