ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 247/253 feeds/APIs · 391/391 docs · synced 12:49 UTC Customize Public modeDiscuss ChangeIntel on Discord

Authentication registration campaigns

This page's changes and edits · All guidance changes

Microsoft's edit ·

Copy-edit: fix style, accessibility, and SEO issues

Microsoft's commit message in MicrosoftDocs/entra-docs · commit 50a7991 · +12 −12 lines · also on GitHub

11 ---
22 title: Run a registration campaign to set up Microsoft Authenticator or passkey
3 −description: Learn how to nudge users to set up Microsoft Authenticator or a passkey by using a registration campaign in Microsoft Entra ID.
3 +description: Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward Microsoft Authenticator or passkeys for stronger sign-in security.
44 ms.topic: how-to
55 ms.date: 05/04/2026
66 author: mjsantani
⋯ 23 unchanged lines
3030
3131 - If you want to know the number of users who registered each authentication method before you configure the registration campaign, see [the Authentication methods activity report](howto-authentication-methods-activity.md#registration-details).
3232 - Your organization must enable Microsoft Entra multifactor authentication. The registration campaign has no license requirements.
33 −- **For Authenticator campaigns**: Users can't have already set up the Authenticator app for push notifications on their account. Admins need to enable users for the Authenticator app in the Authentication methods policy. The **Authentication mode** must be set to **Any** or **Push**. If the **Authentication mode** is set to **Passwordless**, users aren't eligible for the nudge. For more information about how to set the **Authentication mode**, see [Enable passwordless sign-in with Microsoft Authenticator](howto-authentication-passwordless-phone.md).
33 +- **For Authenticator campaigns**: Users can't already have the Authenticator app set up for push notifications on their account. Enable users for the Authenticator app in the Authentication methods policy. The **Authentication mode** must be set to **Any** or **Push**. If the mode is set to **Passwordless**, users aren't eligible for the nudge. For more information, see [Enable passwordless sign-in with Microsoft Authenticator](howto-authentication-passwordless-phone.md).
3434 - **For passkey campaigns**: The passkey (FIDO2) authentication method must be enabled in the Authentication methods policy. In addition, the **Allow self-service setup** toggle must be enabled in the passkey (FIDO2) method configuration. For more information, see [Enable passkeys](how-to-enable-passkey-fido2.md).
3535
3636 ## User experience
⋯ 72 unchanged lines
109109
110110 ## Enable the registration campaign policy using Graph Explorer
111111
112 −In addition to using the Microsoft Entra admin center, you can also enable the registration campaign policy using Graph Explorer. To enable the registration campaign policy, you must use the Authentication Methods Policy using Graph APIs. Those assigned at least the [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator) role can update the policy.
112 +In addition to using the Microsoft Entra admin center, you can enable the registration campaign policy using Graph Explorer. You must use the Authentication Methods Policy Graph APIs. Those assigned at least the [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator) role can update the policy.
113113
114114 To configure the policy using Graph Explorer:
115115
⋯ 11 unchanged lines
127127
128128 1. Update the registrationEnforcement and authenticationMethodsRegistrationCampaign section of the policy to enable the nudge on a user or group.
129129
130 − ![Screenshot of the API response.](media/how-to-mfa-registration-campaign/response.png)
130 + ![Screenshot of the Graph Explorer API response showing the registrationEnforcement section of the authentication methods policy.](media/how-to-mfa-registration-campaign/response.png)
131131
132132 To update the policy, perform a PATCH on the Authentication Methods Policy with only the updated registrationEnforcement section:
133133
⋯ 146 unchanged lines
280280 }
281281 ```
282282
283 −### Identify the GUIDs of users to insert in the JSONs
283 +### Identify user GUIDs for the JSON request body
284284
285285 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).
286286 1. In the **Manage** blade, select **Users**.
287287 1. On the **Users** page, identify the specific user you want to target.
288 −1. When you tap the specific user, you’ll see their **Object ID**, which is the user’s GUID.
288 +1. When you select the specific user, you see their **Object ID**, which is the user's GUID.
289289
290 − ![User object ID](./media/how-to-nudge-authenticator-app/object-id.png)
290 + ![Screenshot of user properties page showing the Object ID field.](./media/how-to-nudge-authenticator-app/object-id.png)
291291
292 −### Identify the GUIDs of groups to insert in the JSONs
292 +### Identify group GUIDs for the JSON request body
293293
294294 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).
295295 1. In the **Manage** blade, select **Groups**.
296296 1. On the **Groups** page, identify the specific group you want to target.
297297 1. Select the group to get the **Object ID**.
298298
299 − ![Nudge group](./media/how-to-nudge-authenticator-app/group.png)
299 + ![Screenshot of group properties page showing the Object ID field.](./media/how-to-nudge-authenticator-app/group.png)
300300
301301 <!-- comment out PS until ready
302302
⋯ 39 unchanged lines
342342
343343 **Can users be nudged within an application?**
344344
345 −Yes. Registration campaigns support embedded browser views in certain applications. We don't nudge users in out-of-the-box experiences or in browser views embedded in Windows settings.
345 +Yes. Registration campaigns support embedded browser views in certain applications. The campaign doesn't nudge users in out-of-the-box experiences or in browser views embedded in Windows settings.
346346
347347 **Can users be nudged within a single sign-on (SSO) session?**
348348
349 −Nudge doesn't trigger if the user is already signed in with SSO.
349 +The nudge doesn't trigger if the user is already signed in with SSO.
350350
351351 **Can users be nudged on a mobile device?**
352352
⋯ 67 unchanged lines
420420
421421 No, there are no such plans.
422422
423 −## Next steps
423 +## Related content
424424
425425 - [Enable passwordless sign-in with Microsoft Authenticator](howto-authentication-passwordless-phone.md)
426426 - [Enable passkeys (FIDO2)](how-to-enable-passkey-fido2.md)
⋯ 1 unchanged line

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 10 Oct 12:49 UTC · 247 of 253 readable · documentation 391/391 current