Authentication registration campaigns
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit 2c393c9 · +9 −7 lines · also on GitHub
⋯ 1 unchanged line
22
title: Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator
33
description: Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
44
ms.topic: how-to
5
−ms.date: 09/02/2026
5
+ms.date: 09/15/2026
66
ms.reviewer: marisanchez
77
ai-usage: ai-assisted
88
ms.custom: sfi-ga-nochange, sfi-image-nochange, msecd-doc-authoring-1012
⋯ 27 unchanged lines
3636
3737
A registration campaign prompts users to set up a stronger authentication method—a passkey (FIDO2) or Microsoft Authenticator—after they complete multifactor authentication (MFA).
3838
39
−The following conditions apply:
39
+The MFA requirement depends on the campaign state and targeted authentication method:
4040
41
−| Targeted authentication method | When the user is prompted |
42
−|---|---|
43
−| Microsoft Authenticator | After the user successfully completes MFA by using SMS or voice call. |
44
−| Passkey (FIDO2) | After the user successfully completes MFA by using any method. |
41
+| Campaign state | Targeted authentication method | MFA requirement |
42
+|---|---|---|
43
+| Microsoft managed | Microsoft Authenticator | The user completes MFA by using SMS or voice call. |
44
+| Microsoft managed | Passkey (FIDO2) | The user completes MFA by using any method. |
45
+| Enabled | Microsoft Authenticator | The user completes MFA by using any method. |
46
+| Enabled | Passkey (FIDO2) | The user completes MFA by using any method. |
4547
4648
For either campaign, a user is prompted only if they're eligible. A user's eligibility depends on the campaign state and the targeted authentication method.
4749
⋯ 66 unchanged lines
114116
|---|---|---|
115117
| Days allowed to snooze | 0–14 | 0–14 |
116118
| Limited number of snoozes | Enabled or disabled | Enabled or disabled |
117
−| Eligible users | Users who meet **all** of the following:<br>• Sign in by using voice call or text message (SMS)<br>• Are enabled for Authenticator push notifications in the authentication methods policy<br>• Don't already have Authenticator push set up | Users who meet **all** of the following:<br>• Sign in by using any MFA method<br>• Are in **any** passkey profile configuration |
119
+| Eligible users | Users who meet **all** of the following:<br>• Sign in by using any MFA method<br>• Are enabled for Authenticator push notifications in the authentication methods policy<br>• Don't already have Authenticator push set up | Users who meet **all** of the following:<br>• Sign in by using any MFA method<br>• Are in **any** passkey profile configuration |
118120
119121
The **Enabled** state doesn't apply the Microsoft managed passkey-profile eligibility check. For example, use the Enabled state to deploy synced passkeys with AAGUID restrictions that aren't in scope for the Microsoft managed state.
120122
⋯ 428 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy today 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.