| MC1459133 | (Updated) Microsoft Entra ID: Passkey support for B2B users |
|---|
| Classification | stayInformed | ||||||
|---|---|---|---|---|---|---|---|
| Last Updated | 09/14/2026 18:48:07 | ||||||
| Start Time | 08/21/2026 22:38:08 | ||||||
| End Time | 03/30/2027 07:00:00 | ||||||
| Message Content |
Updated September 14, 2026: We have updated the content. Thank you for your patience. [What and why] Microsoft Entra ID will support passkey registration and sign-in for B2B users, including internal guest users and external users. Eligible B2B users will be able to register and use passkeys issued by the resource tenant to satisfy that tenant’s multifactor authentication (MFA) requirements. Passkeys are already supported for member users in their home tenant. Until now, B2B users could not use a resource tenant passkey when that tenant required MFA and did not trust the home tenant’s MFA. This update closes that gap and gives guest and external users a phishing-resistant way to satisfy MFA requirements in the resource tenant. B2B users can register a resource tenant passkey from the resource tenant’s My Security Info page, during a proof-up prompt, or through a passkey registration campaign. Once registered, the passkey can satisfy the resource tenant’s MFA requirements during sign-in. Microsoft Authenticator app passkeys will be supported for internal guest users but not for external users. Important: This rollout intersects with the previously announced retirement of SMS and voice authentication. As described in Message Center posts MC1426371 and MC1434201, any user enabled for SMS or voice in the Authentication methods policy or legacy MFA policies will be automatically enabled for all passkey types. This will include eligible B2B users when B2B passkey support becomes available. [Rollout schedule] General Availability (GCC, Worldwide): Beginning in early October 2026 and expected to complete by late February 2027
[Impact on your organization] Who is affected
Platforms and services
What will happen
[Action required and recommendations] No action is required. We recommend that administrators review current passkey and MFA configurations before rollout:
Consider notifying your help desk and identity support teams that eligible B2B users may begin receiving passkey registration prompts after rollout. [Compliance considerations]
|
||||||
| Machine Translation |
2026年9月14日更新:内容を更新しました。ご辛抱いただきありがとうございます。 [何となぜ] Microsoft Entra IDは、 内部ゲストユーザーおよび外部ユーザーを含むB2Bユーザーに対してパスキー登録およびサインインをサポートします。対象となるB2Bユーザーは、リソーステナントが発行したパスキーを登録し、そのテナントの多要素認証(MFA)要件を満たすために使用できます。 パスキーはすでにホームテナントのメンバーユーザーに対してサポートされています。これまで、B2Bユーザーはリソーステナントのパスキーを使えなかった。テナントがMFAを必要とし、ホームテナントのMFAを信用していなかった場合です。このアップデートによりそのギャップは埋められ、ゲストおよび外部ユーザーがリソーステナントのMFA要件を満たすためのフィッシングに強い手段が提供されます。 B2Bユーザーは、リソーステナントの「My Security Info」ページ、校正プロンプト中、またはパスキー登録キャンペーンを通じてリソーステナントのパスキーを登録できます。登録後、パスキーはサインイン時にリソーステナントのMFA要件を満たすことができます。 Microsoft Authenticatorアプリのパスキーは内部ゲストユーザーにはサポートされますが、外部ユーザーにはサポートされません。 重要:この展開は、以前発表されたSMSおよび音声認証の廃止と重なります。メッセージセンターの投稿MC1426371およびMC1434201で説明されている通り、認証方法ポリシーまたはレガシーMFAポリシーでSMSまたは音声が有効化されたユーザーは、すべてのパスキータイプで自動的に有効化されます。これは、B2Bパスキーサポートが利用可能になった際に対象となるB2Bユーザーも含まれます。 [展開スケジュール] 一般稼働(GCC、世界): 2026年10月初旬から開始され、2027年2月下旬までに完了予定です
[組織への影響] 影響を受ける人物
ホームとサービス
何が起こるのか
[行動が必要と提言] 何の対応も必要ありません。 導入前に管理者に現在のパスキーおよびMFA設定を確認することをお勧めします。
対象となるB2Bユーザーが展開後にパスキー登録の提示を受け始める可能性があることを、ヘルプデスクやアイデンティティサポートチームに通知することを検討してください。 [コンプライアンスの考慮事項]
|