Authentication registration campaigns
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit 89e5d49 · +17 −15 lines · also on GitHub
11
---
2
−title: Run a registration campaign to set up Microsoft Authenticator or passkey
3
−description: Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward Microsoft Authenticator or passkeys for stronger sign-in security.
2
+title: Run a registration campaign to set up passkey or Microsoft Authenticator
3
+description: Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
44
ms.topic: how-to
55
ms.date: 05/04/2026
6
−author: mjsantani
6
+author: justinha
7
+ms.reviewer: marisanchez
78
ai-usage: ai-assisted
8
−ms.custom: sfi-ga-nochange, sfi-image-nochange, msecd-doc-authoring-1012
9
−#Customer intent: As an identity administrator, I want to encourage users to set up Microsoft Authenticator or a passkey in Microsoft Entra ID to improve and secure user sign-in events.
9
+ms.custom: sfi-ga-nochange, sfi-image-nochange, msecd-doc-authoring-108
10
+#Customer intent: As an identity administrator, I want to encourage users to set up a passkey or Microsoft Authenticator in Microsoft Entra ID to improve and secure user sign-in events.
1011
---
1112
12
−# Run a registration campaign to set up Microsoft Authenticator or passkey
13
+# Run a registration campaign to set up passkey or Microsoft Authenticator
1314
14
−You can nudge users to set up Microsoft Authenticator or a passkey during sign-in. Users go through their regular sign-in, perform multifactor authentication as usual, and then get prompted to set up the targeted authentication method. You can include or exclude users or groups to control who gets nudged, and create targeted campaigns to move users from less secure authentication methods to Authenticator or passkeys.
15
+You can nudge users to set up a passkey or Microsoft Authenticator during sign-in. Users go through their regular sign-in, perform multifactor authentication as usual, and then get prompted to set up the targeted authentication method. You can include or exclude users or groups to control who gets nudged, and create targeted campaigns to move users from less secure authentication methods to passkeys or Authenticator.
1516
1617
Registration campaigns support two authentication methods:
1718
18
−- **Microsoft Authenticator** — Nudge users to download and set up the Authenticator app for push notifications.
19
+
1920
- **Passkey (FIDO2)** — Nudge users to register a passkey, which includes both sync passkeys and device-bound passkeys.
21
+- - **Microsoft Authenticator** — Nudge users to download and set up the Authenticator app for push notifications.
2022
2123
> [!NOTE]
2224
> A registration campaign can only target one authentication method at a time. You can't run campaigns for both Microsoft Authenticator and passkeys simultaneously in the same tenant.
⋯ 5 unchanged lines
2830
2931
## Prerequisites
3032
31
−- If you want to know the number of users who registered each authentication method before you configure the registration campaign, see [Authentication methods activity report](howto-authentication-methods-activity.md#registration-details).
33
+- If you want to know the number of users who registered each authentication method before you configure the registration campaign, see [the Authentication methods activity report](howto-authentication-methods-activity.md#registration-details).
3234
- Your organization must enable Microsoft Entra multifactor authentication. The registration campaign has no license requirements.
3335
- **For Authenticator campaigns**: Users can't already have the Authenticator app set up for push notifications on their account. Enable users for the Authenticator app in the Authentication methods policy. The **Authentication mode** must be set to **Any** or **Push**. If the mode is set to **Passwordless**, users aren't eligible for the nudge. For more information, see [Enable passwordless sign-in with Microsoft Authenticator](howto-authentication-passwordless-phone.md).
3436
- **For passkey campaigns**: The passkey (FIDO2) authentication method must be enabled in the Authentication methods policy. In addition, the **Allow self-service setup** toggle must be enabled in the passkey (FIDO2) method configuration. For more information, see [Enable passkeys](how-to-enable-passkey-fido2.md).
⋯ 282 unchanged lines
317319
## Limitations
318320
319321
> [!IMPORTANT]
320
−> The passkey nudge is evaluated on a per-user basis under Microsoft managed mode. When a user signs in and is scoped into the registration campaign, their passkey profile is checked for restrictions. If the user's passkey profile has any of the following restrictions, they don't see a nudge upon MFA completion:
322
+> The passkey nudge is evaluated on a per-user basis. When a user signs in and is scoped into the registration campaign, their passkey profile is checked for restrictions. If the user's passkey profile has any of the following restrictions, they don't see a nudge upon MFA completion:
321323
>
322324
> - Synced only
323325
> - Device-bound only
⋯ 9 unchanged lines
333335
| Credential | Windows + Chrome | Windows + Edge | Windows + Other | Mac + Chrome | Mac + Edge | Mac + Other | iOS | Android |
334336
|---|---|---|---|---|---|---|---|---|
335337
| Windows Hello for Business | ✔️ | ✔️ | ✔️ | — | — | — | — | — |
336
−| Entra passkey on Windows (EPOW) | ✔️ | ✔️ | — | ✔️ | — | — | — | — |
338
+| Entra passkey on Windows (EPOW) | ✔️ | ✔️ | ✔️ | — | — | — | — | — |
337339
| Google Password Manager | ✔️ | — | — | ✔️ | — | — | — | ✔️ |
338
−| Microsoft Password Manager | ✔️ | — | — | ✔️ | — | — | — | — |
339
−| iCloud Keychain (incl. Managed) | — | — | — | — | ✔️ | ✔️ | ✔️ | — |
340
+| Microsoft Password Manager | — | ✔️ | — | — | ✔️ | — | — | — |
341
+| iCloud Keychain (incl. Managed) | — | — | — | ✔️ | ✔️ | ✔️ | ✔️ | — |
340342
| Mac Platform SSO | — | — | — | ✔️ | ✔️ | ✔️ | — | — |
341343
| Samsung Pass | — | — | — | — | — | — | — | ✔️ |
342344
| Any non-platform provider (such as security keys or authenticator apps) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
343345
344346
> [!NOTE]
345
−> **Linux**: Users aren't nudged. FIDO2 passkeys aren't available on Linux.
347
+> - **Linux**: Users aren't nudged. FIDO2 passkeys aren't available on Linux.
346348
347349
## Frequently asked questions
348350
⋯ 55 unchanged lines
404406
405407
**Will Guest/B2B users in my tenant be nudged?**
406408
407
−Yes, if they're included in the registration campaign policy.
409
+Yes. If they have been scoped for the nudge using the policy.
408410
409411
**What if the user closes the browser?**
410412
⋯ 23 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.