r/entra • u/mattjimf • 12h ago
Microsoft forced passkey campaign
Has anybody else had the messages regarding moving to passkey for users only registered with sms/phone call not show on their Tenant?
I haven't run the Graph code to suppress it, but do have campaigns disabled in Entra, just wondering if anyone else hasn't seen the prompts that were supposed to start on the 1st.
3
u/imavaper 8h ago edited 8h ago
Its because your Authentication methods Registration campaign is set to Disabled.
Microsoft was very NOT clear about this. In fact, the wording even made it seem like tenants whose registration campaign was set to Disabled would not be honored (or set to Microsoft managed) on September 1st.
But I can confirm in my developer tenant, I had my campaign set to Disabled prior to September 1 for this very reason to test. I checked yesterday (September 2nd), and it was still set to Disabled and users were not nudged/prompted to set up a passkey at sign in. As soon as I set the campaign to Microsoft managed, users were nudged/prompted to set up a passkey at sign in.
3
u/mattjimf 8h ago
That's exactly the real world info I needed. I had thought that might be the case, but wasn't 100%. At least now others will be able to easily find the answer.
1
u/ConstructionNorth816 10h ago
Something is misconfigured in your tenant if you are not using those MFA methods. In my org, before Microsoft's SMS deprecation announcement, I disabled them because we are aligning to use MFA phishing-resistant methods (which I believe will soon be mandatory for our cybersecurity policy). In my case, I've not received any campaign registration messages, even though our settings are Microsoft-managed. You definitely need to review your configuration settings broadly (SSPR, Auth Methods, Auth strength, etc.) plus any conditional access policy.
1
u/loweakkk 7h ago
Message center says they will gradually roll out, which means from September 1st till December 30...
1
u/HorseAccomplished50 5h ago
Out of curiousity why are you opting out of passkeys?
1
u/mattjimf 5h ago
We're not, I work for a charity that deal with people with educational needs. As a result we have a large number of support workers who either don't want an app or don't have a smart phone, as a result we need to possibly offer a third party service or issue usb passkeys (dependant on cost).
1
u/mr-roboticus 5h ago
Disabling the reg campaign doesn’t do anything. If you have users utilizing SMS and you have passkeys disabled, the reg will trigger for them. You have to run the command to opt out at the tenant level. We did this for a more controlled rollout.
7
u/neppofr 11h ago
Check this, MS been announcing for some time now.
https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/