Published Jan 23, 2026
Message Center
Updated March 11,April 15, 2026: We have updated the content. Thank you for your patience.
Introduction
Starting in March 2026, Microsoft Entra ID will introduce passkey profiles and synced passkeys to General Availability (GA). This update allows administrators to opt in to a new passkey profiles experience that supports group-based passkey configurations and introduces a new passkeyType property.
Important: Only tenants that already have Passkeys (FIDO2) enabled are affected by this update.
The passkeyType property enables admins to configure:
If your tenant already has Passkeys (FIDO2) enabled and you do not opt in to passkey profiles during the initial rollout window, your tenant will be automatically migrated to the passkey profiles schema at the date range specified below. When this occurs:
Authentication Methods Registration Campaign changes (Microsoft-Managed Only)
For tenants with passkeysTenants are impacted when all the following conditions are met:
For these tenants, Microsoft-managed registration campaign settings may changewill be updated after passkey profile automatic migration.migration is complete. We will roll out changes incrementally to in-scope tenants according to the timeline outlined below.
When this will happen
Passkey profile and Synced passkeys General Availability (Worldwide):
Automatic migration for existing Passkeyspasskeys (FIDO2) enabled tenants (GCC, GCC High, and DoD):
Authentication Methods registration campaign changes in Microsoft-Managed state (for in-scope tenants):
How this affects your organization
Who is affected: Microsoft Entra IDAutomatic migration for existing passkeys (FIDO2) enabled tenants with Passkeys (FIDO2) enabled
What will happen:
If you have not opted in to passkey profiles by your automatic enablement period, your tenant will be migrated to passkey profiles.
Who is affected for Authentication Methods Registration Campaign changes:
Microsoft Entra ID tenants with passkeys (FIDO2) enabled and active Authentication methods registration campaign set to “Microsoft-managed” state.changes in Microsoft-Managed state (for in-scope tenants)
What will happen:
If your tenant has passkey profiles that allow both device-bound and synced passkeys, does not have attestation enforcement, and does not have AAGUID‑specific key restrictions, your Microsoft-managed registration campaign settings will be updated.
Resulting Microsoft-managed registration campaign changes:updated:
What is the end user impact:
Once the above changes have taken effect, users targeted in the registration campaign will begin to receive passkey registration nudges during sign-in flows after they have completed multifactor authentication.
What you can do to prepare
If you want a configuration different from the migration defaults, review the timeline above and opt in to passkey profiles before your tenant’s automatic enablement window begins. Then configure the Default passkey profile’s passkeyType to your preferred values.
We also recommend:
Learn more:
Compliance considerations
No compliance considerations identified. Review as appropriate for your organization.
Updated March 11, 2026: We have updated the content. Thank you for your patience.
Introduction
Starting in March 2026, Microsoft Entra ID will introduce passkey profiles and synced passkeys to General Availability (GA). This update allows administrators to opt in to a new passkey profiles experience that supports group-based passkey configurations and introduces a new passkeyType property.
Important: Only tenants that already have Passkeys (FIDO2) enabled are affected by this update.
The passkeyType property enables admins to configure:
If your tenant already has Passkeys (FIDO2) enabled and you do not opt in to passkey profiles during the initial rollout window, your tenant will be automatically migrated to the passkey profiles schema at the date range specified below. When this occurs:
Authentication Methods Registration Campaign changes (Microsoft-Managed Only)
For tenants with passkeys (FIDO2) enabled and active Authentication methods registration campaign set to “Microsoft-managed” state, the registration campaign settings may change after passkey profile automatic migration.
When this will happen
How this affects your organization
Who is affected: Microsoft Entra ID tenants with Passkeys (FIDO2) enabled
What will happen:
If you have not opted in to passkey profiles by your automatic enablement period, your tenant will be migrated to passkey profiles.
Who is affected for Authentication Methods Registration Campaign changes:
Microsoft Entra ID tenants with passkeys (FIDO2) enabled and active Authentication methods registration campaign set to “Microsoft-managed” state.
What will happen:
If your tenant has passkey profiles that allow both device-bound and synced passkeys, does not have attestation enforcement, and does not have AAGUID‑specific key restrictions, your Microsoft-managed registration campaign settings will be updated.
Resulting Microsoft-managed registration campaign changes:
What is the end user impact:
Once the above changes have taken effect, users targeted in the registration campaign will begin to receive passkey registration nudges during sign-in flows after they have completed multifactor authentication.
What you can do to prepare
If you want a configuration different from the migration defaults, review the timeline above and opt in to passkey profiles before your tenant’s automatic enablement window begins. Then configure the Default passkey profile’s passkeyType to your preferred values.
We also recommend:
Learn more:
Compliance considerations
No compliance considerations identified. Review as appropriate for your organization.