SHD / MC Checker

MC1450133 | Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method



MC1450133 | Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method

Classification stayInformed
Last Updated 08/07/2026 21:55:51
Start Time 08/07/2026 21:55:44
End Time 03/29/2027 07:00:00
Message Content

[What and why]

Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method like SMS or Voice before they could add a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey, making it easier to adopt strong authentication from day one. As part of this work, we will also be enabling Authenticator App passwordless sign-in to be a user’s first registered MFA method. 

[Rollout schedule]

This feature will roll out in phases: 

Phase 1: Support for synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys.  

General Availability (Worldwide, GCC): We will begin rolling out in mid-October 2026 and expect to complete by mid-November 2026. 

Phase 2: Support for Windows Hello for Business, macOS Platform SSO, and Authenticator App passwordless sign-in. 

General Availability (Worldwide, GCC): We will begin rolling out in early January 2026 and expect to complete by late February 2027. 

[Impact on your organization]

Who is affected

  • Users who have not yet registered a multifactor authentication method
  • Identity and security administrators responsible for authentication onboarding and registration policies

Platforms and services

  • Microsoft Entra ID
  • Passkeys (FIDO2)
  • Windows Hello for Business
  • macOS Platform SSO
  • Microsoft Authenticator passwordless sign-in

What will happen

  • Password-only users will be able to register passkeys or passwordless sign-in as their first MFA method.
  • Users will no longer need to register a method such as SMS or voice before registering a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO, or Authenticator passwordless sign-in.
  • Organizations may see reduced registration friction and increased adoption of phishing-resistant authentication methods.

[Action required and recommendations]

No action is required for this change.

We recommend that administrators:

  • Review Conditional Access policies related to security information registration.
  • Consider requiring MFA to register security information if additional verification is required by your organization.
  • Review onboarding and registration guidance so users know to set up a passkey as their preferred first method.

Learn more 

[Compliance considerations]

Question Answer
Does the change include an admin control? Yes. Administrators can control which authentication methods users are allowed to register through existing Microsoft Entra authentication method policies and Conditional Access policies.
Does the change affect access or authentication controls? Yes. The update changes how users register multifactor authentication methods by allowing eligible users to register supported passkeys or passwordless authentication methods as their first MFA method.
Can administrators govern the feature through existing Microsoft Entra controls? Yes. Administrators retain control over the feature through Microsoft Entra authentication method policies and Conditional Access configurations.
Machine Translation

[何となぜ]

ユーザーはまもなくパスキーを最初の多要素認証手段として登録できるようになります。以前は、パスキーを追加する前にSMSやVoiceなどの代替MFA方法(FIDO2)、Windows Hello for Business、macOS Platform SSOを導入しなければなりませんでした。この追加ステップにより、ユーザーはより弱い方法に移行し、フィッシング耐性サインインへの移行が遅れました。現在ではパスワードのみのユーザーも直接パスキーに移行できるため、初日から強力な認証の導入が容易になりました。この取り組みの一環として、Authenticator Appのパスワードレスサインインをユーザーの最初の登録MFA方式として可能にします。 

[展開スケジュール]

この機能は段階的に展開されます: 

フェーズ1:同期パスキー、WindowsのMicrosoft Entraパスキー、FIDO2セキュリティキーのサポート。  

一般公開(世界、GCC):2026年10月中旬から展開を開始し、2026年11月中旬までに完了する予定です。 

フェーズ2:Windows Hello for Business、macOSプラットフォームSSO、認証アプリによるパスワードレスサインインのサポート。 

一般公開(世界、GCC):2026年1月初旬に展開を開始し、2027年2月下旬までに完了する予定です。 

[組織への影響]

影響を受ける人物

  • まだ多要素認証方法を登録していないユーザー
  • 認証、オンボーディングおよび登録ポリシーを担当するアイデンティティおよびセキュリティ管理者

ホームとサービス

  • Microsoft Entra ID
  • パスキー(FIDO2)
  • Windows Hello for Business(ビジネス用 Windows Hello)
  • macOS Platform SSO
  • Microsoft Authenticator パスワードレスサインイン

何が起こるのか

  • パスワードのみのユーザーは、パスキーやパスワードレスサインインを最初のMFA方法として登録できます。
  • ユーザーはパスキー(FIDO2)、Windows Hello for Business、macOSプラットフォームSSO、Authenticatorのパスワードレスサインイン登録前にSMSや音声などの方法を登録する必要がなくなりました。
  • 組織は登録摩擦の減少とフィッシング耐性認証方法の採用増加を実感するかもしれません。

[行動が必要と提言]

この変更に対しては何の措置も必要ありません。

私たちは管理者に以下のことを推奨します:

  • セキュリティ情報登録に関する条件付きアクセスポリシーを確認してください。
  • 組織で追加の認証が必要な場合は、セキュリティ情報の登録にMFAを義務付けることを検討してください。
  • オンボーディングや登録のガイダンスを確認し、ユーザーがパスキーを最初に設定することを推奨します。

詳しく はこちら

[コンプライアンスの考慮事項]

質問 回答
変更には管理者管理も含まれていますか? はい。管理者は既存のMicrosoft Entra認証方法ポリシーや条件付きアクセスポリシーを通じて、ユーザーが登録できる認証方法を管理できます。
この変更はアクセスや認証の制御に影響しますか? はい。このアップデートでは、対象となるユーザーがサポート済みパスキーやパスワードレス認証方式を最初のMFA方法として登録できるようになり、多要素認証方法の登録方法を変更しました。
管理者は既存のMicrosoft Entraコントロールを使ってこの機能を管理できますか? はい。管理者はMicrosoft Entraの認証方法ポリシーや条件付きアクセス設定を通じて機能のコントロールを保持します。