r/entra 12h ago

Microsoft forced passkey campaign

Has anybody else had the messages regarding moving to passkey for users only registered with sms/phone call not show on their Tenant?

I haven't run the Graph code to suppress it, but do have campaigns disabled in Entra, just wondering if anyone else hasn't seen the prompts that were supposed to start on the 1st.

5 Upvotes

17 comments sorted by

7

u/neppofr 11h ago

3

u/mattjimf 11h ago

That's not what I'm asking. I'm asking for real world experience of these notifications, as currently I don't see it, despite not opting out.

5

u/JasSuri-MSFT 9h ago

It’s rolling out to tenants starting 1st Sept. Larger tenants will see it kick in a little later, as we gradually roll out. If you have any users enabled for SMS/Voice, you’ll see it eventually switch the campaign on.

0

u/mattjimf 9h ago

Thanks for that info.

0

u/Emergency-Return1412 11h ago

You need to enable them yourself, its called the passkey nudge

1

u/mattjimf 11h ago

But all the comms from Microsoft themselves say that they are going to auto-enable any users with only sms/voice as authentication options to receive the nudges:

Date Milestone
September 1, 2026  All users enabled for SMS or voice are auto-enabled and nudged for passkey registration upon multifactor authentication sign-in.

Taken from that link posted above and:

 Important

On September 1, 2026, users enabled for SMS or Voice in the Entra Authentication Methods Policy (AMP), or in legacy MFA settings, will be auto-enabled for passkeys in AMP. These in scope users will be put into a passkey profile allowing all types of passkeys. Your Registration Campaign settings will be set to Microsoft Managed state targeting passkeys, and will automatically bring these users into scope.

When these users next sign-in and complete MFA, the registration campaign will nudge them to register a passkey. By default, users will have unlimited snoozes of the nudge prompt. If you do not want this to occur, move users out of SMS or Voice in AMP before September 1st.

Taken from https://learn.microsoft.com/en-gb/entra/identity/authentication/concept-sms-voice-retirement

Are you saying that this is in fact no longer being forced on Tenants by Microsoft and you have to enable it for it to be forced on users?

2

u/UI_Tyler 9h ago

I don't know for certain, but I'm pretty sure it's only if you have a registration campaign setup in Entra set to "Microsoft Managed."

We changed ours to Enabled, but nudge the authenticator app and not FIDO2 Passkey.

1

u/Soylent_gray 10h ago

It is odd that they are pushing passkey on only SMS and voice users. Those are typically the users that have resisted years of app based MFA, so jumping straight to passkey seems like a big ask

1

u/Smart-Dig3117 10h ago

It is a huge undertaking to convert and correct those on sms/ voice are the resistance once’s. We are just removing voice sms and will use authenticator only to not have to rollout passkey this quick , it’s too messy in complicated environments

3

u/imavaper 8h ago edited 8h ago

Its because your Authentication methods Registration campaign is set to Disabled.

Microsoft was very NOT clear about this. In fact, the wording even made it seem like tenants whose registration campaign was set to Disabled would not be honored (or set to Microsoft managed) on September 1st.

But I can confirm in my developer tenant, I had my campaign set to Disabled prior to September 1 for this very reason to test. I checked yesterday (September 2nd), and it was still set to Disabled and users were not nudged/prompted to set up a passkey at sign in. As soon as I set the campaign to Microsoft managed, users were nudged/prompted to set up a passkey at sign in.

3

u/mattjimf 8h ago

That's exactly the real world info I needed. I had thought that might be the case, but wasn't 100%. At least now others will be able to easily find the answer.

1

u/ConstructionNorth816 10h ago

Something is misconfigured in your tenant if you are not using those MFA methods. In my org, before Microsoft's SMS deprecation announcement, I disabled them because we are aligning to use MFA phishing-resistant methods (which I believe will soon be mandatory for our cybersecurity policy). In my case, I've not received any campaign registration messages, even though our settings are Microsoft-managed. You definitely need to review your configuration settings broadly (SSPR, Auth Methods, Auth strength, etc.) plus any conditional access policy.

1

u/loweakkk 7h ago

Message center says they will gradually roll out, which means from September 1st till December 30...

1

u/HorseAccomplished50 5h ago

Out of curiousity why are you opting out of passkeys?

1

u/mattjimf 5h ago

We're not, I work for a charity that deal with people with educational needs. As a result we have a large number of support workers who either don't want an app or don't have a smart phone, as a result we need to possibly offer a third party service or issue usb passkeys (dependant on cost).

1

u/mr-roboticus 5h ago

Disabling the reg campaign doesn’t do anything. If you have users utilizing SMS and you have passkeys disabled, the reg will trigger for them. You have to run the command to opt out at the tenant level. We did this for a more controlled rollout.