Message Center
Updated August 11, 2026: We have updated the content. Thank you for your patience.
What and why
Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method like SMS or Voice before they could add a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey, making it easier to adopt strong authentication from day one. As part of this work, we will also be enabling Authenticator App passwordless sign-in to be a user's first registered MFA method.
Rollout schedule
This feature will roll out in phases:
Phase 1: Support for synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys.
General Availability (Worldwide, GCC): We will begin rolling out in mid-October 2026 and expect to complete by mid-November 2026.
Phase 2: Support for Windows Hello for Business, macOS Platform SSO, Authenticator App passkey, and Authenticator App passwordless sign-in.
General Availability (Worldwide, GCC): We will begin rolling out in early January 2026 and expect to complete by late February 2027.
Impact on your organization
Who is affected
Platforms and services
What will happen
Action required and recommendations
No action is required for this change.
We recommend that administrators:
Learn more
Compliance considerations
| Question | Answer |
| Does the change include an admin control? | Yes. Administrators can control which authentication methods users are allowed to register through existing Microsoft Entra authentication method policies and Conditional Access policies. |
| Does the change affect access or authentication controls? | Yes. The update changes how users register multifactor authentication methods by allowing eligible users to register supported passkeys or passwordless authentication methods as their first MFA method. |
| Can administrators govern the feature through existing Microsoft Entra controls? | Yes. Administrators retain control over the feature through Microsoft Entra authentication method policies and Conditional Access configurations. |
What and why
Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method like SMS or Voice before they could add a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey, making it easier to adopt strong authentication from day one. As part of this work, we will also be enabling Authenticator App passwordless sign-in to be a user's first registered MFA method.
Rollout schedule
This feature will roll out in phases:
Phase 1: Support for synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys.
General Availability (Worldwide, GCC): We will begin rolling out in mid-October 2026 and expect to complete by mid-November 2026.
Phase 2: Support for Windows Hello for Business, macOS Platform SSO, and Authenticator App passwordless sign-in.
General Availability (Worldwide, GCC): We will begin rolling out in early January 2026 and expect to complete by late February 2027.
Impact on your organization
Who is affected
Platforms and services
What will happen
Action required and recommendations
No action is required for this change.
We recommend that administrators:
Learn more
Compliance considerations
| Question | Answer |
| Does the change include an admin control? | Yes. Administrators can control which authentication methods users are allowed to register through existing Microsoft Entra authentication method policies and Conditional Access policies. |
| Does the change affect access or authentication controls? | Yes. The update changes how users register multifactor authentication methods by allowing eligible users to register supported passkeys or passwordless authentication methods as their first MFA method. |
| Can administrators govern the feature through existing Microsoft Entra controls? | Yes. Administrators retain control over the feature through Microsoft Entra authentication method policies and Conditional Access configurations. |