SHD / MC Checker

MC1440968 | Microsoft Entra ID: Optimizations for passkey registration experience



MC1440968 | Microsoft Entra ID: Optimizations for passkey registration experience

Classification stayInformed
Last Updated 07/27/2026 22:53:36
Start Time 07/27/2026 22:53:27
End Time 09/28/2026 07:00:00
Message Content

[What and why]

We’re rolling out optimizations to passkey registration across Microsoft Entra ID. These changes improve how passkey registration is handled through Registration Campaign, Authentication Strengths, and My Sign-Ins.

The updated registration logic will more consistently:

  • Guide users to register passkey types that comply with administrator configured passkey profile restrictions, reducing unsuccessful or non-compliant registration attempts.
  • Prioritize registration of a passkey that is local to the user’s current device when permitted by policy.

These improvements are designed to increase successful passkey registrations, reduce registration friction, and help organizations strengthen adoption of phishing resistant authentication methods.

There are no user interface changes associated with this update.

[Rollout schedule]

  • General Availability (Worldwide and GCC): Beginning in late August 2026 and expected to complete in late August 2026

[Impact on your organization]

Who is affected

  • Users who register passkeys through Registration Campaign, Authentication Strengths, or My Sign-Ins
  • Organizations using passkey profiles, including Synced-only, Device-bound-only, Attestation Enforced, and AAGUID-restricted configurations
  • Organizations using AAGUID-restricted passkey profiles will benefit from these registration optimizations. The greatest benefit is expected for Microsoft-supported passkey experiences. Other AAGUID-restricted providers continue to be supported and can be configured as before.

Platforms and services

  • Microsoft Entra ID Registration Campaign
  • Authentication Strengths
  • My Sign-Ins self-service passkey registration
  • Microsoft-supported passkey experiences for AAGUID-restricted profiles:
    • Entra passkey on Windows
    • Microsoft Authenticator passkey
    • iCloud Keychain passkey
    • Google Password Manager passkey

What will happen

  • Users will continue to register passkeys through the same registration screens and entry points they use today.
  • Registration will more consistently align with administrator configured passkey profile requirements.
  • When permitted by policy, registration will prioritize a passkey native to the user’s current device to improve the sign-in experience.

[Action required and recommendations]

No action is required.

Organizations should continue driving passkey adoption through Registration Campaign and Authentication Strengths. These optimizations are intended to improve the likelihood of successful passkey registration while helping users remain compliant with organizational passkey policies.

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Machine Translation

[何となぜ]

Microsoft Entra ID全体でパスキー登録の最適化を展開しています。これらの変更により、 登録キャンペーン認証の強さマイサインインを通じてパスキー登録の扱いが改善されます。

更新された登録ロジックにより、より一貫性が示されます:

  • 管理者が設定したパスキープロファイルの制限に準拠したパスキータイプを登録するようユーザーに案内し、不成功や不適合の登録試行を減らすこと。
  • ポリシーで許可されている場合、ユーザーの現在のデバイスにローカル なパスキーの登録を優先してください。

これらの改善は、パスキー登録の成功率を高め、登録の摩擦を減らし、組織がフィッシング耐性認証手法の採用を強化することを目的としています。

このアップデートに伴う ユーザーインターフェースの変更はありません

[展開スケジュール]

  • 一般稼働(世界およびGCC): 2026年8月下旬から始まり、2026年8月下旬に完了予定です

[組織への影響]

影響を受ける人物

  • 登録キャンペーン、認証強度、または私のサインインを通じてパスキーを登録するユーザーはいます
  • パスキープロファイルを使用している組織(同期のみ、デバイスバウンドのみ、認証強制、AAGUID制限設定など)
  • AAGUID制限付きパスキープロファイルを使用している組織は、これらの登録最適化の恩恵を受けられます。最大のメリットはMicrosoft対応のパスキー体験に期待されます。他のAAGUID制限付きプロバイダーも引き続きサポートされており、以前と同様に設定可能です。

ホームとサービス

  • Microsoft Entra ID Registration Campaign
  • 認証の強み
  • 私のサインイン セルフサービスパスキー登録
  • AAGUID制限プロファイル向けのMicrosoftサポートパスキー体験:
    • Windows での Entra パスキー
    • Microsoft Authenticator パスキー
    • iCloudキーチェーンのパスキー
    • Googleパスワードマネージャーのパスキー

何が起こるのか

  • ユーザーは現在使用しているのと同じ登録画面と入り口を通じてパスキーの登録を継続します。
  • 登録は管理者が設定したパスキープロファイルの要件により一貫して一致します。
  • ポリシーで許可されている場合、登録はユーザーの現在のデバイスに固有のパスキーを優先し、サインイン体験を向上させます。

[行動が必要と提言]

何の対応も必要ありません。

組織は登録キャンペーンと認証の強みを通じてパスキー導入を推進し続けるべきです。これらの最適化は、パスキー登録の成功率を高めるとともに、ユーザーが組織のパスキーポリシーに準拠し続けることを目的としています。

[コンプライアンスの考慮事項]

コンプライアンス上の考慮事項は特定されていません。組織に応じた適切なレビューを行ってください。