ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 341/391 docs · synced 23:23 UTC Customize Public modeDiscuss ChangeIntel on Discord

Authentication registration campaigns

This page's changes and edits · All guidance changes

Microsoft's edit ·

Clarify registration campaign MFA requirements

Microsoft's commit message in MicrosoftDocs/entra-docs · commit 2c393c9 · +9 −7 lines · also on GitHub

⋯ 1 unchanged line
22 title: Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator
33 description: Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
44 ms.topic: how-to
5 −ms.date: 09/02/2026
5 +ms.date: 09/15/2026
66 ms.reviewer: marisanchez
77 ai-usage: ai-assisted
88 ms.custom: sfi-ga-nochange, sfi-image-nochange, msecd-doc-authoring-1012
⋯ 27 unchanged lines
3636
3737 A registration campaign prompts users to set up a stronger authentication method—a passkey (FIDO2) or Microsoft Authenticator—after they complete multifactor authentication (MFA).
3838
39 −The following conditions apply:
39 +The MFA requirement depends on the campaign state and targeted authentication method:
4040
41 −| Targeted authentication method | When the user is prompted |
42 −|---|---|
43 −| Microsoft Authenticator | After the user successfully completes MFA by using SMS or voice call. |
44 −| Passkey (FIDO2) | After the user successfully completes MFA by using any method. |
41 +| Campaign state | Targeted authentication method | MFA requirement |
42 +|---|---|---|
43 +| Microsoft managed | Microsoft Authenticator | The user completes MFA by using SMS or voice call. |
44 +| Microsoft managed | Passkey (FIDO2) | The user completes MFA by using any method. |
45 +| Enabled | Microsoft Authenticator | The user completes MFA by using any method. |
46 +| Enabled | Passkey (FIDO2) | The user completes MFA by using any method. |
4547
4648 For either campaign, a user is prompted only if they're eligible. A user's eligibility depends on the campaign state and the targeted authentication method.
4749
⋯ 66 unchanged lines
114116 |---|---|---|
115117 | Days allowed to snooze | 0–14 | 0–14 |
116118 | Limited number of snoozes | Enabled or disabled | Enabled or disabled |
117 −| Eligible users | Users who meet **all** of the following:<br>• Sign in by using voice call or text message (SMS)<br>• Are enabled for Authenticator push notifications in the authentication methods policy<br>• Don't already have Authenticator push set up | Users who meet **all** of the following:<br>• Sign in by using any MFA method<br>• Are in **any** passkey profile configuration |
119 +| Eligible users | Users who meet **all** of the following:<br>• Sign in by using any MFA method<br>• Are enabled for Authenticator push notifications in the authentication methods policy<br>• Don't already have Authenticator push set up | Users who meet **all** of the following:<br>• Sign in by using any MFA method<br>• Are in **any** passkey profile configuration |
118120
119121 The **Enabled** state doesn't apply the Microsoft managed passkey-profile eligibility check. For example, use the Enabled state to deploy synced passkeys with AAGUID restrictions that aren't in scope for the Microsoft managed state.
120122
⋯ 428 unchanged lines

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy today 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 9 Oct 23:23 UTC · 252 of 253 readable · documentation 341/391 current