Starting October to November 2027, Microsoft will retire the isAttestationEnforced and keyRestrictions properties from the fido2AuthenticationMethodConfiguration API. These will sync with new properties in the updated passkey policy API schema during transition. Admins must update configurations, automations, and integrations accordingly.
Introduction
Starting October 2027 and ending November 2027, we will retire the isAttestationEnforced and keyRestrictionsproperties from the existing fido2AuthenticationMethodConfiguration API schema. This change aligns with the latest update to the passkey policy API schema, which introduces support for granular group-based configurations with passkey profiles.
During the retirement period, isAttestationEnforced and keyRestrictions will remain in sync with their counterparts attestationEnforcement and keyRestrictions within the Default passkey profile.
When this will happen
Retirement begins in mid-October 2027 and is expected to complete by early November 2027.
How this affects your organization:
You are receiving this message because our reporting indicates your organization may be using this feature.
Who is affected: Admins managing FIDO2 authentication configurations and any custom automations or third-party integrations using these properties.
What will happen
isAttestationEnforced and keyRestrictions properties will be retired.What you can do to prepare
Screenshot - The read arrows indicate the properties to be retired:

Learn more: fido2AuthenticationMethodConfiguration resource type | Microsoft Graph | Microsoft Learn
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.