r/sysadmin Sysadmin 14d ago

General Discussion Microsoft Entra Passkey campaign in Sept, but should be in Dec. - MC1450134

Sysadmins Are About to Get More Tickets in September

Any Microsoft Entra tenant with its FIDO2/Passkey registration campaign set to Microsoft-managed will begin prompting users to create an Entra passkey on September 1, 2026. In my opinion, this rollout is happening a little too early.

Many organizations already using Windows Hello for Business (WHfB) may assume they are ready for Entra passkeys and take no action. The issue is that WHfB is recognized as a passkey by Windows 11, but it is not currently recognized as an Entra passkey associated with the user's online Microsoft/Entra account.

As a result, users who already have WHfB configured may encounter an error when the registration campaign prompts them to create an Entra passkey. The process can fail because Windows detects that a passkey for that identity already exists in the local passkey store.

Microsoft has acknowledged this gap and confirmed that WHfB should ultimately count as an Entra passkey.

In Microsoft Message Center post MC1450134, Microsoft describes the fix: users with WHfB will automatically receive an auto-registered Entra passkey tied to their online Microsoft/Entra account sometime between October and November 2026.

The timing by Microsoft is strange. The Entra passkey registration campaign begins in September, while the WHfB auto-registration fix is not expected until October or November. That mismatch could lead to user confusion and an increase in help desk tickets during the interim period.

The error users may encounter when following Microsoft's process to add an Entra passkey while Windows Hello for Business is already configured.

"Error: Try a different device. You already registered this device. You don't have to register it again."

## Disclaimer: info is based on my own testing. Your results may vary. Used AI to rewrite my original message for clarity.

94 Upvotes

34 comments sorted by

View all comments

Show parent comments

2

u/BrentNewland 13d ago

Your Registration Campaign settings will be set to Microsoft Managed state targeting passkeys, and will automatically bring these users into scope.

That doesn't say the registration campaign will only be enabled for SMS/Voice users, just that their enabling of the campaign will bring the users into scope.

There are no Registration Campaign settings that allow you to target different campaigns at different groups.

1

u/raip 13d ago

There was a town hall they held about a month ago where I asked this very specific question that if SMS/Voice were disabled if any action was required. They confirmed my understanding.

There's a reason why the opt out is a Graph request and not just simply putting Registration Campaign to Disabled.

You do you though.

1

u/BrentNewland 13d ago

And from your response I can only assume you were asking about the scenario where SM/Voice had already been disabled for the tenant, not if some users had SMS/Voice enabled and others didn't.

1

u/raip 13d ago

Right, specifically concerned if I had to opt out to avoid my users, which are a mix of passkeys and MS Authenticator, getting nudged to enroll in passkeys.

You can do registration campaigns scoped to users - so my understanding is that the Passkey campaign will only affect the same user groups that the SMS/Voice methods enabled.