SHD / MC Checker

MC1459133 | Microsoft Entra ID: Passkey support for B2B users



MC1459133 | Microsoft Entra ID: Passkey support for B2B users

Classification stayInformed
Last Updated 08/21/2026 22:38:13
Start Time 08/21/2026 22:38:08
End Time 03/30/2027 07:00:00
Message Content

[What and why]

Microsoft Entra ID will support passkey registration and sign-in for B2B users, including internal guest users and external users. Eligible B2B users will be able to register and use passkeys issued by the resource tenant to satisfy that tenant’s multifactor authentication (MFA) requirements.

Passkeys are already supported for member users in their home tenant. Until now, B2B users could not use a resource tenant passkey when that tenant required MFA and did not trust the home tenant’s MFA. This update closes that gap and gives guest and external users a phishing-resistant way to satisfy MFA requirements in the resource tenant.

B2B users can register a resource tenant passkey from the resource tenant’s My Security Info page, during a proof-up prompt, or through a passkey registration campaign. Once registered, the passkey can satisfy the resource tenant’s MFA requirements during sign-in.

Microsoft Authenticator app passkeys will be supported for internal guest users but not for external users.

[Rollout schedule]

General Availability (GCC, Worldwide): Beginning in early October 2026 and expected to complete by late February 2027

  • Internal guest users: Beginning in early October 2026 and is expected to complete by late October 2026
  • External users (excluding Microsoft Authenticator app passkeys): Rollout timing will be communicated in a future Message center post update.

[Impact on your organization]

Who is affected

  • Microsoft Entra administrators managing Authentication methods policies
  • Organizations that use Microsoft Entra B2B collaboration
  • Internal guest users and external users who are in scope for passkey authentication

Platforms and services

  • Microsoft Entra ID
  • My Security Info
  • Authentication methods policy
  • Conditional Access

What will happen

  • The feature will be enabled by default.
  • B2B users who are already in scope for passkeys in your Authentication methods policy will automatically be able to register and sign in with resource tenant passkeys.
  • No administrative action is required to enable this feature.
  • Eligible B2B users may receive prompts to register a passkey during sign-in through proof-up experiences or passkey registration campaigns, if those experiences are configured in your tenant.
  • Users can also register a passkey from the resource tenant’s My Security Info page.
  • If your organization has excluded B2B users from passkeys in the Authentication methods policy, those users will not be prompted and will not be able to register or sign in with a resource tenant passkey.
  • This change gives guest and external users a phishing-resistant sign-in option and helps organizations extend strong authentication requirements to their B2B population.

[Action required and recommendations]

No action is required.

We recommend that administrators review current passkey and MFA configurations before rollout:

  • Review your Authentication methods policy. Confirm which users are in scope for passkeys, including guest and external users. B2B users who are in scope will be enabled automatically. Exclude them from the policy if that is not the intended behavior.
  • Review your passkey registration campaign. Confirm that the campaign’s user scope includes the intended users.
  • Review your Conditional Access policies. Confirm that MFA and authentication strength requirements will apply as intended for B2B users when resource tenant passkeys become available.
  • Confirm user scoping across authentication-related policies. Make sure the groups and user types targeted by each policy align with your organization’s requirements for guest and external users.

Consider notifying your help desk and identity support teams that eligible B2B users may begin receiving passkey registration prompts after rollout.

[Compliance considerations]

Question Answer
Does the change store new customer data? Passkey credential registration data may be stored as part of Microsoft Entra authentication management.
Does the change alter how existing customer data is processed, stored, or accessed? The change introduces an additional authentication method for B2B users accessing resource tenant resources.

Machine Translation

[何となぜ]

Microsoft Entra IDは、内部ゲストユーザーおよび外部ユーザーを含むB2Bユーザー向けのパスキー登録およびサインインをサポートします。対象となるB2Bユーザーは、リソーステナントが発行したパスキーを登録し、そのテナントの多要素認証(MFA)要件を満たすために使用できます。

パスキーは、メンバーのホームテナントですでにサポートされています。これまで、B2Bユーザーはリソースのテナントパスキーを使えなかった。そのテナントがMFAを必要とし、ホームテナントのMFAを信用していなかった場合です。このアップデートによりそのギャップは埋められ、ゲストおよび外部ユーザーがリソーステナントのMFA要件を満たすフィッシングに強い手段が提供されます。

B2Bユーザーは、リソーステナントの「My Security Info」ページ、校正プロンプト中、またはパスキー登録キャンペーンを通じて、リソーステナントのパスキーを登録できます。登録後、パスキーはサインイン時にリソーステナントのMFA要件を満たすことができます。

Microsoft Authenticatorアプリのパスキーは内部ゲストユーザーにはサポートされますが、外部ユーザーにはサポートされません。

[展開スケジュール]

一般公開(GCC、世界公開): 2026年10月初旬に開始し、2027年2月下旬までに完了する予定です

  • 内部ゲストユーザー:2026年10月初旬から開始され、2026年10月下旬までに完了予定です
  • 外部ユーザー(Microsoft Authenticatorアプリのパスキーを除く): 展開時期は今後のメッセージセンターの更新でお知らせします。

[組織への影響]

影響を受ける人物

  • Microsoft Entra管理者が認証方法ポリシーを管理する
  • Microsoft Entra B2Bコラボレーションを利用する組織
  • パスキー認証の対象となる内部ゲストユーザーおよび外部ユーザー

ホームとサービス

  • Microsoft Entra ID
  • 私のセキュリティ情報
  • 認証方法ポリシー
  • 条件付きアクセス

何が起こるのか

  • この機能はデフォルトで有効化されます。
  • 認証方法ポリシーでパスキーの対象となるB2Bユーザーは、自動的にリソーステナントパスキーで登録・サインインできます。
  • この機能を有効にするために管理的な手続きは必要ありません。
  • 対象となるB2Bユーザーは、テナント内で設定されているプルーフアップ体験やパスキー登録キャンペーンを通じてサインイン時にパスキー登録のプロンプトを受け取ることがあります。
  • ユーザーはリソーステナントの「My Security Info」ページからパスキーを登録することもできます。
  • もし組織の認証方法ポリシーでB2Bユーザーをパスキーから除外している場合、そのユーザーはリソーステナントパスキーで登録やサインインを行えなくなります。
  • この変更により、ゲストおよび外部ユーザーにフィッシング耐性のサインインオプションが提供され、組織がB2B集団に対して強力な認証要件を拡張するのを支援します。

[行動が必要と提言]

何の対応も必要ありません。

導入前に管理者に現在のパスキーおよびMFA設定を確認することをお勧めします。

  • 認証方法ポリシーを確認してください。パスキーの対象となるユーザー(ゲストユーザーや外部ユーザーを含む)を確認してください。範囲内のB2Bユーザーは自動的に有効化されます。もしそれが意図された行動でなければ、保険から除外してください。
  • パスキー登録キャンペーンを見直しましょう。キャンペーンのユーザー範囲に意図されたユーザーも含まれているか確認してください。
  • 条件付きアクセスポリシーを見直しましょう。リソーステナントパスキーが利用可能になった際に、B2Bユーザーに対してMFAおよび認証強度要件が本来の通り適用されるかを確認してください。
  • 認証関連ポリシー間のユーザースコープを確認しましょう。各ポリシーで対象となるグループやユーザータイプが、ゲストおよび外部ユーザーに対する組織の要件に合致していることを確認してください。

対象となるB2Bユーザーが展開後にパスキー登録の提示を受け始める可能性があることを、ヘルプデスクやアイデンティティサポートチームに通知することを検討してください。

[コンプライアンスの考慮事項]

質問 回答
変更は新しい顧客データを保存しますか? パスキー認証情報の登録データは、Microsoft Entra認証管理の一部として保存されることがあります。
この変更は既存の顧客データの処理、保存、アクセス方法を変えますか? この変更により、リソーステナントリソースにアクセスするB2Bユーザー向けの追加の認証方法が導入されます。