Skip to Content

MC1450133 Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method

Summary

Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method like SMS or Voice before they could add a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey, making it easier to adopt strong authentication from day one. As part of this work, we will also be enabling Authenticator App passwordless sign-in to be a user’s first registered MFA method.

Microsoft 365 Message Center ID: MC1450133
Last Modified: August 8, 2026
Category: Message Center
Tags: New feature, User impact
Status: Launched
Products & Platforms: Microsoft Entra

Rollout schedule

This feature will roll out in phases:

Phase 1: Support for synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys.

General Availability (Worldwide, GCC): We will begin rolling out in mid-October 2026 and expect to complete by mid-November 2026.

Phase 2: Support for Windows Hello for Business, macOS Platform SSO, and Authenticator App passwordless sign-in.

General Availability (Worldwide, GCC): We will begin rolling out in early January 2026 and expect to complete by late February 2027.

Impact on your organization

Who is affected

  • Users who have not yet registered a multifactor authentication method
  • Identity and security administrators responsible for authentication onboarding and registration policies

Platforms and services

  • Microsoft Entra ID
  • Passkeys (FIDO2)
  • Windows Hello for Business
  • macOS Platform SSO
  • Microsoft Authenticator passwordless sign-in

What will happen

  • Password-only users will be able to register passkeys or passwordless sign-in as their first MFA method.
  • Users will no longer need to register a method such as SMS or voice before registering a passkey (FIDO2), Windows Hello for Business, macOS Platform SSO, or Authenticator passwordless sign-in.
  • Organizations may see reduced registration friction and increased adoption of phishing-resistant authentication methods.

Action required and recommendations

No action is required for this change.

We recommend that administrators:

  • Review Conditional Access policies related to security information registration.
  • Consider requiring MFA to register security information if additional verification is required by your organization.
  • Review onboarding and registration guidance so users know to set up a passkey as their preferred first method.

Learn more

(To be updated closer to rollout) Register a synced passkey (FIDO2) | Authentication | Microsoft Entra ID | Microsoft Learn

Compliance considerations

Question: Does the change include an admin control?

Answer: Yes. Administrators can control which authentication methods users are allowed to register through existing Microsoft Entra authentication method policies and Conditional Access policies.

Question: Does the change affect access or authentication controls?

Answer: Yes. The update changes how users register multifactor authentication methods by allowing eligible users to register supported passkeys or passwordless authentication methods as their first MFA method.

Question: Can administrators govern the feature through existing Microsoft Entra controls?

Answer: Yes. Administrators retain control over the feature through Microsoft Entra authentication method policies and Conditional Access configurations.