Skip to Content

MC1450133 Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method

Summary

  • Microsoft Entra is changing MFA registration so password-only users can register a passkey or passwordless sign-in as their first method.
  • The initial methods covered include synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys, with broader support coming later for Windows Hello for Business, macOS Platform SSO, and Microsoft Authenticator passwordless sign-in.
  • This reduces reliance on weaker first-step methods such as SMS or voice and should improve adoption of phishing-resistant authentication.
  • Admins can govern the experience through existing Microsoft Entra authentication method policies and Conditional Access controls.
  • Microsoft says no action is required, but admins should review registration and Conditional Access settings and update user onboarding guidance if needed.

Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out from October 2026 to February 2027, aims to increase adoption of phishing-resistant authentication without requiring admin action.

Microsoft 365 Message Center ID: MC1450133
Primary Service: Entra
Admin Impact: Medium
User Impact: Medium
Release Start: 15 Oct 2026
Release End: 15 Nov 2026
Last Updated: Aug 11, 2026
Services: Entra, Mac, Security, Windows
Category: Stay informed
Tags: Admin Action, New Feature, Updated message, User impact, Highlighted
Status: Launched
Products & Platforms: Microsoft Entra

History

Updated August 11, 2026: We have updated the content. Thank you for your patience.
8/7/2026 Item Added to Message Center

Microsoft Message

Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method like SMS or Voice before they could add a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey, making it easier to adopt strong authentication from day one. As part of this work, we will also be enabling Authenticator App passwordless sign-in to be a user’s first registered MFA method.

Rollout schedule

This feature will roll out in phases:

Phase 1: Support for synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys.

General Availability (Worldwide, GCC): We will begin rolling out in mid-October 2026 and expect to complete by mid-November 2026.

Phase 2: Support for Windows Hello for Business, macOS Platform SSO, Authenticator App passkey, and Authenticator App passwordless sign-in.

General Availability (Worldwide, GCC): We will begin rolling out in early January 2026 and expect to complete by late February 2027.

Impact on your organization

Who is affected

  • Users who have not yet registered a multifactor authentication method
  • Identity and security administrators responsible for authentication onboarding and registration policies

Platforms and services

  • Microsoft Entra ID
  • Passkeys (FIDO2)
  • Windows Hello for Business
  • macOS Platform SSO
  • Microsoft Authenticator passwordless sign-in

What will happen

  • Password-only users will be able to register passkeys or passwordless sign-in as their first MFA method.
  • Users will no longer need to register a method such as SMS or voice before registering a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO, or Authenticator passwordless sign-in.
  • Organizations may see reduced registration friction and increased adoption of phishing-resistant authentication methods.

Action required and recommendations

No action is required for this change.

We recommend that administrators:

  • Review Conditional Access policies related to security information registration.
  • Consider requiring MFA to register security information if additional verification is required by your organization.
  • Review onboarding and registration guidance so users know to set up a passkey as their preferred first method.

Learn more

(To be updated closer to rollout) Register a synced passkey (FIDO2) | Authentication | Microsoft Entra ID | Microsoft Learn

Compliance considerations

Question: Does the change include an admin control?

Answer: Yes. Administrators can control which authentication methods users are allowed to register through existing Microsoft Entra authentication method policies and Conditional Access policies.

Question: Does the change affect access or authentication controls?

Answer: Yes. The update changes how users register multifactor authentication methods by allowing eligible users to register supported passkeys or passwordless authentication methods as their first MFA method.

Question: Can administrators govern the feature through existing Microsoft Entra controls?

Answer: Yes. Administrators retain control over the feature through Microsoft Entra authentication method policies and Conditional Access configurations.