IAMinerva
HomeBlogAbout
m3M365 NewscoMicrosoft CopilotteMicrosoft TeamsshSharePoint & OneDriveinIntune & SecurityexExchange & OutlookpoPower PlatformazAzure & Entra IDtuTutorials & GuidesevEvents & ConferencesseSecuritywiWindows
IAMinerva

Professional blog dedicated to the Microsoft 365 ecosystem.

Quick links

HomeBlogAboutNewsletter

Stay informed

Get the latest Microsoft 365 news delivered straight to your inbox.

© 2026 IAMinerva. All rights reserved.

Built withNext.js&Tailwind
Microsoft Entra Passkeys : Enregistrement et Retards Explores
BlogSecurityMicrosoft Entra Passkeys: Registration and Delays Explained
Security#Microsoft Entra#Passkeys#FIDO2

Microsoft Entra Passkeys: Registration and Delays Explained

Analysis of Passkey registration campaign delays in Microsoft Entra and practical solutions for rapid adoption.

Houssem MAKHLOUF
April 15, 2026
3 min read

TL;DR par Minerva

généré par IA

Analysis of Passkey registration campaign delays in Microsoft Entra and practical solutions for rapid adoption.

Introduction

Passkeys in Microsoft Entra (based on FIDO2) represent a major advancement in security, offering robust and passwordless authentication. Yet their general availability rollout is encountering delays primarily linked to registration campaigns. In this article, we detail the reasons for these obstacles, available configuration statuses, and practical strategies for effective adoption.


The 'Enabled' Status and Its Limitations

Although scheduled for release in April 2026, the 'Enabled' status in Passkey registration campaigns has been suspended by Microsoft. Here are the key points explaining this delay:

  • The underlying logic does not properly handle edge cases, particularly for users with specific restrictions such as AAGUIDs (Apparatus Authentication GUID).
  • Manual activation of campaigns in this 'Enabled' status does not currently produce the expected behavior.
  • Poor user experience prompted Microsoft to reconsider these implementations. Updates will be communicated when this status becomes operational.
i

Good to Know

The 'Enabled' status would allow direct activation of Passkey registration campaigns, but its current unavailability should not deter your adoption of this technology.


The 'Microsoft-managed' Status

Starting in May 2026, Passkey registration campaigns under the 'Microsoft-managed' status will be deployed to tenants meeting the following criteria:

  • FIDO2 authentication policy enabled in your tenant.
  • Configuration allowing self-registration by users.
  • No AAGUID restrictions (specific targeting for certain AAGUIDs must not be enabled).
  • Campaign status configured as 'Microsoft-managed'.
  • At least one user enabled for synchronized and device-linked Passkeys.

Impact of 'Microsoft-managed' Status on Users

Here are the main changes for qualified tenants:

  • MFA-eligible users will be progressively invited to register Passkeys.
  • The deferral period will be reduced to a single day, with the option to resubmit indefinitely.
  • All compatible MFA users who meet the criteria will receive these requests.
✦

Tip

Use the available reports in Azure AD to verify which users meet the criteria and could be impacted by this campaign.


Practical Strategies for Passkey Adoption

Effective alternatives exist to facilitate the transition to Passkeys and increase their adoption without relying solely on registration campaigns. Here are three approaches:

1. Use of Temporary Access Pass (TAP)

Temporary Access Passes (TAPs) provide strong temporary authentication. They simplify:

  • User onboarding.
  • Access recovery for post-loss scenarios or device reset.

Key steps:

1

TAP Generation

Generate a TAP via the Azure AD portal or PowerShell.

⚡PowerShell
1New-AzureADTemporaryAccessPass -UserPrincipalName "user@example.com"
2

Redirect to Registration Page

Ask your users to visit aka.ms/mysecurityinfo to configure their Passkey without requiring a password.

2. Conditional Access Policies via Authentication Strengths

Enforce security at the point of access by configuring a phishing-resistant MFA capability through a conditional access policy.

Example policy:

⚡PowerShell
1# Create strong MFA policy resistant to phishing
2New-AzureADConditionalAccessPolicy -Name "PhishingResistantMFA" -AuthenticationStrength "Phishing-resistant MFA"
!

Warning

Ensure that user MFA compatibility is verified before making this policy fully mandatory.

3. Direct Communications to Users

Facilitate adoption by sending targeted communications:

  • Internal documents explaining benefits and instructions.
  • Practical guides included in kits for physical FIDO2 devices.
  • Direct links to the Passkey registration page.
✦

Tip

Pair communications with Q&A sessions to reduce resistance to change.


Conclusion

Although the 'Enabled' status is experiencing delays, the 'Microsoft-managed' status enables automatic adjustments to Passkey campaigns for qualified tenants. Adopt proactive solutions such as TAPs, conditional access policies, and targeted communications to begin the transition.

To learn more, feel free to consult our other articles on MFA authentication strategies in Microsoft 365.

Share:
HM

Houssem MAKHLOUF

Microsoft 365 enthusiast & IT professional.

Previous article

Error IT1272653: Intune Company Portal and Config Files

Apr 14, 2026
Next article

Generate a Weekly Report of Incomplete Tasks on Planner

Apr 15, 2026

Related articles

Classeur ancien ouvert, entouré de symboles de gestion des données et d'archivage.securite

Microsoft Purview: Optimize Data Lifecycle Management

Maximize data security with Microsoft Purview through intelligent lifecycle management and advanced features.

Jun 29, 20264 min
Cadenas stylisé avec des éléments graphiques abstraits et du texte sur la sécurité.securite

New Microsoft 365 Security Adoption Model

Discover the Microsoft 365 security adoption guide based on Zero Trust principles: modular approaches and modern strategies.

Jun 29, 20264 min
Bouclier en or avec un cadenas, éléments numériques éparpillés sur fond noir.securite

Accelerating the Patching Process: Five Eyes Priorities

Why do the Five Eyes recommend prioritizing rapid vulnerability patching? Protect your systems against AI-driven threats with these solutions.

Jun 27, 20264 min