ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · synced 10:48 UTC Customize Public modeDiscuss ChangeIntel on Discord

Authentication registration campaigns

This page's changes and edits · All guidance changes

Microsoft's edit ·

Update passkey nudge limitations and platform table clarity

Microsoft's commit message in MicrosoftDocs/entra-docs · commit 46e0d37 · +14 −7 lines · also on GitHub

⋯ 74 unchanged lines
7575
7676 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).
7777 1. Browse to **Entra ID** > **Authentication methods** > **Registration campaign** and select **Edit**.
78 −1. For **Authentication method**, select the method to target:
79 −
80 − - **Microsoft Authenticator** — Nudge users to set up the Authenticator app.
81 − - **Passkey** — Nudge users to register a passkey (includes both sync passkeys and device-bound passkeys).
82 −
8378 1. For **State**:
8479
8580 - Select **Enabled** to enable the registration campaign for all users. When the state is set to **Enabled**, you can configure the target authentication method, snooze duration, limited number of snoozes, and include/exclude targets.
⋯ 19 unchanged lines
105100
106101 :::image type="content" border="true" source="media/how-to-mfa-registration-campaign/admin-experience.png" alt-text="Screenshot of the Microsoft Entra admin center registration campaign settings showing state, authentication method, and snooze configuration options.":::
107102
103 +1. For **Authentication method**, select the method to target:
104 +
105 + - **Microsoft Authenticator** — Nudge users to set up the Authenticator app.
106 + - **Passkey** — Nudge users to register a passkey (includes both sync passkeys and device-bound passkeys).
107 +
108108 1. Select any users or groups to exclude from the registration campaign, and then select **Save**.
109109
110110 ## Enable the registration campaign policy using Graph Explorer
⋯ 206 unchanged lines
317317 ## Limitations
318318
319319 > [!IMPORTANT]
320 −> The passkey nudge experience is currently tailored for users in a passkey profile that allows all types of passkeys (both synced and device-bound), has no AAGUID restrictions, and doesn't enforce attestation. If you use the **Enabled** state to target passkeys for users who are limited to device-bound only, synced only, or have AAGUID restrictions, users might be nudged to register a passkey type they aren't allowed to register, and registration fails. Future updates will refine the nudge logic for synced-only and device-bound-only scenarios.
320 +> The passkey nudge is evaluated on a per-user basis. When a user signs in and is scoped into the registration campaign, their passkey profile is checked for restrictions. If the user's passkey profile has any of the following restrictions, they don't see a nudge upon MFA completion:
321 +>
322 +> - Synced only
323 +> - Device-bound only
324 +> - Attestation enforced
325 +> - AAGUID restrictions
321326
322327 ## Passkey nudge evaluation by platform
323328
324 −The registration campaign evaluates whether a user has a local passkey for their current device and browser combination. The following table describes which platform passkey types suppress the nudge on each OS and browser combination:
329 +The registration campaign evaluates whether a user has a local passkey for their current device and browser combination. The following table describes which platform passkey types suppress the nudge on each OS and browser combination. A user needs at least one matching passkey type for the nudge to be suppressed on that device and browser.
330 +
331 +For example, if a user has a Windows Hello for Business credential and signs in on Windows with Chrome, the nudge is suppressed. But if the same user signs in on a Mac with Chrome, they're nudged because that credential doesn't apply to that platform.
325332
326333 | Credential | Windows + Chrome | Windows + Edge | Windows + Other | Mac + Chrome | Mac + Edge | Mac + Other | iOS | Android |
327334 |---|---|---|---|---|---|---|---|---|
⋯ 99 unchanged lines

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 10 Oct 10:48 UTC · 252 of 253 readable · documentation 391/391 current