SHD / MC Checker

MC1469555 | Microsoft Entra: Optimized passkey registration campaign experience



MC1469555 | Microsoft Entra: Optimized passkey registration campaign experience

Classification planForChange
Last Updated 09/09/2026 00:44:03
Start Time 09/09/2026 00:42:31
End Time 10/18/2026 07:00:00
Message Content

[What and why]

Following earlier announcements regarding passkey registration campaigns and targeting logic (MC1279092 and MC1440968), we’re continuing to refine how Microsoft Entra identifies and guides eligible users toward passkey registration. These changes help increase adoption of phishing-resistant authentication while maintaining alignment with administrator-configured passkey policies.

We’re introducing enhancements to the Microsoft Entra registration campaign to help organizations increase passkey registration and adoption.

With this change, users who are eligible to register a passkey will receive an optimized registration experience. We’re also expanding the Microsoft managed registration campaign experience so that users assigned to qualifying passkey profiles can be automatically prompted to register a passkey.

These updates help organizations accelerate adoption of phishing-resistant authentication while continuing to honor configured passkey policies and administrative controls.

A passkey profile qualifies when it meets one of the following criteria:

Passkey profile configuration Qualification criteria
Unrestricted No passkey profile restrictions are configured.
Synced-only Only synced passkeys are allowed and no key restrictions are configured.
Device-bound-only Only device-bound passkeys are allowed and no key restrictions are configured.
AAGUID-restricted The allow list contains at least one AAGUID for iCloud Keychain, Google Password Manager (GPM), Microsoft Authenticator passkey, or Microsoft Entra passkey on Windows.
Device-bound with attestation enforced The profile qualifies regardless of key restrictions. Key restrictions are not evaluated.

[Rollout schedule]

  1. General Availability (Worldwide, GCC): Beginning in early September 2026 and expected to complete by mid-September 2026

[Impact on your organization]

Who is affected

  1. Administrators who manage Microsoft Entra registration campaigns and passkey authentication method policies
  2. Users who are in scope for a registration campaign and are permitted to register passkeys

Platforms and services

  1. Microsoft Entra registration campaign
  2. Microsoft Entra authentication methods policy
  3. Passkey registration experience

What will happen

  1. Eligible users will receive an optimized passkey registration experience.
  2. When a registration campaign is in the Microsoft managed state, Microsoft will evaluate each in-scope user’s passkey profile at sign-in.
  3. Users assigned to at least one qualifying passkey profile may be prompted to register a passkey.
  4. When a registration campaign is in the Enabled state, qualifying profile checks do not apply. All in-scope users who are allowed to register passkeys may be prompted to register a passkey.
  5. Existing registration campaign scope and authentication method policies continue to determine which users are eligible to register passkeys.

Note: If your registration campaign is in the Microsoft managed state and in-scope users meet one or more of the new qualifying passkey profile criteria, Microsoft managed logic may automatically update campaign targeting to include passkeys. As a result, eligible users may begin receiving passkey registration prompts after rollout.

[Action required and recommendations]

Review your registration campaign configuration before rollout.

Recommended actions:

  1. Review users and groups that are currently in scope for your registration campaign.
  2. Review passkey profiles assigned to in-scope users.
  3. Determine whether in-scope users are assigned to qualifying passkey profiles.
  4. If you do not want Microsoft managed dynamic targeting, change the registration campaign state and directly configure targeted authentication methods.
  5. Verify that intended users are enabled for passkeys through your authentication methods policy.

Learn more

  1. Configure the Microsoft Entra registration campaign – Enable and support passkeys in Authenticator for Microsoft Entra ID – Microsoft Entra ID | Microsoft Learn
  2. Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator – Microsoft Entra ID | Microsoft Learn

[Compliance considerations]

  1. The registration campaign does not override configured passkey authentication method policies.
  2. Users can only be prompted to register passkeys permitted by their assigned passkey profiles.
  3. In the Microsoft managed state, Microsoft uses dynamic logic to determine passkey targeting and may automatically update targeted authentication methods.
  4. Administrators retain control over registration campaign scope, registration campaign state, and authentication method policies.
Machine Translation

[何となぜ]

パスキー登録キャンペーンやターゲティングロジック(MC1279092およびMC1440968)に関する以前の発表を受けて、Microsoft Entraが適格ユーザーを特定し、パスキー登録へと導く方法をさらに洗練させています。これらの変更は、管理者が設定したパスキーポリシーとの整合性を維持しつつ、フィッシング耐性認証の採用を促進するのに役立ちます。

Microsoft Entra登録キャンペーンの強化を導入し、組織がパスキー登録と普及率を高めるのを支援します。

この変更により、パスキー登録資格のあるユーザーは最適化された登録体験を得られます。また、Microsoft管理登録キャンペーンの体験も拡張し、適格なパスキープロファイルに割り当てられたユーザーに自動的にパスキー登録を促されるよう促します。

これらのアップデートは、組織がフィッシング耐性認証の導入を加速させつつ、設定済みのパスキーポリシーや管理管理を引き続き尊重するのに役立ちます。

パスキープロファイルは、以下のいずれかの基準を満たす場合に資格を得ます。

パスキープロファイルの設定 資格基準
制限なし パスキープロファイルの制限は設定されていません。
同期専用 同期されたパスキーのみが許可され、キー制限は設定されていません。
デバイスバウンドオンリー デバイスバウンドのパスキーのみが許可され、キー制限は設定されていません。
AAGUID制限付き 許可リストには、少なくとも1つのAAGUIDがiCloudキーチェーン、Googleパスワードマネージャー(GPM)、Microsoft Authenticatorパスキー、またはWindows版Microsoft Entraパスキーが含まれています。
認証が強制されるデバイスバインド プロファイルは主要な制限に関係なく対象となります。主要な制限は評価されません。

[展開スケジュール]

  1. 一般稼働(世界、GCC):2026年9月初旬から開始され、2026年9月中旬までに完了する予定です

[組織への影響]

影響を受ける人物

  1. Microsoft Entraの登録キャンペーンおよびパスキー認証方法ポリシーを管理する管理者
  2. 登録キャンペーンの対象であり、パスキーの登録が許可されているユーザー

ホームとサービス

  1. Microsoft Entra 登録キャンペーン
  2. Microsoft Entra認証方法ポリシー
  3. パスキー登録の体験

何が起こるのか

  1. 対象となるユーザーは最適化されたパスキー登録体験を受けられます。
  2. 登録キャンペーンが Microsoft管理 状態にある場合、Microsoftはサインイン時に各インスコープユーザーのパスキープロファイルを評価します。
  3. 少なくとも1つの適格なパスキープロファイルに割り当てられたユーザーはパスキーの登録を促されることがあります。
  4. 登録キャンペーンが 有効 状態にある場合、適格なプロファイルチェックは適用されません。パスキー登録が許可されている範囲内のすべてのユーザーにパスキー登録を促されることがあります。
  5. 既存の登録キャンペーンの範囲および認証方法の方針は、パスキー登録資格のあるユーザーを引き続き決定しています。

注意:登録キャンペーンがMicrosoft管理状態にあり、範囲内のユーザーが新しい適格なパスキープロファイルの基準のいずれかを満たしている場合、Microsoft管理ロジックはキャンペーンターゲティングを自動的にパスキーを含めるように更新することがあります。その結果、対象となるユーザーは展開後にパスキー登録プロンプトを受け取る可能性があります。

[行動が必要と提言]

展開前に登録キャンペーンの設定を確認しましょう。

推奨される行動:

  1. 登録キャンペーンの対象となるユーザーやグループをレビューしてください。
  2. 範囲内のユーザーに割り当てられたパスキープロファイルを確認してください。
  3. 範囲内のユーザーが適格なパスキープロファイルに割り当てられているかどうかを確認しましょう。
  4. Microsoftが管理する動的ターゲティングを望まない場合は、登録キャンペーンの状態を変更し、ターゲット認証方法を直接設定してください。
  5. 認証方法ポリシーを通じて、意図されたユーザーがパスキーを有効にしているかを確認してください。

詳しくはこちら

  1. Microsoft Entra登録キャンペーンの設定 – AuthenticatorでMicrosoft Entra IDのパスキーを有効化・サポート – Microsoft Entra ID |Microsoft Learn
  2. パスキーまたはMicrosoft Authenticatorを設定するための登録キャンペーンを実施 – Microsoft Entra ID |Microsoft Learn

[コンプライアンスの考慮事項]

  1. 登録キャンペーンは設定済みのパスキー認証方法ポリシーを上書きしません。
  2. ユーザーは割り当てられたパスキープロファイルで許可されたパスキー登録を促されるだけです。
  3. Microsoftの管理型では、パスキーのターゲティングを決定するために動的ロジックを用い、ターゲット認証方法を自動で更新することがあります。
  4. 管理者は登録キャンペーンの範囲、登録キャンペーンの状態、認証方法のポリシーを保持します。