Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy
Starting October to November 2027, Microsoft will retire the isAttestationEnforced and keyRestrictions properties from the fido2AuthenticationMethodConfiguration API. These will sync with new properties in the updated passkey policy API schema during transition. Admins must update configurations, automations, and integrations accordingly. Introduction Starting October 2027 and ending November 2027, we will retire the isAttestationEnforced and keyRestrictionsproperties from the existing fido2AuthenticationMethodConfiguration API schema. This change aligns with the latest update to the passkey policy API schema, which introduces support for granular group-based configurations with passkey profiles. During the retirement period, isAttestationEnforced and keyRestrictions will remain in sync with their counterparts attestationEnforcement and keyRestrictions within the Default passkey profile. When this will happen Retirement begins in mid-October 2027 and is expected to complete by early November 2027. How this affects your organization: You are receiving this message because our reporting indicates your organization may be using this feature. Who is affected: Admins managing FIDO2 authentication configurations and any custom automations or third-party integrations using these properties. What will happen isAttestationEnforced and keyRestrictions properties will be retired. New properties are available in the updated passkey policy API schema. Existing properties will sync with new ones during the transition period. Automations or integrations using retired properties will stop working after the change. What you can do to prepare Review your current configuration. Update any custom automations and third-party integrations to support the new schema. Notify your admins and update internal documentation. Screenshot – The read arrows indicate the properties to be retired: Compliance considerations: No compliance considerations identified, review as appropriate for your organization. View image in new tab Learn more: fido2AuthenticationMethodConfiguration resource type | Microsoft Graph | Microsoft Learn Message ID: MC1188230
The post Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams
Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...
Microsoft Teams: Enable agents for existing applications in your organization
For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...
Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile
The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...
Planner: Conditional Coloring
Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...
Outlook: Offline settings “Days of email to save” admin policy
Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...
Microsoft Copilot Studio: Agent Sharing amongst makers
Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...