ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · synced 00:24 UTC Customize Public modeDiscuss ChangeIntel on Discord

Authentication registration campaigns

This page's changes and edits · All guidance changes

Microsoft's edit ·

Rewrite registration campaign guidance for passkeys and Authenticator (#14300)

Microsoft's commit message in MicrosoftDocs/entra-docs · commit ab76f7d · +214 −98 lines · also on GitHub

⋯ 1 unchanged line
22 title: Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator
33 description: Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
44 ms.topic: how-to
5 −ms.date: 05/20/2026
5 +ms.date: 09/02/2026
66 ms.reviewer: marisanchez
77 ai-usage: ai-assisted
88 ms.custom: sfi-ga-nochange, sfi-image-nochange, msecd-doc-authoring-1012
⋯ 2 unchanged lines
1111
1212 # Run a registration campaign to set up a passkey or Microsoft Authenticator
1313
14 −You can nudge users to set up a passkey or Microsoft Authenticator during sign-in. Users go through their regular sign-in, perform multifactor authentication (MFA) as usual, and are then prompted to set up the targeted authentication method. You can include or exclude users or groups to control who gets nudged and create targeted campaigns to move users from less secure authentication methods to passkeys or Authenticator.
14 +> [!NOTE]
15 +> We're rolling out this version of the registration campaign. The rollout is expected to finish by the end of September 2026. Until then, the registration campaign experience in your tenant might differ from what's described in this article.
1516
16 −Registration campaigns support two authentication methods:
17 +The registration campaign allows you to nudge users to set up a passkey or Microsoft Authenticator during sign-in. When a user performs an interactive sign-in with multifactor authentication (MFA), they can be prompted to set up the targeted authentication method. You can include or exclude users or groups to control who gets nudged and create targeted campaigns that move users from less secure authentication methods to passkeys or Authenticator.
1718
18 −- **Passkey (FIDO2)**: Nudges users to register a passkey, which includes both synced passkeys and device-bound passkeys.
19 +The registration campaign supports two authentication methods:
20 +
21 +- **Passkey (FIDO2)**: Nudges users to register a passkey.
1922 - **Authenticator**: Nudges users to download and set up Authenticator for push notifications.
2023
21 −A registration campaign can target only one authentication method at a time. You can't run campaigns for both Authenticator and passkeys simultaneously in the same tenant.
24 +The registration campaign can target one authentication method at a time.
2225
23 −You can also define how many days a user can postpone, or "snooze," the nudge. If a user taps **Skip for now** to postpone setup, they get nudged again on the next MFA attempt after the snooze duration elapses. You can decide whether the user can snooze indefinitely or up to three times (after which registration is required).
26 +## Prerequisites
2427
25 −As users go through their regular sign-in, Microsoft Entra Conditional Access policies that govern security information registration apply before the user is nudged to set up an authentication method. For example, if a Conditional Access policy requires that security information updates can occur only on an internal network. Users aren't prompted unless they're on the internal network.
28 +You can choose from two registration campaigns:
2629
27 −## Prerequisites
30 +- **Authenticator campaign**: Target users who don't already have Authenticator push notifications set up on their account. Enable users for Authenticator in the authentication methods policy. **Authentication mode** must be set to **Any** or **Push**. If the mode is set to **Passwordless**, users aren't eligible for the nudge. For more information, see [Enable passwordless sign-in with Authenticator](howto-authentication-passwordless-phone.md). Users targeted by the registration campaign must also be in scope for this authentication method.
31 +- **Passkey campaign**: Enable the passkey (FIDO2) authentication method in the authentication methods policy. Also enable **Allow self-service setup** in the passkey (FIDO2) method configuration. For more information, see [Enable passkeys](how-to-authentication-passkeys-fido2.md). Users targeted by the registration campaign must also be in scope for this authentication method.
2832
29 −- Optionally, you can determine the number of users who registered each authentication method before you configure the registration campaign. See [Authentication methods activity report](howto-authentication-methods-activity.md#registration-details).
30 −- You must enable multifactor authentication, but there are no license requirements.
31 −- You can choose from two authentication campaigns:
32 − - **Authenticator campaigns**: Users can't already have Authenticator set up for push notifications on their account. Enable users for Authenticator in the authentication methods policy. **Authentication mode** must be set to **Any** or **Push**. If the mode is set to **Passwordless**, users aren't eligible for the nudge. For more information, see [Enable passwordless sign-in with Authenticator](howto-authentication-passwordless-phone.md).
33 − - **Passkey campaigns**: The passkey (FIDO2) authentication method must be enabled in the authentication methods policy. In addition, the **Allow self-service setup** toggle must be enabled in the passkey (FIDO2) method configuration. For more information, see [Enable passkeys](how-to-enable-passkey-fido2.md).
33 +Optionally, determine the number of users who registered each authentication method before you configure the registration campaign. See [Authentication methods activity report](howto-authentication-methods-activity.md#registration-details).
3434
35 +## How a registration campaign works
36 +
37 +A registration campaign prompts users to set up a stronger authentication method—a passkey (FIDO2) or Microsoft Authenticator—after they complete multifactor authentication (MFA).
38 +
39 +The following conditions apply:
40 +
41 +| Targeted authentication method | When the user is prompted |
42 +|---|---|
43 +| Microsoft Authenticator | After the user successfully completes MFA by using SMS or voice call. |
44 +| Passkey (FIDO2) | After the user successfully completes MFA by using any method. |
45 +
46 +For either campaign, a user is prompted only if they're eligible. A user's eligibility depends on the campaign state and the targeted authentication method.
47 +
48 +> [!NOTE]
49 +> As users go through their regular sign-in, Microsoft Entra Conditional Access policies that govern security information registration apply before the user is nudged to set up an authentication method. For example, if a Conditional Access policy requires that security information updates can occur only on an internal network, users aren't prompted unless they're on the internal network.
50 +
51 +## Choose a campaign state
52 +
53 +The campaign state determines who configures and manages the campaign settings.
54 +
55 +| State | Who configures the campaign |
56 +|---|---|
57 +| Microsoft managed | Microsoft selects the targeted authentication method and settings, and updates them to match the current best practices. You define which users are included. |
58 +| Enabled | You select the targeted authentication method, snooze settings, and included users. |
59 +| Disabled | The registration campaign is disabled. |
60 +
61 +Use **Microsoft managed** to apply Microsoft's recommended settings. Use **Enabled** when you need to control the targeted method or the snooze behavior, or when you need to run a passkey campaign for users whose passkey profile isn't eligible under Microsoft managed. For more information, see [Passkey profile eligibility for Microsoft managed registration campaign](#passkey-profile-eligibility-for-microsoft-managed-registration-campaign).
62 +
63 +The following table shows which settings you control in each state.
64 +
65 +| Setting | Microsoft managed | Enabled |
66 +|---|---|---|
67 +| Targeted authentication method | Set by Microsoft | Passkey or Authenticator |
68 +| Days allowed to snooze | Set by Microsoft | 0–14 |
69 +| Limited number of snoozes | Set by Microsoft | On or off |
70 +| Include and exclude users and groups | Configurable | Configurable |
71 +
72 +## Microsoft managed state
73 +
74 +In the **Microsoft managed** state, Microsoft selects the targeted authentication method based on your tenant's authentication method configuration and applies the corresponding recommended settings. Microsoft targets passkey (FIDO2) when included users are enabled for passkeys, and Microsoft Authenticator when they aren't enabled for passkeys but are enabled for Authenticator.
75 +
76 +The following table shows the settings and eligibility that Microsoft applies for each method.
77 +
78 +| Property | Microsoft Authenticator | Passkey (FIDO2) |
79 +|---|---|---|
80 +| Days allowed to snooze | 1 | 1 |
81 +| Limited number of snoozes | Enabled: After 3 snoozes, registration is required | Disabled: Unlimited snoozes |
82 +| Eligible users | Users who meet **all** of the following:<br>• Perform MFA by using voice call or text message (SMS)<br>• Are enabled for Authenticator push notifications in the authentication methods policy<br>• Don't already have Authenticator push set up | Users who meet **all** of the following:<br>• Sign in by using any MFA method<br>• Are in at least one eligible passkey profile (see [Passkey profile eligibility for Microsoft managed registration campaign](#passkey-profile-eligibility-for-microsoft-managed-registration-campaign)) |
83 +
84 +
85 +### Passkey profile eligibility for Microsoft managed registration campaign
86 +
87 +When your registration campaign is in the **Microsoft managed** state and targets passkeys, each scoped user's passkey profile is checked when they sign in. A user is nudged if they're in **at least one** passkey profile configuration that meets the following criteria. This check doesn't apply in the **Enabled** state.
88 +
89 +| Passkey profile configuration | Details |
90 +|---|---|
91 +| Unrestricted | No passkey profile restrictions. |
92 +| Synced-only | Synced passkeys only. No key restrictions. |
93 +| Device-bound-only | Device-bound passkeys only. No key restrictions. |
94 +| AAGUID-restricted | The allow list contains at least one AAGUID for the following providers:<br>• iCloud Keychain<br>• Google Password Manager (GPM)<br>• Microsoft Authenticator passkey<br>• Microsoft Entra passkey on Windows |
95 +| Device-bound with attestation enforced | Key restrictions aren't evaluated. |
96 +
97 +
98 +In AAGUID-restricted profiles:
99 +
100 +- You can add other AAGUIDs as long as the allow list contains at least one AAGUID for a provider in the preceding table.
101 +- **Exclude** and **Block** lists are ignored when campaign eligibility is determined. An admin can have entries in **Exclude** or **Block**, but the targeting logic doesn't evaluate them for eligibility.
102 +- For iCloud Keychain or Google Password Manager AAGUIDs, select the **Synced** passkey profile type. For Microsoft Authenticator passkey or Microsoft Entra passkey on Windows AAGUIDs, select the **Device bound** passkey profile type. For a combination of synced and device-bound AAGUIDs, select both passkey profile types.
103 +
104 +> [!NOTE]
105 +> A user needs only **one** eligible passkey profile to be nudged. If a user is in multiple passkey profiles and any one of them meets the preceding criteria, the user is eligible.
106 +
107 +## Enabled state
108 +
109 +In the **Enabled** state, you select the targeted authentication method and configure the snooze settings and included users. The snooze settings (days allowed to snooze and whether snoozes are limited) are the same options for both methods; the eligibility rules differ by method.
110 +
111 +The following table shows the configuration and eligibility for each method.
112 +
113 +| Setting | Microsoft Authenticator | Passkey (FIDO2) |
114 +|---|---|---|
115 +| Days allowed to snooze | 0–14 | 0–14 |
116 +| Limited number of snoozes | Enabled or disabled | Enabled or disabled |
117 +| Eligible users | Users who meet **all** of the following:<br>• Sign in by using voice call or text message (SMS)<br>• Are enabled for Authenticator push notifications in the authentication methods policy<br>• Don't already have Authenticator push set up | Users who meet **all** of the following:<br>• Sign in by using any MFA method<br>• Are in **any** passkey profile configuration |
118 +
119 +The **Enabled** state doesn't apply the Microsoft managed passkey-profile eligibility check. For example, use the Enabled state to deploy synced passkeys with AAGUID restrictions that aren't in scope for the Microsoft managed state.
120 +
121 +## Snooze experience
122 +
123 +A user can postpone setup of the targeted authentication method by selecting **Skip for now**. When snoozes are limited, a user can snooze up to three times before registration is required. When snoozes aren't limited, a user can snooze indefinitely. After the snooze duration elapses, the user is prompted again the next time they sign in and perform MFA.
124 +
125 +When the registration campaign state is set to **Enabled**, configure the snooze experience by using the following settings:
126 +
127 +| Setting | Description |
128 +|---|---|
129 +| **Days allowed to snooze** | Sets the period between successive prompts. For example, if the period is three days, users who skip registration aren't prompted again for three days. |
130 +| **Limited number of snoozes** | **Enabled**: Users can skip the prompt three times, after which they must register the targeted authentication method.<br><br>**Disabled**: Users can snooze an unlimited number of times. |
131 +
132 +> [!NOTE]
133 +> When **Limited number of snoozes** is set to **Enabled**, the snooze count is tracked per user and persists across campaign restarts or configuration changes (including targeted method updates).
134 +
35135 ## User experience
36136
37137 ### Authenticator campaign
⋯ 4 unchanged lines
42142
43143 1. If you're enabled for Authenticator push notifications and it isn't set up, you're prompted to set up Authenticator to improve your sign-in experience.
44144
45 − Other security features, such as passwordless passkey, self-service password reset, or security defaults, might also prompt you for setup.
145 + Other security features, such as passwordless sign-in, self-service password reset, or security defaults, might also prompt you to set up an authentication method.
46146
47147 :::image type="content" source="./media/how-to-mfa-registration-campaign/user-prompt.png" alt-text="Screenshot that shows the registration campaign prompt asking the user to set up Authenticator.":::
48148
49149 1. Select **Next** and step through Authenticator setup.
50150
51 −1. If you don't want to set up Authenticator, you can select **Skip for now** to snooze the prompt for up to 14 days, which can be set by an admin. Users with free and trial subscriptions can snooze the prompt up to three times.
151 +1. If you don't want to set up Authenticator, select **Skip for now** to snooze the prompt for the number of days configured by your administrator. Users with free and trial subscriptions can snooze the prompt up to three times.
52152
53153 :::image type="content" source="./media/how-to-mfa-registration-campaign/snooze.png" alt-text="Screenshot that shows the Skip for now option to snooze the registration campaign prompt.":::
54154
⋯ 3 unchanged lines
58158
59159 1. You need to complete MFA.
60160
61 −1. If passkey registration is enabled for your account and a passkey isn't registered, you're prompted to set up a passkey.
161 +1. If passkey registration is enabled for your account and a qualifying passkey isn't available for your current platform, you're prompted to set up a passkey.
62162
163 + :::image type="content" source="./media/how-to-mfa-registration-campaign/passkey-campaign-prompt.png" alt-text="Screenshot that shows a passkey registration campaign prompt with Next and Other options." lightbox="./media/how-to-mfa-registration-campaign/passkey-campaign-prompt.png" border="true":::
164 +
63165 > [!NOTE]
64 − > The passkey nudge evaluation determines whether you have a local passkey for your current device and browser combination. If you already have a local passkey for that experience, you aren't nudged. The nudge evaluation is based on each device-and-browser combination that you use, rather than for your user account. For more information about which passkey types satisfy the nudge on each platform, see the [Passkey nudge evaluation by platform](#passkey-nudge-evaluation-by-platform) section.
166 + > The passkey nudge evaluation determines whether you have a local passkey for your current OS and browser combination. If you already have a local passkey for that experience, you aren't nudged. The nudge evaluation is based on each device-and-browser combination that you use, rather than what is registered for your user account. For more information about which passkey types satisfy the nudge on each platform, see the [Passkey nudge evaluation by platform](#passkey-nudge-evaluation-by-platform) section.
65167
168 +1. Select **Next**. Your device or browser displays the passkey creation prompt and shows where the passkey will be saved. Depending on your platform, you might be able to select a different passkey provider or save location.
169 +
170 + :::image type="content" source="./media/how-to-mfa-registration-campaign/passkey-campaign-create.png" alt-text="Screenshot that shows the Setting up your passkey screen while the device opens a security window." lightbox="./media/how-to-mfa-registration-campaign/passkey-campaign-create.png" border="true":::
171 +
172 +1. Follow the device prompts to verify your identity by using your face, fingerprint, or PIN. After verification, the passkey is saved.
173 +
174 +1. On the **Let's name your passkey** screen, enter a name that helps you identify the passkey, and then select **Next**.
175 +
176 + :::image type="content" source="./media/how-to-mfa-registration-campaign/passkey-campaign-name.png" alt-text="Screenshot that shows the Let's name your passkey screen with a passkey name field and Next button." lightbox="./media/how-to-mfa-registration-campaign/passkey-campaign-name.png" border="true":::
177 +
178 +1. On the **Passkey created** screen, select **Done** to finish signing in.
179 +
180 + :::image type="content" source="./media/how-to-mfa-registration-campaign/passkey-campaign-success.png" alt-text="Screenshot that shows the Passkey created screen confirming that registration succeeded." lightbox="./media/how-to-mfa-registration-campaign/passkey-campaign-success.png" border="true":::
181 +
66182 1. If you don't want to set up a passkey, select **Skip for now** to snooze the prompt.
67183
68 −1. If you encounter an error during passkey registration, you see an error screen with a skip option. Skips from the error screen don't count toward your limited skip count, so registration errors don't block your sign-in.
184 +1. If you encounter an error during passkey registration, you see an error screen with a **Skip** option. Skips from the error screen don't count toward your limited snooze count, so registration errors don't block your sign-in.
69185
70186 ## Enable the registration campaign policy by using the Microsoft Entra admin center
71187
⋯ 3 unchanged lines
75191 1. Browse to **Entra ID** > **Authentication methods** > **Registration campaign**, and select **Edit**.
76192 1. For **State**:
77193
78 − - Select **Enabled** to enable the registration campaign for all users. When the state is set to **Enabled**, you can configure the target authentication method, snooze duration, limited number of snoozes, and include/exclude targets.
79 − - Select **Microsoft managed** to enable the registration campaign with Microsoft-recommended defaults. When **Microsoft managed** is selected, the target authentication method, snooze duration, and limited number of snoozes are set automatically and can't be configured. You can still configure include/exclude targets. For more information, see [Protecting authentication methods in Microsoft Entra ID](concept-authentication-default-enablement.md).
80 −
81 − > [!NOTE]
82 − > When the state is set to **Microsoft managed**, Microsoft determines the optimal campaign settings based on best practices for your tenant. The following changes are incrementally rolled out to tenants:
83 − >
84 − > - **Targeted authentication method** changes from Authenticator to passkeys (FIDO2).
85 − > - **Days allowed to snooze** changes to one day. This setting is no longer configurable.
86 − > - **Limited number of snoozes** changes to **Disabled** (unlimited snoozes). This setting is no longer configurable.
87 − > - **User targeting** changes from voice call or text message users to all MFA capable users.
88 − >
89 − > If your tenant targets specific AAGUIDs in the passkey (FIDO2) policy, the targeted authentication method doesn't update to passkeys under Microsoft managed mode. You can still switch to **Enabled** and configure passkey targeting manually. After the changes take effect, targeted users receive passkey registration nudges during sign-in after they finish MFA.
90 − >
91 − > If you want passkeys enabled but don't want the registration campaign to target passkeys, you can switch the state to **Enabled** and target Authenticator. You can also set the state to **Disabled**. For more information about how Microsoft managed values are set, see [Microsoft managed values](concept-authentication-default-enablement.md).
92 −
93 − If the registration campaign state is set to **Enabled**, you can configure the experience for users by using **Limited number of snoozes**:
94 − - If **Limited number of snoozes** is set to **Enabled**, users can skip the interrupt prompt three times, after which they're forced to register the targeted authentication method.
95 − - If **Limited number of snoozes** is set to **Disabled**, users can snooze an unlimited number of times and avoid registration.
96 −
97 − > [!NOTE]
98 − > When **Limited number of snoozes** is set to **Enabled**, the snooze count is tracked per user and persists across campaign restarts or configuration changes (including targeted method updates). This setting ensures a consistent and predictable registration experience.
99 −
100 − **Days allowed to snooze** sets the period between two successive interrupt prompts. For example, if the period is set to three days, users who skipped registration don't get prompted again until after three days.
194 + - Select **Enabled** to enable and configure the registration campaign. When the state is set to **Enabled**, you can configure the target authentication method, snooze duration, limited number of snoozes, and included or excluded targets.
195 + - Select **Microsoft managed** to enable the registration campaign with Microsoft-recommended defaults. When **Microsoft managed** is selected, the target authentication method, snooze duration, and limited number of snoozes are set automatically and can't be configured. You can still configure included or excluded targets. For more information, see [Protecting authentication methods in Microsoft Entra ID](concept-authentication-default-enablement.md).
101196
102197 1. For **Authentication method**, select the method to target:
103198
104199 - **Microsoft Authenticator**: Nudges users to set up Authenticator.
105 − - **Passkey**: Nudges users to register a passkey (includes both synced passkeys and device-bound passkeys).
200 + - **Passkey**: Nudges users to register a passkey that meets the requirements of at least one passkey profile configuration they're scoped to.
106201
107 −1. Select any users or groups to exclude from the registration campaign, and then select **Save**.
202 +1. Select the users or groups to include in or exclude from the registration campaign, and then select **Save**.
108203
109204 :::image type="content" source="./media/how-to-mfa-registration-campaign/enabled-passkey-campaign.png" alt-text="Screenshot that shows the Registration campaign page in the Microsoft Entra admin center showing an enabled passkey campaign with authentication method, snooze settings, and include/exclude targets." lightbox="./media/how-to-mfa-registration-campaign/enabled-passkey-campaign.png" border="true":::
110205
206 +## Passkey nudge evaluation by platform
207 +
208 +After a user is deemed eligible to enroll a passkey based on the registration campaign settings, the campaign performs a further evaluation before nudging them. The campaign checks whether the user already has a local passkey for their current OS and browser combination (platform).
209 +
210 +The following table shows which platform passkey types suppress the nudge on each OS and browser combination. **A user needs at least one matching passkey type on an OS and browser combination for the nudge to be suppressed**. Otherwise, if all other campaign requirements are met, they're nudged to register a compatible passkey type.
211 +
212 +
213 +| Available passkey type | Windows + Chrome | Windows + other browsers | macOS + Chrome | macOS + other browsers | iOS | Android |
214 +|---|---|---|---|---|---|---|
215 +| Windows Hello for Business | ✔️ | ✔️ | — | — | — | — |
216 +| Microsoft Entra passkey on Windows | ✔️ | ✔️ | — | — | — | — |
217 +| Google Password Manager | ✔️ | — | ✔️ | — | — | ✔️ |
218 +| iCloud Keychain (including Managed) | — | — | ✔️ | ✔️ | ✔️ | — |
219 +| macOS Platform SSO | — | — | ✔️ | ✔️ | — | — |
220 +| Samsung Pass | — | — | — | — | — | ✔️ |
221 +| Passkey in Microsoft Authenticator | — | — | — | — | ✔️ | ✔️ |
222 +| Any cross-platform provider, such as a security key | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
223 +
224 +✔️ Nudge is suppressed in this combination
225 +
226 +For example, if a user has a Windows Hello for Business credential and signs in on Windows with Chrome, the nudge is suppressed. But if the same user signs in on a Mac with Chrome browser, they're nudged because that credential is not available to be used on this OS and browser combination.
227 +
228 +> [!NOTE]
229 +> Linux users aren't nudged by passkey registration campaigns.
230 +
231 +### How the passkey profile affects the nudge evaluation
232 +
233 +The passkey nudge evaluation by platform applies when the campaign is in either the Enabled or Microsoft managed state. The evaluation also depends on the passkey profiles configured for the user. The following table describes the behavior for each passkey profile type the user is in scope for.
234 +
235 +| Passkey profile configuration | How the nudge is evaluated |
236 +|---|---|
237 +| Unrestricted | Suppressed per OS and browser according to the preceding table, once the user has a qualifying local passkey for that platform. |
238 +| Synced-only | The user is nudged to register a local **synced** passkey on each platform where one is possible. The nudge is suppressed on a platform after the user has a qualifying local synced passkey available. |
239 +| Device-bound-only | The user is nudged to register a local **device-bound** passkey on each platform where one is possible. The nudge is suppressed on a platform after the user has a qualifying local device-bound passkey available. |
240 +| AAGUID-restricted | The per-platform evaluation doesn't apply. After the user registers **one eligible** passkey, the nudge stops on all OS and browser combinations. |
241 +| Device-bound with attestation enforced | The per-platform evaluation doesn't apply. After the user registers **one eligible** passkey, the nudge stops on all OS and browser combinations. |
242 +
111243 ## Enable the registration campaign policy by using Graph Explorer
112244
113245 In addition to using the Microsoft Entra admin center, you can enable the registration campaign policy by using Graph Explorer. You must use the authentication methods policy Graph APIs. Users who are assigned at least the [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator) role can update the policy.
114246
115247 To configure the policy by using Graph Explorer:
116248
117 −1. Sign in to Graph Explorer and ensure that you consented to the **Policy.Read.All** and **Policy.ReadWrite.AuthenticationMethod** permissions to open the permissions pane.
249 +1. Sign in to [Graph Explorer](https://aka.ms/ge) and consent to the **Policy.Read.All** and **Policy.ReadWrite.AuthenticationMethod** permissions.
118250
119251 ![Screenshot that shows Graph Explorer showing the permissions pane with Policy.Read.All and Policy.ReadWrite.AuthenticationMethod consented.](./media/how-to-nudge-authenticator-app/permissions.png)
120252
121253 1. Retrieve the authentication methods policy:
122254
123 − ```json
255 + ```http
124256 GET https://graph.microsoft.com/v1.0/policies/authenticationmethodspolicy
125257 ```
126258
127259 1. Update the `registrationEnforcement` and `authenticationMethodsRegistrationCampaign` section of the policy to enable the nudge on a user or group.
128260
129 − ![Screenshot that shows the Graph Explorer API response showing the registrationEnforcement section of the authentication methods policy.](media/how-to-mfa-registration-campaign/response.png)
261 + ![Screenshot that shows the Graph Explorer API response showing the registrationEnforcement section of the authentication methods policy.](./media/how-to-mfa-registration-campaign/response.png)
130262
131263 To update the policy, perform a `PATCH` on the authentication methods policy with only the updated `registrationEnforcement` section:
132264
133 − ```json
265 + ```http
134266 PATCH https://graph.microsoft.com/v1.0/policies/authenticationmethodspolicy
135267 ```
136268
⋯ 1 unchanged line
138270
139271 |Name|Possible values|Description|
140272 |------|-----------------|-------------|
141 −|`snoozeDurationInDays`|Range: 0 to 14|Defines the number of days before the user is nudged again.<br>If the value is `0`, the user is nudged during every MFA attempt.<br>Default: One day|
273 +|`snoozeDurationInDays`|Range: 0 to 14|Defines the number of days before the user is nudged again.<br>If the value is `0`, the user is nudged during every MFA attempt.<br>Default: one day|
142274 |`enforceRegistrationAfterAllowedSnoozes`|`true`<br>`false`|Dictates whether a user is required to perform setup after three snoozes.<br>If `true`, the user is required to register.<br>If `false`, the user can snooze indefinitely.<br>Default: `true`|
143275 |`state`|`enabled`<br>`disabled`<br>`default`|Allows you to enable or disable the feature.<br>Default value is used when the configuration isn't explicitly set and uses the Microsoft Entra ID default value for this setting.<br>Change state to `enabled` (for all users) or `disabled` as needed.|
144276 |`excludeTargets`|Doesn't apply|Allows you to exclude different users and groups that you want omitted from the feature. If a user is in an excluded group and an included group, the user is excluded from the feature.|
⋯ 20 unchanged lines
165297
166298 - Include all users and target Authenticator.
167299
168 − If you want to include all users in your tenant and nudge them to set up Authenticator, update the following JSON example with the relevant globally unique identifiers (GUIDs) of your users and groups. Then paste it in Graph Explorer and run `PATCH` on the endpoint.
300 + To include all users in your tenant and nudge them to set up Authenticator, paste the following JSON in Graph Explorer and run `PATCH` on the endpoint.
169301
170302 ```json
171303 {
⋯ 140 unchanged lines
312444
313445 -->
314446
315 −## Limitations
316447
317 −The passkey nudge is evaluated on a per-user basis under Microsoft managed mode. When a user signs in and is scoped into the registration campaign, their passkey profile is checked for restrictions. Users don't see a nudge when MFA is finished if their passkey profile has any of the following restrictions:
318 −
319 −- Synced only
320 −- Device-bound only
321 −- Attestation enforced
322 −- AAGUID restrictions
323 −
324 −## Passkey nudge evaluation by platform
325 −
326 −The registration campaign evaluates whether a user has a local passkey for their current device and browser combination. The following table describes which platform passkey types suppress the nudge on each OS and browser combination. A user needs at least one matching passkey type for the nudge to be suppressed on that device and browser.
448 +## Frequently asked questions
327449
328 −For example, if a user has a Windows Hello for Business credential and signs in on Windows with Chrome, the nudge is suppressed. But if the same user signs in on a Mac with Chrome, they're nudged because that credential doesn't apply to that platform.
450 +### What's the difference between the Enabled and Microsoft managed states?
329451
330 −| Credential | Windows + Chrome | Windows + Other | Mac + Chrome | Mac + Other | iOS | Android |
331 −|---|---|---|---|---|---|---|
332 −| Windows Hello for Business | ✔️ | ✔️ | — | — | — | — |
333 −| Microsoft Entra passkey on Windows | ✔️ | ✔️ | — | — | — | — |
334 −| Google Password Manager | ✔️ | — | ✔️ | — | — | ✔️ |
335 −| iCloud Keychain (including Managed) | — | — | ✔️ | ✔️ | ✔️ | — |
336 −| Mac Platform single sign-on (SSO) | — | — | ✔️ | ✔️ | — | — |
337 −| Samsung Pass | — | — | — | — | — | ✔️ |
338 −| Passkey in Microsoft Authenticator App | — | — | — | — | ✔️ | ✔️ |
339 −| Any nonplatform provider (such as security keys or authenticator apps) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
452 +In the **Enabled** state, you configure the campaign yourself: the targeted method, snooze duration, snooze limit, and who's included or excluded. In the **Microsoft managed** state, Microsoft sets the targeted method, snooze duration, and snooze limit for you based on best practices, and keeps them current. You can still set include/exclude targets in either state. For a full comparison, see [Choose a campaign state](#choose-a-campaign-state).
340453
341 −> [!NOTE]
342 −> Linux users aren't nudged. FIDO2 passkeys aren't available on Linux.
454 +### Why isn't a user I scoped in getting nudged for passkeys under Microsoft managed?
343455
344 −## Frequently asked questions
456 +Under Microsoft managed passkey targeting, a scoped user is nudged only if they're in at least one eligible passkey profile. If the user's only passkey profiles don't meet the criteria (for example, an AAGUID-restricted profile whose Allow list doesn't include any supported AAGUID), they aren't nudged. In the **Enabled** state, passkey targeting doesn't apply these profile checks. For the rules, see [Passkey profile eligibility for Microsoft managed registration campaign](#passkey-profile-eligibility-for-microsoft-managed-registration-campaign).
345457
346 −#### Can users be nudged within an application?
458 +### Can users be nudged within an application?
347459
348460 Yes. Registration campaigns support embedded browser views in certain applications. The campaign doesn't nudge users in out-of-the-box experiences or in browser views embedded in Windows settings.
349461
350 −#### Can users be nudged within an SSO session?
462 +### Can users be nudged within an SSO session?
351463
352464 The nudge doesn't trigger if the user is already signed in with SSO.
353465
354 −#### Can users be nudged on a mobile device?
466 +### Can users be nudged on a mobile device?
355467
356468 It depends on the registration campaign:
357469
⋯ 3 unchanged lines
361473 - Browser-based experiences on mobile devices.
362474 - Native iOS mobile apps. Native Android mobile app support isn't currently available.
363475
364 −#### How long does the campaign run?
476 +### How long does the campaign run?
365477
366478 You can enable the campaign for as long as you want. Whenever you want to be finished running the campaign, use the admin center or APIs to disable the campaign.
367479
368 −#### Can each group of users have a different snooze duration?
480 +### Can each group of users have a different snooze duration?
369481
370482 No. The snooze duration for the prompt is a tenant-wide setting and applies to all groups in scope.
371483
372 −#### Can users be nudged to set up passwordless phone sign-in?
484 +### What if I don't want users to be able to skip registration?
373485
486 +Set **Days allowed to snooze** to `0` and set **Limited number of snoozes** to **Enabled**. Users can still snooze up to three times, but they're prompted again the next time they complete MFA. After the third snooze, registration is required. These settings are available in the **Enabled** state, where you control the campaign configuration.
487 +
488 +### Can users be nudged to set up passwordless phone sign-in?
489 +
374490 The registration campaign feature supports nudging users to set up MFA by using Authenticator or to register a passkey. Passwordless phone sign-in isn't a targeted method for registration campaigns.
375491
376 −#### Does a user who signs in with a non-Microsoft authenticator app see the nudge?
492 +### Does a user who signs in with a non-Microsoft authenticator app see the nudge?
377493
378 −Yes. If a user is enabled for the registration campaign and the targeted authentication method isn't set up (Authenticator for push notifications or a passkey), the user is nudged.
494 +It depends on the targeted authentication method. A passkey campaign can nudge the user after MFA with a non-Microsoft authenticator app if the user meets the other eligibility requirements. An Authenticator campaign prompts the user only after MFA by SMS or voice call.
379495
380 −#### Does a user who has Authenticator set up only for time-based one-time password codes see the nudge?
496 +### Does a user who has Authenticator set up only for time-based one-time password codes see the nudge?
381497
382 −Yes. If a user is enabled for an Authenticator registration campaign and Authenticator isn't set up for push notifications, the user is nudged to set up push notification with Authenticator.
498 +The user is eligible for an Authenticator registration campaign if Authenticator isn't set up for push notifications. However, the prompt appears only after the user completes MFA by SMS or voice call, not after they use a time-based one-time password code.
383499
384 −#### Does a user who already has a passkey see the nudge?
500 +### Does a user who already has a passkey see the nudge?
385501
386 −The passkey nudge evaluates whether a user has a local passkey for their current device and browser combination. If the user already has a local passkey for that experience, they aren't nudged. For this reason, a user might be nudged on one device but not another. For platform-specific information, see the [Passkey nudge evaluation by platform](#passkey-nudge-evaluation-by-platform) section.
502 +The passkey nudge evaluates whether a user has a local passkey for their current OS and browser combination. If the user already has a local passkey for that experience, they aren't nudged. For this reason, a user might be nudged on one device but not another. For platform-specific information, see the [Passkey nudge evaluation by platform](#passkey-nudge-evaluation-by-platform) section.
387503
388 −#### Can I run registration campaigns for both Authenticator and passkeys at the same time?
504 +### Can I run registration campaigns for both Authenticator and passkeys at the same time?
389505
390506 No. A registration campaign can target only one authentication method at a time. You can target either Authenticator or passkeys, but not both simultaneously in the same tenant.
391507
392 −#### If a user just went through MFA registration, are they nudged in the same sign-in session?
508 +### If a user just went through MFA registration, are they nudged in the same sign-in session?
393509
394510 No. To provide a good user experience, users aren't nudged to set up Authenticator in the same session in which they registered other authentication methods.
395511
396 −#### Can I nudge my users to register another authentication method?
512 +### Can I nudge my users to register another authentication method?
397513
398514 Yes. Registration campaigns support nudging users to set up Authenticator or to register a passkey (FIDO2). Select the targeted authentication method when you configure the campaign.
399515
400 −#### Is there a way for me to hide the snooze option and force my users to set up Authenticator?
516 +### Can I hide the snooze option and require users to set up Authenticator?
401517
402 −Set **Limited number of snoozes** to **Enabled** so that users can postpone the app setup for up to three times, after which setup is required.
518 +You can't hide the snooze option immediately. Set **Limited number of snoozes** to **Enabled** so that users can postpone setup up to three times, after which setup is required.
403519
404 −#### Can I nudge my users if I'm not using Microsoft Entra MFA?
520 +### Can I nudge my users if I'm not using Microsoft Entra MFA?
405521
406522 No. The nudge works only for users who are doing MFA by using Microsoft Entra MFA.
407523
408 −#### Are Guest/B2B users in my tenant nudged?
524 +### Are guest users in my tenant nudged?
409525
410526 They're nudged if they're included in a registration campaign for Authenticator. They're not nudged if they're included in a registration campaign for passkeys because passkey support for guest users isn't currently available.
411527
412 −#### What if the user closes the browser?
528 +### What if the user closes the browser?
413529
414530 Closing the browser is the same as snoozing. If setup is required for a user after they snoozed three times, the user is nudged when they next sign in.
415531
416 −#### Why don't some users see a nudge when there's a Conditional Access policy for "Register security information"?
532 +### Why don't some users see a nudge when there's a Conditional Access policy for "Register security information"?
417533
418534 A nudge doesn't appear if a user is in scope for a Conditional Access policy that blocks access to the **Register security information** page.
419535
420 −#### Do users see a nudge when a terms-of-use screen appears during sign-in?
536 +### Do users see a nudge when a terms-of-use screen appears during sign-in?
421537
422538 A nudge doesn't appear if a [terms of use](~/identity/conditional-access/terms-of-use.md) screen appears during sign-in.
423539
424 −#### Do users see a nudge when Conditional Access custom controls are applicable to the sign-in?
540 +### Do users see a nudge when Conditional Access custom controls apply to the sign-in?
425541
426542 A nudge doesn't appear if a user is redirected during sign-in because of [Conditional Access custom controls](~/identity/conditional-access/controls.md) settings.
427543
428544 ## Related content
429545
430546 - [Enable passwordless sign-in with Authenticator](howto-authentication-passwordless-phone.md)
431 −- [Enable passkeys (FIDO2)](how-to-enable-passkey-fido2.md)
547 +- [Enable passkeys (FIDO2)](how-to-authentication-passkeys-fido2.md)
432548 - [Protect authentication methods in Microsoft Entra ID](concept-authentication-default-enablement.md)

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 10 Oct 00:24 UTC · 252 of 253 readable · documentation 391/391 current