{"id":17391,"date":"2026-07-21T04:01:14","date_gmt":"2026-07-20T19:01:14","guid":{"rendered":"https:\/\/m365jp.net\/?p=17391"},"modified":"2026-07-21T04:06:05","modified_gmt":"2026-07-20T19:06:05","slug":"mc1221452-updatemicrosoft-entra-id-general-availability-of-passkey-profiles-and-migration-for-existing-passkeys-fido2-tenants-3","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2026-07-21-mc1221452-updatemicrosoft-entra-id-general-availability-of-passkey-profiles-and-migration-for-existing-passkeys-fido2-tenants-3","title":{"rendered":"MC1221452 | (Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC1221452 | (Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>planForChange<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>07\/20\/2026 18:35:44<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>01\/23\/2026 00:54:46<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>11\/30\/2026 07:00:00<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<p>Updated July 20, 2026: We have updated the content. Thank you for your patience.<\/p>\n<p><strong>[Introduction]<\/strong><\/p>\n<p>Starting in <strong>March 2026<\/strong>, Microsoft Entra ID will introduce <strong>  passkey profiles <\/strong>and <strong>synced passkeys<\/strong> to General Availability (GA). This update allows administrators to opt in to a new passkey profiles experience that supports group-based passkey configurations and introduces a new  <strong>passkeyType<\/strong> property.<\/p>\n<p><strong>Important:<\/strong> Only tenants that <strong>already have Passkeys (FIDO2) enabled<\/strong> are affected by this update.  <\/p>\n<p>  <\/p>\n<p>  <\/p>\n<p>The <strong>passkeyType<\/strong> property enables admins to configure:<\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Device-bound passkeys<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Synced passkeys<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Both<\/li>\n<\/ol>\n<p>If your tenant already has Passkeys (FIDO2) enabled and you do not opt in to passkey profiles during the initial rollout window, your tenant will be automatically migrated to the passkey profiles schema at the date range specified below. When this occurs:  <\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Existing Passkey (FIDO2) authentication method configurations will be moved into a  <strong>Default passkey profile.<\/strong> <\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>The <strong>  passkeyType<\/strong> value will be set based on the tenant\u2019s current attestation settings. Synced passkeys will be enabled for tenants with attestation enforcement disabled.  <\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>No new authentication methods are enabled as part of this migration.  <\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>This migration also impacts Authentication methods registration campaign set to \u201cMicrosoft managed\u201d state, which uses passkey configuration settings to determine which registration prompts   are shown to users.<\/li>\n<\/ol>\n<p><strong>Authentication Methods Registration Campaign changes (Microsoft-Managed Only)<\/strong><\/p>\n<p>Tenants are impacted when all the following conditions are met:<\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>The Passkeys (FIDO2) authentication method policy is Enabled<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Authentication methods registration campaign is set to \u201cMicrosoft managed\u201d state<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Allow self-service setup is Enabled<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Target specific AAGUIDs is not selected (no AAGUID restrictions configured)<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>The Authentication Methods Registration Campaign state is set to Microsoft-managed<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>The tenant has at least one user enabled for  <strong>both<\/strong> synced passkeys and device\u2011bound passkeys<\/li>\n<li data-list=\"bullet\" class=\"ql-indent-1\"><span class=\"ql-ui\"><\/span>Only users who are enabled for both synced passkeys and device\u2011bound passkeys, with no passkey profile restrictions configured (i.e. attestation enforcement, AAGUID   restrictions), will receive a passkey registration nudge during sign\u2011in.<\/li>\n<\/ol>\n<p>For these tenants, Microsoft-managed registration campaign settings will be updated after passkey profile automatic migration is complete. We will roll out changes incrementally to in-scope tenants according to the timeline outlined below.  <\/p>\n<p><strong>[When this will happen]<\/strong><\/p>\n<p><strong>Passkey profile and Synced passkeys General Availability<\/strong><\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><strong>Public cloud Worldwide, GCC:<\/strong> Rollout begins in early March 2026 and is expected to complete by late March 2026  <\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><strong>GCC High, DoD clouds:<\/strong> Rollout begins in early May 2026 and is expected to complete by late May 2026  <\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><strong>USNat, USSec:<\/strong> Rollout begins in early October 2026 (previously early July) and is expected to complete by late October 2026 (previously late July)  <\/li>\n<\/ol>\n<p><strong>Automatic migration for existing passkeys (FIDO2) enabled tenants<\/strong><\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><strong>Public cloud Worldwide, GCC:  <\/strong>Rollout begins in early May 2026 and is expected to complete by late June 2026<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><strong>GCC High, DoD clouds:  <\/strong>Rollout begins in early October 2026 (previously early August) and is expected to complete by late October 2026 (previously late August)<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><strong>USNat, USSec<\/strong>: Rollout begins in early October 2026 (previously early August) and is expected to complete by late October 2026 (previously late August)<\/li>\n<\/ol>\n<p><strong>Authentication Methods registration campaign changes in Microsoft-Managed state (for in-scope tenants):<\/strong><\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><strong>Public cloud Worldwide, GCC:  <\/strong>Rollout begins in early May 2026 and is expected to complete by late June 2026  <\/li>\n<\/ol>\n<p><strong>[How this affects your organization]<\/strong><\/p>\n<p><strong>Automatic migration for existing passkeys (FIDO2) enabled tenants <\/strong>  <\/p>\n<p><em>What will happen:<\/em><\/p>\n<p>If you have not opted in to passkey profiles by your automatic enablement period, your tenant will be migrated to passkey profiles.<\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Your existing Passkey (FIDO2) configurations will be migrated into a  <strong>Default passkey profile<\/strong><\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>New <strong>  passkeyType <\/strong>property will be auto-populated<\/li>\n<li data-list=\"bullet\" class=\"ql-indent-1\"><span class=\"ql-ui\"><\/span>If  <strong>enforce attestation <\/strong>is <strong>enabled<\/strong>, then device-bound allowed<\/li>\n<li data-list=\"bullet\" class=\"ql-indent-1\"><span class=\"ql-ui\"><\/span>If  <strong>enforce attestation <\/strong>is <strong>disabled<\/strong>, then device-bound and synced allowed<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Any existing  <strong>key restrictions <\/strong>will remain intact<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Any existing  <strong>user targets <\/strong>will be assigned to the <strong>Default passkey profile<\/strong><\/li>\n<\/ol>\n<p><strong>Authentication Methods registration campaign changes in Microsoft-Managed state (for in-scope tenants)  <\/strong><\/p>\n<p><em>What will happen:<\/em><\/p>\n<p>Microsoft-managed registration campaign settings will be updated: <\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>&#8220;Targeted authentication method\u201d will change from Microsoft Authenticator to \u201cpasskeys (FIDO2)\u201d.  <\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>\u201cDays allowed to snooze\u201d setting will change from 3days to \u201c1 day\u201d. This setting will no longer be configurable.  <\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>\u201cLimited number of snoozes\u201d setting will change from Enabled to &#8220;Disabled\u201d. This setting will no longer be configurable.  <\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>The default user targeting will be updated from voice call or text message users to all multifactor authentication (MFA) capable users.  <\/li>\n<\/ol>\n<p>What is the end user impact: <\/p>\n<p>Once the above changes have taken effect, users targeted in the registration campaign will begin to receive passkey registration nudges during sign-in flows after they have completed multifactor authentication.  <\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>  <\/li>\n<\/ol>\n<p><strong>[What you can do to prepare]<\/strong><\/p>\n<p>If you want a configuration different from the migration defaults, review the timeline above and opt in to passkey profiles  <strong>before your tenant\u2019s automatic enablement window begins<\/strong>. Then configure the Default passkey profile\u2019s<strong> passkeyType<\/strong> to your preferred values.<\/p>\n<p>We also recommend:<\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Review your  <strong>registration campaign <\/strong>configuration,<strong> especially if its set to Microsoft-managed<\/strong>. If you do not want registration campaign to target passkeys, you can:  <\/li>\n<li data-list=\"bullet\" class=\"ql-indent-1\"><span class=\"ql-ui\"><\/span>Switch the registration campaign state to<strong><em> Enabled<\/em><\/strong> and continue targeting Microsoft Authenticator, or  <\/li>\n<li data-list=\"bullet\" class=\"ql-indent-1\"><span class=\"ql-ui\"><\/span>Set the registration campaign state to  <strong><em>Disabled<\/em><\/strong>.<\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span>Update runbooks and help content so your help desk and end users understand any changes in passkey availability or behavior.  <\/li>\n<\/ol>\n<p>Learn more:<\/p>\n<ol>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/authentication\/how-to-enable-passkey-fido2#enable-passkey-fido2-authentication-method\" rel=\"noopener noreferrer\" target=\"_blank\">Enable   passkeys for your organization &#8211; Microsoft Entra ID | Microsoft Learn<\/a> <\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/authentication\/how-to-authentication-passkey-profiles\" rel=\"noopener noreferrer\" target=\"_blank\">How to Enable Passkey (FIDO2) Profiles   in Microsoft Entra ID (preview) &#8211; Microsoft Entra ID | Microsoft Learn<\/a><\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/authentication\/how-to-authentication-synced-passkeys\" rel=\"noopener noreferrer\" target=\"_blank\">How to Enable Synced Passkeys (FIDO2)   in Microsoft Entra ID (preview) &#8211; Microsoft Entra ID | Microsoft Learn<\/a><\/li>\n<li data-list=\"bullet\"><span class=\"ql-ui\"><\/span><a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/authentication\/synced-passkey-faq\" rel=\"noopener noreferrer\" target=\"_blank\">Synced passkeys FAQ &#8211; Microsoft Entra ID | Microsoft Learn<\/a><\/li>\n<\/ol>\n<p><strong>[Compliance considerations]<\/strong><\/p>\n<p>No compliance considerations identified. Review as appropriate for your organization.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC1221452 | (Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Pa [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-17391","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/17391","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=17391"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/17391\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=17391"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=17391"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=17391"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}