Loading...

Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy

Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy

Starting October to November 2027, Microsoft will retire the isAttestationEnforced and keyRestrictions properties from the fido2AuthenticationMethodConfiguration API. These will sync with new properties in the updated passkey policy API schema during transition. Admins must update configurations, automations, and integrations accordingly. Introduction Starting October 2027 and ending November 2027, we will retire the isAttestationEnforced and keyRestrictionsproperties from the existing fido2AuthenticationMethodConfiguration API schema. This change aligns with the latest update to the passkey policy API schema, which introduces support for granular group-based configurations with passkey profiles. During the retirement period, isAttestationEnforced and keyRestrictions will remain in sync with their counterparts attestationEnforcement and keyRestrictions within the Default passkey profile. When this will happen  Retirement begins in mid-October 2027 and is expected to complete by early November 2027. How this affects your organization: You are receiving this message because our reporting indicates your organization may be using this feature. Who is affected: Admins managing FIDO2 authentication configurations and any custom automations or third-party integrations using these properties. What will happen isAttestationEnforced and keyRestrictions properties will be retired. New properties are available in the updated passkey policy API schema. Existing properties will sync with new ones during the transition period. Automations or integrations using retired properties will stop working after the change. What you can do to prepare Review your current configuration. Update any custom automations and third-party integrations to support the new schema. Notify your admins and update internal documentation. Screenshot – The read arrows indicate the properties to be retired: Compliance considerations: No compliance considerations identified, review as appropriate for your organization. View image in new tab Learn more: fido2AuthenticationMethodConfiguration resource type | Microsoft Graph | Microsoft Learn Message ID: MC1188230

The post Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Private tasks now stored in your private plan in Planner

Starting November 2026, private tasks in Microsoft Planner will be stored in users’ private Planner plans instead of Microsoft To Do, en...

7 hours ago

Microsoft Teams: Breakout room support for Teams Rooms on Android

Microsoft Teams Rooms on Android will support breakout rooms, allowing meeting organizers to assign and move these devices between breakout an...

7 hours ago

Updated My Task experience in Planner

Microsoft Planner’s My Tasks experience will be redesigned for clearer navigation, better task organization, and streamlined task creati...

7 hours ago

Microsoft Word for Android: Agent Mode

Microsoft Word for Android will gain Copilot Agent Mode by late September 2026, enabling users to draft, reason, and refine content with AI as...

7 hours ago

Microsoft Dataverse – Bulk generate prompt column values for existing records (backfill)

We are introducing bulk generation of prompt column values for existing Dataverse records. Now, you can have AI-generated values across existi...

7 hours ago

Microsoft Outlook: Update to default blocked file types in OwaMailboxPolicy

Outlook on the web and new Outlook for Windows will block .msix and .msixbundle file types by default in OwaMailboxPolicy starting November 20...

7 hours ago

Dynamics 365 Contact Center: Quality evaluation – Recurring conversation evaluations

Quality Evaluation now supports recurring frequency for conversation evaluations. Previously, only event-based trigger evaluations were suppor...

16 hours ago

Dynamics 365 Commerce: Add multiple items to a transaction using bulk entry

Associates can trigger the Bulk add operation from the button grid on the transaction screen in Store Commerce. A drawer-based dialog opens wh...

16 hours ago

SharePoint: Advanced Management – Inactive files policy

SharePoint administrators can use the Inactive files policy in SharePoint Advanced Management to automatically archive files based on when the...

16 hours ago

OneDrive: Presentation mode for PDFs in the iOS app on iPad

Microsoft OneDrive is introducing presentation mode in the OneDrive iOS app for users on iPad devices. Users select a new Presentation button ...

16 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.