| MC1450133 | Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method |
|---|
| Classification | stayInformed | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Last Updated | 08/07/2026 21:55:51 | ||||||||
| Start Time | 08/07/2026 21:55:44 | ||||||||
| End Time | 03/29/2027 07:00:00 | ||||||||
| Message Content |
[What and why] Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method like SMS or Voice before they could add a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey, making it easier to adopt strong authentication from day one. As part of this work, we will also be enabling Authenticator App passwordless sign-in to be a user’s first registered MFA method. [Rollout schedule] This feature will roll out in phases: Phase 1: Support for synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys. General Availability (Worldwide, GCC): We will begin rolling out in mid-October 2026 and expect to complete by mid-November 2026. Phase 2: Support for Windows Hello for Business, macOS Platform SSO, and Authenticator App passwordless sign-in. General Availability (Worldwide, GCC): We will begin rolling out in early January 2026 and expect to complete by late February 2027. [Impact on your organization] Who is affected
Platforms and services
What will happen
[Action required and recommendations] No action is required for this change. We recommend that administrators:
Learn more
[Compliance considerations]
|
||||||||
| Machine Translation |
[何となぜ] ユーザーはまもなくパスキーを最初の多要素認証手段として登録できるようになります。以前は、パスキーを追加する前にSMSやVoiceなどの代替MFA方法(FIDO2)、Windows Hello for Business、macOS Platform SSOを導入しなければなりませんでした。この追加ステップにより、ユーザーはより弱い方法に移行し、フィッシング耐性サインインへの移行が遅れました。現在ではパスワードのみのユーザーも直接パスキーに移行できるため、初日から強力な認証の導入が容易になりました。この取り組みの一環として、Authenticator Appのパスワードレスサインインをユーザーの最初の登録MFA方式として可能にします。 [展開スケジュール] この機能は段階的に展開されます: フェーズ1:同期パスキー、WindowsのMicrosoft Entraパスキー、FIDO2セキュリティキーのサポート。 一般公開(世界、GCC):2026年10月中旬から展開を開始し、2026年11月中旬までに完了する予定です。 フェーズ2:Windows Hello for Business、macOSプラットフォームSSO、認証アプリによるパスワードレスサインインのサポート。 一般公開(世界、GCC):2026年1月初旬に展開を開始し、2027年2月下旬までに完了する予定です。 [組織への影響] 影響を受ける人物
ホームとサービス
何が起こるのか
[行動が必要と提言] この変更に対しては何の措置も必要ありません。 私たちは管理者に以下のことを推奨します:
詳しく はこちら
[コンプライアンスの考慮事項]
|