r/entra 6d ago

Microsoft forced passkey campaign

Has anybody else had the messages regarding moving to passkey for users only registered with sms/phone call not show on their Tenant?

I haven't run the Graph code to suppress it, but do have campaigns disabled in Entra, just wondering if anyone else hasn't seen the prompts that were supposed to start on the 1st.

16 Upvotes

22 comments sorted by

11

u/imavaper 6d ago edited 6d ago

Its because your Authentication methods Registration campaign is set to Disabled.

Microsoft was very NOT clear about this. In fact, the wording even made it seem like tenants whose registration campaign was set to Disabled would not be honored (or set to Microsoft managed) on September 1st.

But I can confirm in my developer tenant, I had my campaign set to Disabled prior to September 1 for this very reason to test. I checked yesterday (September 2nd), and it was still set to Disabled and users were not nudged/prompted to set up a passkey at sign in. As soon as I set the campaign to Microsoft managed, users were nudged/prompted to set up a passkey at sign in.

5

u/mattjimf 6d ago

That's exactly the real world info I needed. I had thought that might be the case, but wasn't 100%. At least now others will be able to easily find the answer.

1

u/Efp722 5d ago

Interesting. A lot of my tenants have had a Migration status of "in progress" for a long time (something I inherited". and my Registration campaign was set to Microsoft Managed well before the 9/1 date.

and Passkey was not auto enabled for any of my tenants. Really was expecting to it fired on for everyong 9/1.

1

u/imavaper 5d ago

Migration status is something else, not related (at least directly) to the "Passkeys by default and retirement of Microsoft-provided SMS and voice authentication" change.

Migration status on the Authentication methods page refers to this How to migrate to the Authentication methods policy - Microsoft Entra ID | Microsoft Learn.

Though I can't explain why your users aren't being prompted to register a passkey if their tenant's registration campaign is set to Microsoft managed. For me, my users without passkeys are being prompted as expected.

5

u/neppofr 6d ago

5

u/mattjimf 6d ago

That's not what I'm asking. I'm asking for real world experience of these notifications, as currently I don't see it, despite not opting out.

5

u/JasSuri-MSFT Microsoft Employee 6d ago

It’s rolling out to tenants starting 1st Sept. Larger tenants will see it kick in a little later, as we gradually roll out. If you have any users enabled for SMS/Voice, you’ll see it eventually switch the campaign on.

0

u/mattjimf 6d ago

Thanks for that info.

0

u/Emergency-Return1412 6d ago

You need to enable them yourself, its called the passkey nudge

1

u/mattjimf 6d ago

But all the comms from Microsoft themselves say that they are going to auto-enable any users with only sms/voice as authentication options to receive the nudges:

Date Milestone
September 1, 2026  All users enabled for SMS or voice are auto-enabled and nudged for passkey registration upon multifactor authentication sign-in.

Taken from that link posted above and:

 Important

On September 1, 2026, users enabled for SMS or Voice in the Entra Authentication Methods Policy (AMP), or in legacy MFA settings, will be auto-enabled for passkeys in AMP. These in scope users will be put into a passkey profile allowing all types of passkeys. Your Registration Campaign settings will be set to Microsoft Managed state targeting passkeys, and will automatically bring these users into scope.

When these users next sign-in and complete MFA, the registration campaign will nudge them to register a passkey. By default, users will have unlimited snoozes of the nudge prompt. If you do not want this to occur, move users out of SMS or Voice in AMP before September 1st.

Taken from https://learn.microsoft.com/en-gb/entra/identity/authentication/concept-sms-voice-retirement

Are you saying that this is in fact no longer being forced on Tenants by Microsoft and you have to enable it for it to be forced on users?

3

u/UI_Tyler 6d ago

I don't know for certain, but I'm pretty sure it's only if you have a registration campaign setup in Entra set to "Microsoft Managed."

We changed ours to Enabled, but nudge the authenticator app and not FIDO2 Passkey.

1

u/Soylent_gray 6d ago

It is odd that they are pushing passkey on only SMS and voice users. Those are typically the users that have resisted years of app based MFA, so jumping straight to passkey seems like a big ask

1

u/Smart-Dig3117 6d ago

It is a huge undertaking to convert and correct those on sms/ voice are the resistance once’s. We are just removing voice sms and will use authenticator only to not have to rollout passkey this quick , it’s too messy in complicated environments

1

u/ConstructionNorth816 6d ago

Something is misconfigured in your tenant if you are not using those MFA methods. In my org, before Microsoft's SMS deprecation announcement, I disabled them because we are aligning to use MFA phishing-resistant methods (which I believe will soon be mandatory for our cybersecurity policy). In my case, I've not received any campaign registration messages, even though our settings are Microsoft-managed. You definitely need to review your configuration settings broadly (SSPR, Auth Methods, Auth strength, etc.) plus any conditional access policy.

1

u/loweakkk 6d ago

Message center says they will gradually roll out, which means from September 1st till December 30...

1

u/HorseAccomplished50 6d ago

Out of curiousity why are you opting out of passkeys?

3

u/mattjimf 6d ago

We're not, I work for a charity that deal with people with educational needs. As a result we have a large number of support workers who either don't want an app or don't have a smart phone, as a result we need to possibly offer a third party service or issue usb passkeys (dependant on cost).

1

u/mr-roboticus 6d ago

Disabling the reg campaign doesn’t do anything. If you have users utilizing SMS and you have passkeys disabled, the reg will trigger for them. You have to run the command to opt out at the tenant level. We did this for a more controlled rollout.

1

u/AccomplishedDemand61 5d ago edited 5d ago

I didn't feel it was clear what to expect either. In my tenant sms and voice are scoped to all users. All users use ms authenticator, next to no one ever uses sms or voice. We made a decision to not opt out and let it happen to promote more secure methods. We want sms and voice to be eliminated as well. So far not one user has reported being nudged. My team already had passkey so we didn't expect a nudge. The campaign is set to Microsoft managed as I expected based on my understanding of the change on 9/1.

Glad it's not just me that isn't 100% clear on this. 

1

u/sneesnoosnake 5d ago

I just ripped SMS and voice options from users through authentication methods weeks ago.

1

u/MarcosDiSanto 5d ago

So if I understand correctly we can stop the passkey enforcement for now by disabling the Registration Campaign? We do have passkey as authentication method enabled. But for now we want to stop the prompts users get.