Loading...

Microsoft Entra ID: Auto-enabling passkey profiles

Microsoft Entra ID: Auto-enabling passkey profiles

Starting March 2026, Microsoft Entra ID will auto-enable passkey profiles with a new passkeyType property for device-bound and synced passkeys. Tenants not opting in will be migrated automatically, with existing settings preserved. Microsoft-managed registration campaigns will update targeting to passkeys. Preparation and configuration before rollout are recommended. Starting in March 2026, Microsoft Entra ID will introduce passkey profiles and synced passkeys to General Availability (GA). This update allows administrators to opt in to a new passkey profiles experience that supports group-based passkey configurations and introduces a new passkeyType property. The passkeyType property enables admins to configure: Device-bound passkeys Synced passkeys Both If a tenant does not opt in to passkey profiles during the initial rollout window, the new schema will be automatically enabled at the date range specified below. When this occurs:  Existing Passkey (FIDO2) authentication method configurations will be moved into a Default passkey profile.  The passkeyType value will be set based on the tenant’s current attestation settings. For tenants that have synced passkeys enabled, Microsoft-managed registration campaigns will update to target passkeys. When this will happen General Availability (Worldwide): Rollout begins in early March 2026 and is expected to complete by late March 2026. Automatic enablement for tenants that have not yet opted in (Worldwide): Rollout begins in early April 2026 and is expected to complete by late May 2026. General Availability (GCC, GCC High, and DoD): Rollout begins in early April 2026 and is expected to complete by late April 2026. Automatic enablement for tenants that have not yet opted in (GCC, GCC High, and DoD): Rollout begins in early June 2026 and is expected to complete by late June 2026.  How this affects your organization Who is affected: All Microsoft Entra ID tenants What will happen: If you have not opted in to passkey profiles by your automatic enablement period, your tenant will be migrated to passkey profiles. Your existing Passkey (FIDO2) configurations will be migrated into a Default passkey profile New passkeyType property will be auto-populated If enforce attestation is enabled, then device-bound allowed If enforce attestation is disabled, then device-bound and synced allowed Any existing […]

The post Microsoft Entra ID: Auto-enabling passkey profiles appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Entra ID: Auto-enabling passkey profiles

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

OneDrive Photos on Windows: admin controls and policy support

OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...

9 hours ago

Admin app retiring in Teams, Outlook and Microsoft365.com

The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...

9 hours ago

Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting

Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...

9 hours ago

Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices

The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...

9 hours ago

Outlook for iOS: Minimum system requirements updated to iOS 26 and above

Outlook for iOS will require iOS 26 or later starting mid-September 2026, supporting only the two latest iOS, iPadOS, and watchOS versions. Us...

9 hours ago

Allow connections to copilot.cloud.microsoft before the Copilot URL redirect

Starting September 2026, Microsoft will redirect users from m365.cloud.microsoft to copilot.cloud.microsoft. Organizations must ensure network...

9 hours ago

Prepare for the removal of WMIC from Windows 11

The Windows Management Instrumentation command-line (WMIC) utility has been removed from Windows 11, version 24H2 and later. It’s no longer av...

9 hours ago

Microsoft Agent 365: Active Users export for agent usage reporting

Microsoft Agent 365 will add an Active Users export in the Microsoft 365 admin center, allowing AI and Global Admins to generate a CSV report ...

9 hours ago

The August 2026 Windows non-security preview update is now available

The August 2026 non-security preview update is now available for Windows 11, versions 26H1, 25H2, and 24H2. Information about the contents of ...

9 hours ago

Dynamics 365 Project Operations – Assign task level schedule mode for precise planning

We are announcing the ability to assign task level schedule mode for precise planning in Dynamics 365 Project Operations. This feature will re...

17 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.