Authentication registration campaigns
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit ae87878 · +5 −5 lines · also on GitHub
⋯ 4 unchanged lines
55
ms.date: 05/04/2026
66
author: mjsantani
77
ai-usage: ai-assisted
8
−ms.custom: sfi-ga-nochange, sfi-image-nochange, msecd-doc-authoring-108
8
+ms.custom: sfi-ga-nochange, sfi-image-nochange, msecd-doc-authoring-1012
99
#Customer intent: As an identity administrator, I want to encourage users to set up Microsoft Authenticator or a passkey in Microsoft Entra ID to improve and secure user sign-in events.
1010
---
1111
⋯ 16 unchanged lines
2828
2929
## Prerequisites
3030
31
−- If you want to know the number of users who registered each authentication method before you configure the registration campaign, see [the Authentication methods activity report](howto-authentication-methods-activity.md#registration-details).
31
+- If you want to know the number of users who registered each authentication method before you configure the registration campaign, see [Authentication methods activity report](howto-authentication-methods-activity.md#registration-details).
3232
- Your organization must enable Microsoft Entra multifactor authentication. The registration campaign has no license requirements.
3333
- **For Authenticator campaigns**: Users can't already have the Authenticator app set up for push notifications on their account. Enable users for the Authenticator app in the Authentication methods policy. The **Authentication mode** must be set to **Any** or **Push**. If the mode is set to **Passwordless**, users aren't eligible for the nudge. For more information, see [Enable passwordless sign-in with Microsoft Authenticator](howto-authentication-passwordless-phone.md).
3434
- **For passkey campaigns**: The passkey (FIDO2) authentication method must be enabled in the Authentication methods policy. In addition, the **Allow self-service setup** toggle must be enabled in the passkey (FIDO2) method configuration. For more information, see [Enable passkeys](how-to-enable-passkey-fido2.md).
⋯ 282 unchanged lines
317317
## Limitations
318318
319319
> [!IMPORTANT]
320
−> The passkey nudge is evaluated on a per-user basis. When a user signs in and is scoped into the registration campaign, their passkey profile is checked for restrictions. If the user's passkey profile has any of the following restrictions, they don't see a nudge upon MFA completion:
320
+> The passkey nudge is evaluated on a per-user basis under Microsoft managed mode. When a user signs in and is scoped into the registration campaign, their passkey profile is checked for restrictions. If the user's passkey profile has any of the following restrictions, they don't see a nudge upon MFA completion:
321321
>
322322
> - Synced only
323323
> - Device-bound only
⋯ 18 unchanged lines
342342
| Any non-platform provider (such as security keys or authenticator apps) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
343343
344344
> [!NOTE]
345
−> - **Linux**: Users aren't nudged. FIDO2 passkeys aren't available on Linux.
345
+> **Linux**: Users aren't nudged. FIDO2 passkeys aren't available on Linux.
346346
347347
## Frequently asked questions
348348
⋯ 55 unchanged lines
404404
405405
**Will Guest/B2B users in my tenant be nudged?**
406406
407
−Yes. If they have been scoped for the nudge using the policy.
407
+Yes, if they're included in the registration campaign policy.
408408
409409
**What if the user closes the browser?**
410410
⋯ 23 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.