ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · synced 03:18 UTC Customize Public modeDiscuss ChangeIntel on Discord

Authentication registration campaigns

This page's changes and edits · All guidance changes

Microsoft's edit ·

[AQ] edit pass: Security info registration (#13295)

Microsoft's commit message in MicrosoftDocs/entra-docs · commit 6f600eb · +138 −149 lines · also on GitHub

11 ---
2 −title: Run a registration campaign to set up passkey or Microsoft Authenticator
2 +title: Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator
33 description: Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
44 ms.topic: how-to
55 ms.date: 05/20/2026
⋯ 4 unchanged lines
1010 #Customer intent: As an identity administrator, I want to encourage users to set up a passkey or Microsoft Authenticator in Microsoft Entra ID to improve and secure user sign-in events.
1111 ---
1212
13 −# Run a registration campaign to set up passkey or Microsoft Authenticator
13 +# Run a registration campaign to set up a passkey or Microsoft Authenticator
1414
15 −You can nudge users to set up a passkey or Microsoft Authenticator during sign-in. Users go through their regular sign-in, perform multifactor authentication as usual, and then get prompted to set up the targeted authentication method. You can include or exclude users or groups to control who gets nudged, and create targeted campaigns to move users from less secure authentication methods to passkeys or Authenticator.
15 +You can nudge users to set up a passkey or Microsoft Authenticator during sign-in. Users go through their regular sign-in, perform multifactor authentication (MFA) as usual, and are then prompted to set up the targeted authentication method. You can include or exclude users or groups to control who gets nudged and create targeted campaigns to move users from less secure authentication methods to passkeys or Authenticator.
1616
1717 Registration campaigns support two authentication methods:
1818
19 −- **Passkey (FIDO2)** — Nudge users to register a passkey, which includes both synced passkeys and device-bound passkeys.
20 −- **Microsoft Authenticator** — Nudge users to download and set up the Authenticator app for push notifications.
19 +- **Passkey (FIDO2)**: Nudges users to register a passkey, which includes both synced passkeys and device-bound passkeys.
20 +- **Authenticator**: Nudges users to download and set up Authenticator for push notifications.
2121
22 −> [!NOTE]
23 −> A registration campaign can only target one authentication method at a time. You can't run campaigns for both Microsoft Authenticator and passkeys simultaneously in the same tenant.
22 +A registration campaign can target only one authentication method at a time. You can't run campaigns for both Authenticator and passkeys simultaneously in the same tenant.
2423
2524 You can also define how many days a user can postpone, or "snooze," the nudge. If a user taps **Skip for now** to postpone setup, they get nudged again on the next MFA attempt after the snooze duration elapses. You can decide whether the user can snooze indefinitely or up to three times (after which registration is required).
2625
27 −> [!NOTE]
28 −> As users go through their regular sign-in, Conditional Access policies that govern security info registration apply before the user is nudged to set up an authentication method. For example, if a Conditional Access policy requires that security info updates can only occur on an internal network, users won't be prompted unless they're on the internal network.
26 +As users go through their regular sign-in, Microsoft Entra Conditional Access policies that govern security information registration apply before the user is nudged to set up an authentication method. For example, if a Conditional Access policy requires that security information updates can occur only on an internal network. Users aren't prompted unless they're on the internal network.
2927
30 −## Prerequisites
28 +## Prerequisites
3129
32 −- If you want to know the number of users who registered each authentication method before you configure the registration campaign, see [Authentication methods activity report](howto-authentication-methods-activity.md#registration-details).
33 −- Your organization must enable Microsoft Entra multifactor authentication. The registration campaign has no license requirements.
34 −- **For Authenticator campaigns**: Users can't already have the Authenticator app set up for push notifications on their account. Enable users for the Authenticator app in the Authentication methods policy. The **Authentication mode** must be set to **Any** or **Push**. If the mode is set to **Passwordless**, users aren't eligible for the nudge. For more information, see [Enable passwordless sign-in with Microsoft Authenticator](howto-authentication-passwordless-phone.md).
35 −- **For passkey campaigns**: The passkey (FIDO2) authentication method must be enabled in the Authentication methods policy. In addition, the **Allow self-service setup** toggle must be enabled in the passkey (FIDO2) method configuration. For more information, see [Enable passkeys](how-to-enable-passkey-fido2.md).
30 +- Optionally, you can determine the number of users who registered each authentication method before you configure the registration campaign. See [Authentication methods activity report](howto-authentication-methods-activity.md#registration-details).
31 +- You must enable multifactor authentication, but there are no license requirements.
32 +- You can choose from two authentication campaigns:
33 + - **Authenticator campaigns**: Users can't already have Authenticator set up for push notifications on their account. Enable users for Authenticator in the authentication methods policy. **Authentication mode** must be set to **Any** or **Push**. If the mode is set to **Passwordless**, users aren't eligible for the nudge. For more information, see [Enable passwordless sign-in with Authenticator](howto-authentication-passwordless-phone.md).
34 + - **Passkey campaigns**: The passkey (FIDO2) authentication method must be enabled in the authentication methods policy. In addition, the **Allow self-service setup** toggle must be enabled in the passkey (FIDO2) method configuration. For more information, see [Enable passkeys](how-to-enable-passkey-fido2.md).
3635
3736 ## User experience
3837
⋯ 1 unchanged line
4039
4140 When you're targeted for an Authenticator registration campaign, you experience the following flow:
4241
43 −1. Authenticate using Microsoft Entra multifactor authentication (MFA).
42 +1. You need to complete MFA.
4443
45 −1. If you're enabled for Authenticator push notifications and don't have it already set up, you get prompted to set up Authenticator to improve your sign-in experience.
44 +1. If you're enabled for Authenticator push notifications and it isn't set up, you're prompted to set up Authenticator to improve your sign-in experience.
4645
47 − > [!NOTE]
48 − > Other security features, such as passwordless passkey, self-service password reset, or security defaults, might also prompt you for setup.
46 + Other security features, such as passwordless passkey, self-service password reset, or security defaults, might also prompt you for setup.
4947
50 − :::image type="content" source="./media/how-to-mfa-registration-campaign/user-prompt.png" alt-text="Screenshot showing the registration campaign prompt asking the user to set up Microsoft Authenticator.":::
48 + :::image type="content" source="./media/how-to-mfa-registration-campaign/user-prompt.png" alt-text="Screenshot that shows the registration campaign prompt asking the user to set up Authenticator.":::
5149
52 −1. Select **Next** and step through the Authenticator app setup.
50 +1. Select **Next** and step through Authenticator setup.
5351
54 −1. If you don't want to set up the Authenticator app, you can select **Skip for now** to snooze the prompt for up to 14 days, which can be set by an admin. Users with free and trial subscriptions can snooze the prompt up to three times.
52 +1. If you don't want to set up Authenticator, you can select **Skip for now** to snooze the prompt for up to 14 days, which can be set by an admin. Users with free and trial subscriptions can snooze the prompt up to three times.
5553
56 − :::image type="content" source="./media/how-to-mfa-registration-campaign/snooze.png" alt-text="Screenshot showing the Skip for now option to snooze the registration campaign prompt.":::
54 + :::image type="content" source="./media/how-to-mfa-registration-campaign/snooze.png" alt-text="Screenshot that shows the Skip for now option to snooze the registration campaign prompt.":::
5755
5856 ### Passkey campaign
5957
6058 When you're targeted for a passkey registration campaign, you experience the following flow:
6159
62 −1. Authenticate using Microsoft Entra multifactor authentication (MFA).
60 +1. You need to complete MFA.
6361
64 −1. If passkey is enabled for your account and you haven't already registered a passkey, you get prompted to set up a passkey.
62 +1. If passkey registration is enabled for your account and a passkey isn't registered, you're prompted to set up a passkey.
6563
6664 > [!NOTE]
67 − > The passkey nudge evaluates whether you have a **local passkey** for your current device and browser combination. If you already have a local passkey for that experience, you aren't nudged. This means the nudge is per-device/browser, not account-wide. For details about which passkey types satisfy the nudge on each platform, see the [passkey nudge evaluation by platform](#passkey-nudge-evaluation-by-platform) section.
65 + > The passkey nudge evaluation determines whether you have a local passkey for your current device and browser combination. If you already have a local passkey for that experience, you aren't nudged. The nudge evaluation is based on each device-and-browser combination that you use, rather than for your user account. For more information about which passkey types satisfy the nudge on each platform, see the [Passkey nudge evaluation by platform](#passkey-nudge-evaluation-by-platform) section.
6866
69 −1. If you don't want to set up a passkey, you can tap **Skip for now** to snooze the prompt.
67 +1. If you don't want to set up a passkey, select **Skip for now** to snooze the prompt.
7068
7169 1. If you encounter an error during passkey registration, you see an error screen with a skip option. Skips from the error screen don't count toward your limited skip count, so registration errors don't block your sign-in.
7270
73 −## Enable the registration campaign policy using the Microsoft Entra admin center
71 +## Enable the registration campaign policy by using the Microsoft Entra admin center
7472
75 −To enable a registration campaign in the Microsoft Entra admin center, complete the following steps:
73 +To enable a registration campaign in the Microsoft Entra admin center, follow these steps:
7674
7775 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).
78 −1. Browse to **Entra ID** > **Authentication methods** > **Registration campaign** and select **Edit**.
76 +1. Browse to **Entra ID** > **Authentication methods** > **Registration campaign**, and select **Edit**.
7977 1. For **State**:
8078
8179 - Select **Enabled** to enable the registration campaign for all users. When the state is set to **Enabled**, you can configure the target authentication method, snooze duration, limited number of snoozes, and include/exclude targets.
8280 - Select **Microsoft managed** to enable the registration campaign with Microsoft-recommended defaults. When **Microsoft managed** is selected, the target authentication method, snooze duration, and limited number of snoozes are set automatically and can't be configured. You can still configure include/exclude targets. For more information, see [Protecting authentication methods in Microsoft Entra ID](concept-authentication-default-enablement.md).
8381
84 − > [!NOTE]
85 − > When the state is set to **Microsoft managed**, Microsoft determines the optimal campaign settings based on best practices for your tenant. The following changes are incrementally rolled out to tenants:
86 − >
87 − > - **Targeted authentication method** changes from Microsoft Authenticator to passkeys (FIDO2).
88 − > - **Days allowed to snooze** changes to 1 day. This setting is no longer configurable.
89 − > - **Limited number of snoozes** changes to Disabled (unlimited snoozes). This setting is no longer configurable.
90 − > - **User targeting** changes from voice call or text message users to all multifactor authentication (MFA) capable users.
91 − >
92 − > If your tenant targets specific AAGUIDs in the passkey (FIDO2) policy, the targeted authentication method won't update to passkeys under Microsoft managed mode. You can still switch to **Enabled** and configure passkey targeting manually. Once the changes take effect, targeted users receive passkey registration nudges during sign-in after they complete multifactor authentication.
93 − >
94 − > If you want passkeys enabled but don't want the registration campaign to target passkeys, you can switch the state to **Enabled** and target Microsoft Authenticator, or set the state to **Disabled**. For more information about how Microsoft managed values are set, see [Microsoft managed values](concept-authentication-default-enablement.md).
95 −
96 − If the registration campaign state is set to **Enabled**, you can configure the experience for end users by using **Limited number of snoozes**:
97 − - If **Limited number of snoozes** is Enabled, users can skip the interrupt prompt 3 times, after which they're forced to register the targeted authentication method.
98 − - If **Limited number of snoozes** is Disabled, users can snooze an unlimited number of times and avoid registration.
82 + > [!NOTE]
83 + > When the state is set to **Microsoft managed**, Microsoft determines the optimal campaign settings based on best practices for your tenant. The following changes are incrementally rolled out to tenants:
84 + >
85 + > - **Targeted authentication method** changes from Authenticator to passkeys (FIDO2).
86 + > - **Days allowed to snooze** changes to one day. This setting is no longer configurable.
87 + > - **Limited number of snoozes** changes to **Disabled** (unlimited snoozes). This setting is no longer configurable.
88 + > - **User targeting** changes from voice call or text message users to all MFA capable users.
89 + >
90 + > If your tenant targets specific AAGUIDs in the passkey (FIDO2) policy, the targeted authentication method doesn't update to passkeys under Microsoft managed mode. You can still switch to **Enabled** and configure passkey targeting manually. After the changes take effect, targeted users receive passkey registration nudges during sign-in after they finish MFA.
91 + >
92 + > If you want passkeys enabled but don't want the registration campaign to target passkeys, you can switch the state to **Enabled** and target Authenticator. You can also set the state to **Disabled**. For more information about how Microsoft managed values are set, see [Microsoft managed values](concept-authentication-default-enablement.md).
93 +␣␣␣␣␣␣␣␣
94 + If the registration campaign state is set to **Enabled**, you can configure the experience for users by using **Limited number of snoozes**:
95 + - If **Limited number of snoozes** is set to **Enabled**, users can skip the interrupt prompt three times, after which they're forced to register the targeted authentication method.
96 + - If **Limited number of snoozes** is set to **Disabled**, users can snooze an unlimited number of times and avoid registration.
9997
10098 > [!NOTE]
101 − > When **Limited number of snoozes** is enabled, the snooze count is tracked per user and persists across campaign restarts or configuration changes (including targeted method updates). This ensures a consistent and predictable registration experience.
102 −
103 − **Days allowed to snooze** sets the period between two successive interrupt prompts. For example, if it's set to 3 days, users who skipped registration don't get prompted again until after 3 days.
99 + > When **Limited number of snoozes** is set to **Enabled**, the snooze count is tracked per user and persists across campaign restarts or configuration changes (including targeted method updates). This setting ensures a consistent and predictable registration experience.
104100
101 + **Days allowed to snooze** sets the period between two successive interrupt prompts. For example, if the period is set to three days, users who skipped registration don't get prompted again until after three days.
105102
106103 1. For **Authentication method**, select the method to target:
107104
108 − - **Microsoft Authenticator** — Nudge users to set up the Authenticator app.
109 − - **Passkey** — Nudge users to register a passkey (includes both synced passkeys and device-bound passkeys).
105 + - **Microsoft Authenticator**: Nudges users to set up Authenticator.
106 + - **Passkey**: Nudges users to register a passkey (includes both synced passkeys and device-bound passkeys).
110107
111108 1. Select any users or groups to exclude from the registration campaign, and then select **Save**.
112109
113 − :::image type="content" source="./media/how-to-mfa-registration-campaign/enabled-passkey-campaign.png" alt-text="Screenshot of the Registration campaign page in the Microsoft Entra admin center showing an enabled passkey campaign with authentication method, snooze settings, and include/exclude targets." lightbox="./media/how-to-mfa-registration-campaign/enabled-passkey-campaign.png" border="true":::
110 + :::image type="content" source="./media/how-to-mfa-registration-campaign/enabled-passkey-campaign.png" alt-text="Screenshot that shows the Registration campaign page in the Microsoft Entra admin center showing an enabled passkey campaign with authentication method, snooze settings, and include/exclude targets." lightbox="./media/how-to-mfa-registration-campaign/enabled-passkey-campaign.png" border="true":::
114111
115 −## Enable the registration campaign policy using Graph Explorer
112 +## Enable the registration campaign policy by using Graph Explorer
116113
117 −In addition to using the Microsoft Entra admin center, you can enable the registration campaign policy using Graph Explorer. You must use the Authentication Methods Policy Graph APIs. Those assigned at least the [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator) role can update the policy.
114 +In addition to using the Microsoft Entra admin center, you can enable the registration campaign policy by using Graph Explorer. You must use the authentication methods policy Graph APIs. Users who are assigned at least the [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator) role can update the policy.
118115
119 −To configure the policy using Graph Explorer:
116 +To configure the policy by using Graph Explorer:
120117
121 −1. Sign in to Graph Explorer and ensure you've consented to the **Policy.Read.All** and **Policy.ReadWrite.AuthenticationMethod** permissions.
118 +1. Sign in to Graph Explorer and ensure that you consented to the **Policy.Read.All** and **Policy.ReadWrite.AuthenticationMethod** permissions to open the permissions pane.
122119
123 − To open the Permissions panel:
120 + ![Screenshot that shows Graph Explorer showing the permissions pane with Policy.Read.All and Policy.ReadWrite.AuthenticationMethod consented.](./media/how-to-nudge-authenticator-app/permissions.png)
124121
125 − ![Screenshot of Graph Explorer showing the Permissions panel with Policy.Read.All and Policy.ReadWrite.AuthenticationMethod consented.](./media/how-to-nudge-authenticator-app/permissions.png)
126 −
127 −1. Retrieve the Authentication methods policy:
122 +1. Retrieve the authentication methods policy:
128123
129124 ```json
130125 GET https://graph.microsoft.com/v1.0/policies/authenticationmethodspolicy
131126 ```
132127
133 −1. Update the registrationEnforcement and authenticationMethodsRegistrationCampaign section of the policy to enable the nudge on a user or group.
128 +1. Update the `registrationEnforcement` and `authenticationMethodsRegistrationCampaign` section of the policy to enable the nudge on a user or group.
134129
135 − ![Screenshot of the Graph Explorer API response showing the registrationEnforcement section of the authentication methods policy.](media/how-to-mfa-registration-campaign/response.png)
136 −
137 − To update the policy, perform a PATCH on the Authentication Methods Policy with only the updated registrationEnforcement section:
130 + ![Screenshot that shows the Graph Explorer API response showing the registrationEnforcement section of the authentication methods policy.](media/how-to-mfa-registration-campaign/response.png)
138131
132 + To update the policy, perform a `PATCH` on the authentication methods policy with only the updated `registrationEnforcement` section:
133 +
139134 ```json
140135 PATCH https://graph.microsoft.com/v1.0/policies/authenticationmethodspolicy
141136 ```
142137
143 −
144 −The following table lists **authenticationMethodsRegistrationCampaign** properties.
138 +The following table lists `authenticationMethodsRegistrationCampaign` properties.
145139
146140 |Name|Possible values|Description|
147141 |------|-----------------|-------------|
148 −|snoozeDurationInDays|Range: 0 - 14|Defines the number of days before the user is nudged again.<br>If the value is 0, the user is nudged during every MFA attempt.<br>Default: 1 day|
149 −|enforceRegistrationAfterAllowedSnoozes|"true"<br>"false"|Dictates whether a user is required to perform setup after 3 snoozes.<br>If true, user is required to register.<br>If false, user can snooze indefinitely.<br>Default: true|
150 −|state|"enabled"<br>"disabled"<br>"default"|Allows you to enable or disable the feature.<br>Default value is used when the configuration hasn't been explicitly set and will use Microsoft Entra ID default value for this setting.<br>Change state to enabled (for all users) or disabled as needed.|
151 −|excludeTargets|N/A|Allows you to exclude different users and groups that you want omitted from the feature. If a user is in a group that is excluded and a group that is included, the user will be excluded from the feature.|
152 −|includeTargets|N/A|Allows you to include different users and groups that you want the feature to target.|
142 +|`snoozeDurationInDays`|Range: 0 to 14|Defines the number of days before the user is nudged again.<br>If the value is `0`, the user is nudged during every MFA attempt.<br>Default: One day|
143 +|`enforceRegistrationAfterAllowedSnoozes`|`true`<br>`false`|Dictates whether a user is required to perform setup after three snoozes.<br>If `true`, the user is required to register.<br>If `false`, the user can snooze indefinitely.<br>Default: `true`|
144 +|`state`|`enabled`<br>`disabled`<br>`default`|Allows you to enable or disable the feature.<br>Default value is used when the configuration isn't explicitly set and uses the Microsoft Entra ID default value for this setting.<br>Change state to `enabled` (for all users) or `disabled` as needed.|
145 +|`excludeTargets`|Doesn't apply|Allows you to exclude different users and groups that you want omitted from the feature. If a user is in an excluded group and an included group, the user is excluded from the feature.|
146 +|`includeTargets`|Doesn't apply|Allows you to include different users and groups that you want the feature to target.|
153147
154 −The following table lists **includeTargets** properties.
148 +The following table lists `includeTargets` properties.
155149
156150 | Name | Possible values | Description |
157151 |------|-----------------|-------------|
158 −| targetType| "user"<br>"group" | The kind of entity targeted. |
159 −| ID | A guid identifier | The ID of the user or group targeted. |
160 −| targetedAuthenticationMethod | "microsoftAuthenticator"<br>"fido2" | The authentication method that the user is nudged to register. Use "microsoftAuthenticator" to nudge users to set up the Authenticator app, or "fido2" to nudge users to register a passkey. |
152 +| `targetType`| `user`<br>`group` | The kind of entity targeted. |
153 +| `ID` | A globally unique identifier (GUID) | The ID of the user or group targeted. |
154 +| `targetedAuthenticationMethod` | `microsoftAuthenticator`<br>`fido2` | The authentication method that the user is nudged to register. Use `microsoftAuthenticator` to nudge users to set up Authenticator, or use `fido2` to nudge users to register a passkey. |
161155
162 −The following table lists **excludeTargets** properties.
156 +The following table lists `excludeTargets` properties.
163157
164158 | Name | Possible values | Description |
165159 |------------|-------------------|---------------------------------------|
166 −| targetType | "user"<br>"group" | The kind of entity targeted. |
167 −| ID | A string | The ID of the user or group targeted. |
160 +| `targetType` | `user`<br>`group` | The kind of entity targeted. |
161 +| `ID` | A string | The ID of the user or group targeted. |
168162
169163 ### Examples
170164
171 −Here are a few sample JSON bodies you can use to get started.
165 +You can use the following sample JSON bodies to get started:
172166
173 −- Include all users and target Authenticator
167 +- Include all users and target Authenticator.
174168
175 − If you want to include ALL users in your tenant and nudge them to set up Authenticator, update the following JSON example with the relevant GUIDs of your users and groups. Then paste it in Graph Explorer and run `PATCH` on the endpoint.
169 + If you want to include all users in your tenant and nudge them to set up Authenticator, update the following JSON example with the relevant globally unique identifiers (GUIDs) of your users and groups. Then paste it in Graph Explorer and run `PATCH` on the endpoint.
176170
177171 ```json
178172 {
⋯ 15 unchanged lines
194188 }
195189 ```
196190
197 −- Include all users and target passkey
191 +- Include all users and target passkeys.
198192
199 − If you want to include ALL users in your tenant and nudge them to register a passkey, update the following JSON example. Then paste it in Graph Explorer and run `PATCH` on the endpoint.
193 + If you want to include all users in your tenant and nudge them to register a passkey, update the following JSON example. Then paste it in Graph Explorer and run `PATCH` on the endpoint.
200194
201195 ```json
202196 {
⋯ 15 unchanged lines
218212 }
219213 ```
220214
221 −- Include specific users or groups of users
215 +- Include specific users or groups of users.
222216
223 − If you want to include certain users or groups in your tenant, update the following JSON example with the relevant GUIDs of your users and groups. Then paste the JSON in Graph Explorer and run `PATCH` on the endpoint.
217 + If you want to include certain users or groups in your tenant, update the following JSON example with the relevant GUIDs of your users and groups. Then paste the JSON in Graph Explorer and run `PATCH` on the endpoint.
224218
225219 ```json
226220 {
⋯ 20 unchanged lines
247241 }
248242 ```
249243
250 −- Include and exclude specific users or groups
244 +- Include and exclude specific users or groups.
251245
252 − If you want to include AND exclude certain users or groups in your tenant, update the following JSON example with the relevant GUIDs of your users and groups. Then paste it in Graph Explorer and run `PATCH` on the endpoint.
246 + If you want to include and exclude certain users or groups in your tenant, update the following JSON example with the relevant GUIDs of your users and groups. Then paste it in Graph Explorer and run `PATCH` on the endpoint.
253247
254248 ```json
255249 {
⋯ 32 unchanged lines
288282 ### Identify user GUIDs for the JSON request body
289283
290284 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).
291 −1. In the **Manage** blade, select **Users**.
292 −1. On the **Users** page, identify the specific user you want to target.
293 −1. When you select the specific user, you see their **Object ID**, which is the user's GUID.
285 +1. In the **Manage** pane, select **Users**.
286 +1. On the **Users** page, identify the specific user that you want to target.
287 +1. When you select the specific user, you see their object ID, which is the user's GUID.
294288
295 − ![Screenshot of user properties page showing the Object ID field.](./media/how-to-nudge-authenticator-app/object-id.png)
296 −␣␣␣
289 + ![Screenshot that shows the user properties page showing the Object ID field.](./media/how-to-nudge-authenticator-app/object-id.png)
290 +
297291 ### Identify group GUIDs for the JSON request body
298292
299293 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).
300 −1. In the **Manage** blade, select **Groups**.
301 −1. On the **Groups** page, identify the specific group you want to target.
302 −1. Select the group to get the **Object ID**.
294 +1. In the **Manage** pane, select **Groups**.
295 +1. On the **Groups** page, identify the specific group that you want to target.
296 +1. Select the group to get the object ID.
303297
304 − ![Screenshot of group properties page showing the Object ID field.](./media/how-to-nudge-authenticator-app/group.png)
305 −␣␣␣
298 + ![Screenshot that shows the group properties page showing the Object ID field.](./media/how-to-nudge-authenticator-app/group.png)
299 +
306300 <!-- comment out PS until ready
307301
308302 ### PowerShell
309303
310304 1. Install the module.
311 −1. Ensure you pass the right roles:
305 +1. Ensure that you pass the right roles:
312306
313307 ```powershell
314308 Connect-MgGraph -Scopes "User.Read.All","Group.ReadWrite.All"
⋯ 6 unchanged lines
321315
322316 ## Limitations
323317
324 −> [!IMPORTANT]
325 −> The passkey nudge is evaluated on a per-user basis under Microsoft managed mode. When a user signs in and is scoped into the registration campaign, their passkey profile is checked for restrictions. If the user's passkey profile has any of the following restrictions, they don't see a nudge upon MFA completion:
326 −>
327 −> - Synced only
328 −> - Device-bound only
329 −> - Attestation enforced
330 −> - AAGUID restrictions
318 +The passkey nudge is evaluated on a per-user basis under Microsoft managed mode. When a user signs in and is scoped into the registration campaign, their passkey profile is checked for restrictions. Users don't see a nudge when MFA is finished if their passkey profile has any of the following restrictions:
331319
320 +- Synced only
321 +- Device-bound only
322 +- Attestation enforced
323 +- AAGUID restrictions
324 +
332325 ## Passkey nudge evaluation by platform
333326
334327 The registration campaign evaluates whether a user has a local passkey for their current device and browser combination. The following table describes which platform passkey types suppress the nudge on each OS and browser combination. A user needs at least one matching passkey type for the nudge to be suppressed on that device and browser.
⋯ 6 unchanged lines
341334 | Microsoft Entra passkey on Windows | ✔️ | ✔️ | — | — | — | — |
342335 | Google Password Manager | ✔️ | — | ✔️ | — | — | ✔️ |
343336 | iCloud Keychain (including Managed) | — | — | ✔️ | ✔️ | ✔️ | — |
344 −| Mac Platform SSO | — | — | ✔️ | ✔️ | — | — |
337 +| Mac Platform single sign-on (SSO) | — | — | ✔️ | ✔️ | — | — |
345338 | Samsung Pass | — | — | — | — | — | ✔️ |
346 −| Any non-platform provider (such as security keys or authenticator apps) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
339 +| Any nonplatform provider (such as security keys or authenticator apps) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
347340
348341 > [!NOTE]
349 −> **Linux**: Users aren't nudged. FIDO2 passkeys aren't available on Linux.
342 +> Linux users aren't nudged. FIDO2 passkeys aren't available on Linux.
350343
351344 ## Frequently asked questions
352345
353 −**Can users be nudged within an application?**
346 +#### Can users be nudged within an application?
354347
355348 Yes. Registration campaigns support embedded browser views in certain applications. The campaign doesn't nudge users in out-of-the-box experiences or in browser views embedded in Windows settings.
356349
357 −**Can users be nudged within a single sign-on (SSO) session?**
358 −
359 −The nudge doesn't trigger if the user is already signed in with SSO.
360 −
361 −**Can users be nudged on a mobile device?**
350 +#### Can users be nudged within an SSO session?
362351
363 −The registration campaign isn't available on mobile devices.
352 +The nudge doesn't trigger if the user is already signed in with SSO.
364353
365 −**How long does the campaign run for?**
354 +#### Can users be nudged on a mobile device?
366355
367 −You can enable the campaign for as long as you like. Whenever you want to be done running the campaign, use the admin center or APIs to disable the campaign.
356 +The registration campaign isn't available on mobile devices.
368357
369 −**Can each group of users have a different snooze duration?**
358 +#### How long does the campaign run?
370359
371 −No. The snooze duration for the prompt is a tenant-wide setting and applies to all groups in scope.
360 +You can enable the campaign for as long as you want. Whenever you want to be finished running the campaign, use the admin center or APIs to disable the campaign.
372361
373 −**Can users be nudged to set up passwordless phone sign-in?**
362 +#### Can each group of users have a different snooze duration?
374363
375 −The registration campaign feature supports nudging users to set up MFA using the Authenticator app or to register a passkey. Passwordless phone sign-in isn't a targeted method for registration campaigns.
364 +No. The snooze duration for the prompt is a tenant-wide setting and applies to all groups in scope.
376365
377 −**Will a user who signs in with a third-party authenticator app see the nudge?**
366 +#### Can users be nudged to set up passwordless phone sign-in?
378367
379 −Yes. If a user is enabled for the registration campaign and doesn't have the targeted authentication method set up (Microsoft Authenticator for push notifications, or a passkey), the user is nudged.
368 +The registration campaign feature supports nudging users to set up MFA by using Authenticator or to register a passkey. Passwordless phone sign-in isn't a targeted method for registration campaigns.
380369
381 −**Will a user who has Authenticator set up only for TOTP codes see the nudge?**
370 +#### Does a user who signs in with a non-Microsoft authenticator app see the nudge?
382371
383 −Yes. If a user is enabled for an Authenticator registration campaign and the Authenticator app isn't set up for push notifications, the user is nudged to set up push notification with Authenticator.
372 +Yes. If a user is enabled for the registration campaign and the targeted authentication method isn't set up (Authenticator for push notifications or a passkey), the user is nudged.
384373
385 −**Will a user who already has a passkey see the nudge?**
374 +#### Does a user who has Authenticator set up only for time-based one-time password codes see the nudge?
386375
387 −The passkey nudge evaluates whether a user has a **local passkey** for their current device and browser combination. If the user already has a local passkey for that experience, they aren't nudged. This means a user might be nudged on one device but not another. For platform-specific details, see the [passkey nudge evaluation by platform](#passkey-nudge-evaluation-by-platform) section.
376 +Yes. If a user is enabled for an Authenticator registration campaign and Authenticator isn't set up for push notifications, the user is nudged to set up push notification with Authenticator.
388377
389 −**Can I run registration campaigns for both Authenticator and passkeys at the same time?**
378 +#### Does a user who already has a passkey see the nudge?
390379
391 −No. A registration campaign can only target one authentication method at a time. You can either target Microsoft Authenticator or passkeys, but not both simultaneously in the same tenant.
380 +The passkey nudge evaluates whether a user has a local passkey for their current device and browser combination. If the user already has a local passkey for that experience, they aren't nudged. For this reason, a user might be nudged on one device but not another. For platform-specific information, see the [Passkey nudge evaluation by platform](#passkey-nudge-evaluation-by-platform) section.
392381
393 −**If a user just went through MFA registration, are they nudged in the same sign-in session?**
382 +#### Can I run registration campaigns for both Authenticator and passkeys at the same time?
394383
395 −No. To provide a good user experience, users won't be nudged to set up the Authenticator in the same session that they registered other authentication methods.
384 +No. A registration campaign can target only one authentication method at a time. You can target either Authenticator or passkeys, but not both simultaneously in the same tenant.
396385
397 −**Can I nudge my users to register another authentication method?**
386 +#### If a user just went through MFA registration, are they nudged in the same sign-in session?
398387
399 −Yes. Registration campaigns support nudging users to set up Microsoft Authenticator or to register a passkey (FIDO2). Select the targeted authentication method when you configure the campaign.
388 +No. To provide a good user experience, users aren't nudged to set up Authenticator in the same session in which they registered other authentication methods.
400389
401 −**Is there a way for me to hide the snooze option and force my users to set up the Authenticator app?**
390 +#### Can I nudge my users to register another authentication method?
402391
403 −Set the **Limited number of snoozes** to **Enabled** such that users can postpone the app setup up to three times, after which setup is required.
392 +Yes. Registration campaigns support nudging users to set up Authenticator or to register a passkey (FIDO2). Select the targeted authentication method when you configure the campaign.
404393
405 −**Will I be able to nudge my users if I'm not using Microsoft Entra multifactor authentication?**
394 +#### Is there a way for me to hide the snooze option and force my users to set up Authenticator?
406395
407 −No. The nudge only works for users who are doing MFA using the Microsoft Entra multifactor authentication service.
396 +Set **Limited number of snoozes** to **Enabled** so that users can postpone the app setup for up to three times, after which setup is required.
408397
409 −**Will Guest/B2B users in my tenant be nudged?**
398 +#### Can I nudge my users if I'm not using Microsoft Entra MFA?
410399
411 −Yes, if they're included in the registration campaign policy.
400 +No. The nudge works only for users who are doing MFA by using Microsoft Entra MFA.
412401
413 −**What if the user closes the browser?**
402 +#### Are Guest/B2B users in my tenant nudged?
414403
415 −It's the same as snoozing. If setup is required for a user after they snoozed three times, the user is nudged when they next sign in.
404 +Yes, if they're included in the registration campaign policy.
416405
417 −**Why don't some users see a nudge when there is a Conditional Access policy for "Register security information"?**
406 +#### What if the user closes the browser?
418407
419 −A nudge won't appear if a user is in scope for a Conditional Access policy that blocks access to the **Register security information** page.
408 +Closing the browser is the same as snoozing. If setup is required for a user after they snoozed three times, the user is nudged when they next sign in.
420409
421 −**Do users see a nudge when there is a terms of use (ToU) screen presented to the user during sign-in?**
410 +#### Why don't some users see a nudge when there's a Conditional Access policy for "Register security information"?
422411
423 −A nudge won't appear if a user is presented with the [terms of use (ToU)](~/identity/conditional-access/terms-of-use.md) screen during sign-in.
412 +A nudge doesn't appear if a user is in scope for a Conditional Access policy that blocks access to the **Register security information** page.
424413
425 −**Do users see a nudge when Conditional Access custom controls are applicable to the sign-in?**
414 +#### Do users see a nudge when a terms-of-use screen appears during sign-in?
426415
427 −A nudge won't appear if a user is redirected during sign-in due to [Conditional Access custom controls](~/identity/conditional-access/controls.md) settings.
416 +A nudge doesn't appear if a [terms of use](~/identity/conditional-access/terms-of-use.md) screen appears during sign-in.
428417
429 −**Are there any plans to discontinue SMS and Voice as methods usable for MFA?**
418 +#### Do users see a nudge when Conditional Access custom controls are applicable to the sign-in?
430419
431 −No, there are no such plans.
420 +A nudge doesn't appear if a user is redirected during sign-in because of [Conditional Access custom controls](~/identity/conditional-access/controls.md) settings.
432421
433422 ## Related content
434423
435 −- [Enable passwordless sign-in with Microsoft Authenticator](howto-authentication-passwordless-phone.md)
424 +- [Enable passwordless sign-in with Authenticator](howto-authentication-passwordless-phone.md)
436425 - [Enable passkeys (FIDO2)](how-to-enable-passkey-fido2.md)
437 −- [Protecting authentication methods in Microsoft Entra ID](concept-authentication-default-enablement.md)
426 +- [Protect authentication methods in Microsoft Entra ID](concept-authentication-default-enablement.md)

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 10 Oct 03:18 UTC · 252 of 253 readable · documentation 391/391 current