All posts
Microsoft 365 Security 2 min read

Entra Passkey Registration Campaigns Just Got Wider Reach

Microsoft has closed a gap in Microsoft-managed passkey registration campaigns that quietly excluded users with restricted passkey profiles from ever getting a nudge. Here is what changed and what MSPs should check before the rollout finishes.

M Michael September 11, 2026
Entra Passkey Registration Campaigns Just Got Wider Reach

Microsoft Entra's automated passkey nudges have had a blind spot since they launched. If you locked down which passkey providers your tenant allowed, Microsoft's own campaign engine would often skip those users entirely.

That gap closes with message center notice MC1469555, published September 9, 2026. The updated experience is rolling out to Worldwide and GCC clouds now, with deployment expected to finish by the end of September.

What was broken

Registration campaigns set to Microsoft managed state let Microsoft pick the targeted method and eligibility rules automatically, so admins only choose who is included or excluded. Until now, that automatic eligibility check quietly dropped anyone whose passkey profile carried restrictions, including:

  • Users limited to device-bound passkeys only
  • Users limited to synced passkeys only
  • Users in AAGUID-restricted profiles, even profiles that allowed mainstream providers such as iCloud Keychain, Google Password Manager, Microsoft Authenticator, or Microsoft Entra passkey on Windows

In practice, tenants that had deliberately restricted passkey providers for security reasons, arguably the tenants most ready to push phishing-resistant sign-in, were the ones least likely to see their users nudged.

What changes

With this update, all of the passkey profile configurations above become eligible for Microsoft-managed nudges, as long as a user matches at least one qualifying profile. A user still needs a local passkey option available for their specific device and browser combination before the nudge is suppressed. Manually configured campaigns in the Enabled state are unaffected, since they never applied this eligibility filter in the first place.

What MSPs should check

Before the rollout completes in your managed tenants:

  • Identify which client tenants run passkey registration campaigns in Microsoft managed state
  • Review passkey profile AAGUID allow lists, since eligibility depends on including at least one supported provider
  • Give clients a heads up if their users have never seen a passkey nudge before. Some may start seeing one at their next sign-in without any change on the admin side.

This is exactly the kind of quiet, Microsoft-driven behavior change that is easy to miss across a large tenant portfolio until a client asks why users are suddenly being prompted. Worth a spot check across your tenant list this month.

One baseline. Every tenant. Zero subscriptions.

Self-hosted, source included, buy it once. Try the full demo offline before you pay a cent.

See pricing