Take a look and decide whether this affects your tenant, users or support teams.
Primary Audience
Why this score?
AT A GLANCE
END USERS
IT ADMINS
ROLLOUT TIMELINE
Mid-October 2026
📢 Official Microsoft Message Center Announcement
Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method
Message ID: MC1450133
[What and why]
Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method like SMS or Voice before they could add a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey, making it easier to adopt strong authentication from day one. As part of this work, we will also be enabling Authenticator App passwordless sign-in to be a user’s first registered MFA method.
[Rollout schedule]
This feature will roll out in phases:
Phase 1: Support for synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys.
General Availability (Worldwide, GCC): We will begin rolling out in mid-October 2026 and expect to complete by mid-November 2026.
Phase 2: Support for Windows Hello for Business, macOS Platform SSO, and Authenticator App passwordless sign-in.
General Availability (Worldwide, GCC): We will begin rolling out in early January 2026 and expect to complete by late February 2027.
[Impact on your organization]
Who is affected
- Users who have not yet registered a multifactor authentication method
- Identity and security administrators responsible for authentication onboarding and registration policies
Platforms and services
- Microsoft Entra ID
- Passkeys (FIDO2)
- Windows Hello for Business
- macOS Platform SSO
- Microsoft Authenticator passwordless sign-in
What will happen
- Password-only users will be able to register passkeys or passwordless sign-in as their first MFA method.
- Users will no longer need to register a method such as SMS or voice before registering a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO, or Authenticator passwordless sign-in.
- Organizations may see reduced registration friction and increased adoption of phishing-resistant authentication methods.
[Action required and recommendations]
No action is required for this change.
We recommend that administrators:
- Review Conditional Access policies related to security information registration.
- Consider requiring MFA to register security information if additional verification is required by your organization.
- Review onboarding and registration guidance so users know to set up a passkey as their preferred first method.
Learn more
- (To be updated closer to rollout) Register a synced passkey (FIDO2) | Authentication | Microsoft Entra ID | Microsoft Learn
[Compliance considerations]
| Question | Answer |
| Does the change include an admin control? | Yes. Administrators can control which authentication methods users are allowed to register through existing Microsoft Entra authentication method policies and Conditional Access policies. |
| Does the change affect access or authentication controls? | Yes. The update changes how users register multifactor authentication methods by allowing eligible users to register supported passkeys or passwordless authentication methods as their first MFA method. |
| Can administrators govern the feature through existing Microsoft Entra controls? | Yes. Administrators retain control over the feature through Microsoft Entra authentication method policies and Conditional Access configurations. |
Source: Microsoft Message Center • Analysed by MWPro


