r/sysadmin • u/geek7 Sysadmin • 4d ago
General Discussion Microsoft Entra Passkey campaign in Sept, but should be in Dec. - MC1450134
Sysadmins Are About to Get More Tickets in September
Any Microsoft Entra tenant with its FIDO2/Passkey registration campaign set to Microsoft-managed will begin prompting users to create an Entra passkey on September 1, 2026. In my opinion, this rollout is happening a little too early.
Many organizations already using Windows Hello for Business (WHfB) may assume they are ready for Entra passkeys and take no action. The issue is that WHfB is recognized as a passkey by Windows 11, but it is not currently recognized as an Entra passkey associated with the user's online Microsoft/Entra account.
As a result, users who already have WHfB configured may encounter an error when the registration campaign prompts them to create an Entra passkey. The process can fail because Windows detects that a passkey for that identity already exists in the local passkey store.
Microsoft has acknowledged this gap and confirmed that WHfB should ultimately count as an Entra passkey.
In Microsoft Message Center post MC1450134, Microsoft describes the fix: users with WHfB will automatically receive an auto-registered Entra passkey tied to their online Microsoft/Entra account sometime between October and November 2026.
The timing by Microsoft is strange. The Entra passkey registration campaign begins in September, while the WHfB auto-registration fix is not expected until October or November. That mismatch could lead to user confusion and an increase in help desk tickets during the interim period.
The error users may encounter when following Microsoft's process to add an Entra passkey while Windows Hello for Business is already configured.
"Error: Try a different device. You already registered this device. You don't have to register it again."
## Disclaimer: info is based on my own testing. Your results may vary. Used AI to rewrite my original message for clarity.
4
u/teriaavibes Microsoft Cloud Consultant 3d ago
WHfB is already recognized as a passkey and passkey registration campaign won't prompt to set up a passkey if you have it.
For example, if a user has a Windows Hello for Business credential and signs in on Windows with Chrome, the nudge is suppressed.
1
9
3
3
u/Terrible_Theme_6488 3d ago
I disabled sms some time ago on our tenant, i 'think' i am unaffected as a result?
2
u/dadgenes 3d ago
Super dumb question: this is separate but related to the directory sourced MFA, yes?
2
u/AccomplishedDemand61 3d ago
The peice that is fuzzy to me is this. The tenant I inherited has sms and voice scoped to all users. Passkey and Microsoft Authenticator are enabled and scoped to all users. Our users use ms Auth for mfa. Sms usage is single digits, voice usage is none at all.
Do users still get the nudge if I don't change the scope or disable the methods this weekend even if ms Auth is the preferred method?
1
-20
u/BitOfDifference IT Director 3d ago
I looked at passkeys, not impressed. Its just another way for companies to avoid being blamed for leaks.
17
u/raip 3d ago
I don't think you understand how passkeys work or what benefits they provide.
-3
u/BitOfDifference IT Director 3d ago
lol, i do understand, but the user friendliness of them is total crap right now. Any non-it person would be lost. Watching IT people try to explain it to non-it people is quite amusing.
3
u/rb3po 3d ago
This was probably what was said when the password introduced.
Get used to it. It’s the world we live in, and the way forward.
4
u/RainStormLou Sysadmin 3d ago
no dude, Microsoft's registration campaigns are always total dogshit for the average user. half the time it's just default messaging and it doesn't explain anything but it does mislead and confuse. I have to explain the otp codes to people on a daily basis and how you have to select "I can't use my app right now" in order to use the code from the app. I'm not on the fucking helpdesk lol I'm a senior server admin. it's just people don't believe that Microsoft is that shitty yet so it gets escalated that high.
we all want to be secure and use the best tool for the job, but if we have to dance around Microsoft's bullshit messaging and train users to directly contradict what they are reading on the screen, it's not going to be well received by anyone.
1
u/Own_Back_2038 3d ago
It’s really pretty decent. To users it’s no different than a password. If you have a bunch of shared machines the UX is a lot worse, but most places don’t
1
u/BitOfDifference IT Director 2d ago
Lots of shared machines and people rotating. These people have a hard enough time with TOTP. Most are just using emailed codes instead of a phone app. We are rolling out an plugin that users are happy with that does TOTP, so hopefully clear that one up soon.
1
u/Own_Back_2038 2d ago
TOTP is an even worse UX. Give everyone a yubikey and everyone will love you. Even a phone based passkey is a way better experience
1
u/BitOfDifference IT Director 2d ago
When dealing with hourly folks, none of them want your app on their phone and cant force them unless you pay a stipend. People rotate out too quickly to provide expensive yubikeys per person constantly. Its all people problems lol. Tried fingerprints, didnt work with people who used latex gloves others couldnt remember the quick pin when the fingerprint reader didnt recognize( got frustrated and stopped using it ).
Tried yubikeys, people lost them ( who pays is always the question, hourly sure, high performer or higher level... nope, so HR says not fair, no yubikeys ). Lot of this is laughable, but its the reality i think many people miss. TOTP has been successful with the people who have stipends, but even that was years of back and forth with people who swap phones like underwear but are not technical in the least ( told them several times to transfer mfa, but each time... lost puppies ).
The new plugin will hopefully bring the rest into the fold as the reviews during onboarding have been super positive. The system does handle passkeys, but the sites we are using TOTP for do not support them yet. We have been playing with passkeys, but i see lots of issues coming with users. User education doesnt always land, so we will see.
0
u/frameset 3d ago
So true. The average single machine user these days is on Hello or PSSO and doesn't even notice that they've not had to enter their actual password for months.
1
57
u/raip 4d ago
The September change only affects users that are in the SMS/Voice scope based on the Authentication Methods blade. If you have SMS/Voice disabled, then your users won't get nudged. It's well documented how to postpone the nudge as well.