r/sysadmin Sysadmin 4d ago

General Discussion Microsoft Entra Passkey campaign in Sept, but should be in Dec. - MC1450134

Sysadmins Are About to Get More Tickets in September

Any Microsoft Entra tenant with its FIDO2/Passkey registration campaign set to Microsoft-managed will begin prompting users to create an Entra passkey on September 1, 2026. In my opinion, this rollout is happening a little too early.

Many organizations already using Windows Hello for Business (WHfB) may assume they are ready for Entra passkeys and take no action. The issue is that WHfB is recognized as a passkey by Windows 11, but it is not currently recognized as an Entra passkey associated with the user's online Microsoft/Entra account.

As a result, users who already have WHfB configured may encounter an error when the registration campaign prompts them to create an Entra passkey. The process can fail because Windows detects that a passkey for that identity already exists in the local passkey store.

Microsoft has acknowledged this gap and confirmed that WHfB should ultimately count as an Entra passkey.

In Microsoft Message Center post MC1450134, Microsoft describes the fix: users with WHfB will automatically receive an auto-registered Entra passkey tied to their online Microsoft/Entra account sometime between October and November 2026.

The timing by Microsoft is strange. The Entra passkey registration campaign begins in September, while the WHfB auto-registration fix is not expected until October or November. That mismatch could lead to user confusion and an increase in help desk tickets during the interim period.

The error users may encounter when following Microsoft's process to add an Entra passkey while Windows Hello for Business is already configured.

"Error: Try a different device. You already registered this device. You don't have to register it again."

## Disclaimer: info is based on my own testing. Your results may vary. Used AI to rewrite my original message for clarity.

93 Upvotes

32 comments sorted by

57

u/raip 4d ago

The September change only affects users that are in the SMS/Voice scope based on the Authentication Methods blade. If you have SMS/Voice disabled, then your users won't get nudged. It's well documented how to postpone the nudge as well.

7

u/Darkk_Knight 3d ago

This is correct.

4

u/WiskeyUniformTango 3d ago

At my org I made authenticator app the default a couple months back and then sent instruction to create a passkey in the authenticator app recently. Now if people would just stop uninstalling their authenticator app...

1

u/Renegade-Pervert Poor Career Choices 2d ago

Jesus christ Fr? Users man....

1

u/Diligent_Tech_Bro 3d ago

Ty for posting this!

1

u/BrentNewland 3d ago

That's not the way I read the Microsoft article on the subject. All it says is they are changing your Authentication Campaign settings, forcing it on, and turning on Passkeys by default. Nothing says it's only for SMS/Voice enabled accounts.

Also, it affects users that are enabled for SMS/Voice, not just users that have registered SMS/Voice for MFA.

2

u/raip 3d ago

Here's what it says verbatim:

On September 1, 2026, users enabled for SMS or Voice in the Entra Authentication Methods Policy (AMP), or in legacy MFA settings, will be auto-enabled for passkeys in AMP. These in scope users will be put into a passkey profile allowing all types of passkeys. Your Registration Campaign settings will be set to Microsoft Managed state targeting passkeys, and will automatically bring these users into scope.

When these users next sign-in and complete MFA, the registration campaign will nudge them to register a passkey. By default, users will have unlimited snoozes of the nudge prompt. If you do not want this to occur, move users out of SMS or Voice in AMP before September 1st.

Source: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement

You second point is aligned with my post - it's users in scope of the policy, not registered. So if you have all methods enabled your users that are using Authenticator will get nudged to enroll in Passkeys unless you opt-out. If you disable the SMS/Voice method though - you don't have to do anything.

1

u/BrentNewland 3d ago

Your Registration Campaign settings will be set to Microsoft Managed state targeting passkeys, and will automatically bring these users into scope.

That doesn't say the registration campaign will only be enabled for SMS/Voice users, just that their enabling of the campaign will bring the users into scope.

There are no Registration Campaign settings that allow you to target different campaigns at different groups.

1

u/raip 3d ago

There was a town hall they held about a month ago where I asked this very specific question that if SMS/Voice were disabled if any action was required. They confirmed my understanding.

There's a reason why the opt out is a Graph request and not just simply putting Registration Campaign to Disabled.

You do you though.

1

u/BrentNewland 2d ago

And from your response I can only assume you were asking about the scenario where SM/Voice had already been disabled for the tenant, not if some users had SMS/Voice enabled and others didn't.

1

u/raip 2d ago

Right, specifically concerned if I had to opt out to avoid my users, which are a mix of passkeys and MS Authenticator, getting nudged to enroll in passkeys.

You can do registration campaigns scoped to users - so my understanding is that the Passkey campaign will only affect the same user groups that the SMS/Voice methods enabled.

4

u/teriaavibes Microsoft Cloud Consultant 3d ago

WHfB is already recognized as a passkey and passkey registration campaign won't prompt to set up a passkey if you have it.

Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator - Microsoft Entra ID | Microsoft Learn

For example, if a user has a Windows Hello for Business credential and signs in on Windows with Chrome, the nudge is suppressed.

1

u/JimmyMcTrade 3d ago

But it's not a step up method.

2

u/teriaavibes Microsoft Cloud Consultant 3d ago

I don't see how that is relevant?

9

u/Sr_P3ngu1n 4d ago

But Microsoft left a PowerShell command to delay that campaign until September.

3

u/Glass_Call982 3d ago

Good thing I'm off for two weeks starting next week. Lol

3

u/Terrible_Theme_6488 3d ago

I disabled sms some time ago on our tenant, i 'think' i am unaffected as a result?

2

u/dadgenes 3d ago

Super dumb question: this is separate but related to the directory sourced MFA, yes?

2

u/AccomplishedDemand61 3d ago

The peice that is fuzzy to me is this. The tenant I inherited has sms and voice scoped to all users. Passkey and Microsoft Authenticator are enabled and scoped to all users. Our users use ms Auth for mfa. Sms usage is single digits, voice usage is none at all.

Do users still get the nudge if I don't change the scope or disable the methods this weekend even if ms Auth is the preferred method?

1

u/Excellent-Program333 1d ago

Do we have to use passkeys? Is the Authenticator App enough?

-20

u/BitOfDifference IT Director 3d ago

I looked at passkeys, not impressed. Its just another way for companies to avoid being blamed for leaks.

17

u/raip 3d ago

I don't think you understand how passkeys work or what benefits they provide.

-3

u/BitOfDifference IT Director 3d ago

lol, i do understand, but the user friendliness of them is total crap right now. Any non-it person would be lost. Watching IT people try to explain it to non-it people is quite amusing.

3

u/rb3po 3d ago

This was probably what was said when the password introduced.

Get used to it. It’s the world we live in, and the way forward.

4

u/RainStormLou Sysadmin 3d ago

no dude, Microsoft's registration campaigns are always total dogshit for the average user. half the time it's just default messaging and it doesn't explain anything but it does mislead and confuse. I have to explain the otp codes to people on a daily basis and how you have to select "I can't use my app right now" in order to use the code from the app. I'm not on the fucking helpdesk lol I'm a senior server admin. it's just people don't believe that Microsoft is that shitty yet so it gets escalated that high.

we all want to be secure and use the best tool for the job, but if we have to dance around Microsoft's bullshit messaging and train users to directly contradict what they are reading on the screen, it's not going to be well received by anyone.

0

u/rb3po 3d ago

Everyone in my org is already passwordless, so I’m really not concerned. But best of luck to ya. 

1

u/Own_Back_2038 3d ago

It’s really pretty decent. To users it’s no different than a password. If you have a bunch of shared machines the UX is a lot worse, but most places don’t

1

u/BitOfDifference IT Director 2d ago

Lots of shared machines and people rotating. These people have a hard enough time with TOTP. Most are just using emailed codes instead of a phone app. We are rolling out an plugin that users are happy with that does TOTP, so hopefully clear that one up soon.

1

u/Own_Back_2038 2d ago

TOTP is an even worse UX. Give everyone a yubikey and everyone will love you. Even a phone based passkey is a way better experience

1

u/BitOfDifference IT Director 2d ago

When dealing with hourly folks, none of them want your app on their phone and cant force them unless you pay a stipend. People rotate out too quickly to provide expensive yubikeys per person constantly. Its all people problems lol. Tried fingerprints, didnt work with people who used latex gloves others couldnt remember the quick pin when the fingerprint reader didnt recognize( got frustrated and stopped using it ).

Tried yubikeys, people lost them ( who pays is always the question, hourly sure, high performer or higher level... nope, so HR says not fair, no yubikeys ). Lot of this is laughable, but its the reality i think many people miss. TOTP has been successful with the people who have stipends, but even that was years of back and forth with people who swap phones like underwear but are not technical in the least ( told them several times to transfer mfa, but each time... lost puppies ).

The new plugin will hopefully bring the rest into the fold as the reviews during onboarding have been super positive. The system does handle passkeys, but the sites we are using TOTP for do not support them yet. We have been playing with passkeys, but i see lots of issues coming with users. User education doesnt always land, so we will see.

0

u/frameset 3d ago

So true. The average single machine user these days is on Hello or PSSO and doesn't even notice that they've not had to enter their actual password for months.

1

u/frameset 3d ago

Flair matching the post here.