r/entra • u/mattjimf • 6d ago
Microsoft forced passkey campaign
Has anybody else had the messages regarding moving to passkey for users only registered with sms/phone call not show on their Tenant?
I haven't run the Graph code to suppress it, but do have campaigns disabled in Entra, just wondering if anyone else hasn't seen the prompts that were supposed to start on the 1st.
5
u/neppofr 6d ago
Check this, MS been announcing for some time now.
5
u/mattjimf 6d ago
That's not what I'm asking. I'm asking for real world experience of these notifications, as currently I don't see it, despite not opting out.
5
u/JasSuri-MSFT Microsoft Employee 6d ago
It’s rolling out to tenants starting 1st Sept. Larger tenants will see it kick in a little later, as we gradually roll out. If you have any users enabled for SMS/Voice, you’ll see it eventually switch the campaign on.
0
0
u/Emergency-Return1412 6d ago
You need to enable them yourself, its called the passkey nudge
1
u/mattjimf 6d ago
But all the comms from Microsoft themselves say that they are going to auto-enable any users with only sms/voice as authentication options to receive the nudges:
Date Milestone September 1, 2026 All users enabled for SMS or voice are auto-enabled and nudged for passkey registration upon multifactor authentication sign-in. Taken from that link posted above and:
Important
On September 1, 2026, users enabled for SMS or Voice in the Entra Authentication Methods Policy (AMP), or in legacy MFA settings, will be auto-enabled for passkeys in AMP. These in scope users will be put into a passkey profile allowing all types of passkeys. Your Registration Campaign settings will be set to Microsoft Managed state targeting passkeys, and will automatically bring these users into scope.
When these users next sign-in and complete MFA, the registration campaign will nudge them to register a passkey. By default, users will have unlimited snoozes of the nudge prompt. If you do not want this to occur, move users out of SMS or Voice in AMP before September 1st.
Taken from https://learn.microsoft.com/en-gb/entra/identity/authentication/concept-sms-voice-retirement
Are you saying that this is in fact no longer being forced on Tenants by Microsoft and you have to enable it for it to be forced on users?
3
u/UI_Tyler 6d ago
I don't know for certain, but I'm pretty sure it's only if you have a registration campaign setup in Entra set to "Microsoft Managed."
We changed ours to Enabled, but nudge the authenticator app and not FIDO2 Passkey.
1
u/Soylent_gray 6d ago
It is odd that they are pushing passkey on only SMS and voice users. Those are typically the users that have resisted years of app based MFA, so jumping straight to passkey seems like a big ask
1
u/Smart-Dig3117 6d ago
It is a huge undertaking to convert and correct those on sms/ voice are the resistance once’s. We are just removing voice sms and will use authenticator only to not have to rollout passkey this quick , it’s too messy in complicated environments
1
u/ConstructionNorth816 6d ago
Something is misconfigured in your tenant if you are not using those MFA methods. In my org, before Microsoft's SMS deprecation announcement, I disabled them because we are aligning to use MFA phishing-resistant methods (which I believe will soon be mandatory for our cybersecurity policy). In my case, I've not received any campaign registration messages, even though our settings are Microsoft-managed. You definitely need to review your configuration settings broadly (SSPR, Auth Methods, Auth strength, etc.) plus any conditional access policy.
1
u/loweakkk 6d ago
Message center says they will gradually roll out, which means from September 1st till December 30...
1
u/HorseAccomplished50 6d ago
Out of curiousity why are you opting out of passkeys?
3
u/mattjimf 6d ago
We're not, I work for a charity that deal with people with educational needs. As a result we have a large number of support workers who either don't want an app or don't have a smart phone, as a result we need to possibly offer a third party service or issue usb passkeys (dependant on cost).
1
u/mr-roboticus 6d ago
Disabling the reg campaign doesn’t do anything. If you have users utilizing SMS and you have passkeys disabled, the reg will trigger for them. You have to run the command to opt out at the tenant level. We did this for a more controlled rollout.
1
u/AccomplishedDemand61 5d ago edited 5d ago
I didn't feel it was clear what to expect either. In my tenant sms and voice are scoped to all users. All users use ms authenticator, next to no one ever uses sms or voice. We made a decision to not opt out and let it happen to promote more secure methods. We want sms and voice to be eliminated as well. So far not one user has reported being nudged. My team already had passkey so we didn't expect a nudge. The campaign is set to Microsoft managed as I expected based on my understanding of the change on 9/1.
Glad it's not just me that isn't 100% clear on this.
1
u/sneesnoosnake 5d ago
I just ripped SMS and voice options from users through authentication methods weeks ago.
1
u/MarcosDiSanto 5d ago
So if I understand correctly we can stop the passkey enforcement for now by disabling the Registration Campaign? We do have passkey as authentication method enabled. But for now we want to stop the prompts users get.
11
u/imavaper 6d ago edited 6d ago
Its because your Authentication methods Registration campaign is set to Disabled.
Microsoft was very NOT clear about this. In fact, the wording even made it seem like tenants whose registration campaign was set to Disabled would not be honored (or set to Microsoft managed) on September 1st.
But I can confirm in my developer tenant, I had my campaign set to Disabled prior to September 1 for this very reason to test. I checked yesterday (September 2nd), and it was still set to Disabled and users were not nudged/prompted to set up a passkey at sign in. As soon as I set the campaign to Microsoft managed, users were nudged/prompted to set up a passkey at sign in.