Microsoft Entra ID
Authentication

Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator

In brief

The documentation now distinguishes Microsoft-managed and enabled campaigns. It specifies the MFA method required for each targeted authentication method and broadens eligible users from SMS or voice sign-ins to users signing in with any MFA method.

What Entra admins need to know

Administrators should use the campaign-state-specific requirements when configuring or troubleshooting MFA registration campaigns.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

A registration campaign prompts users to set up a stronger authentication method—a passkey (FIDO2) or Microsoft Authenticator—after they complete multifactor authentication (MFA).

The following conditions apply:MFA requirement depends on the campaign state and targeted authentication method:

Campaign stateTargeted authentication method When the user is promptedMFA requirement
Microsoft managedMicrosoft Authenticator After theThe user successfully completes MFA by using SMS or voice call.
Microsoft managedPasskey (FIDO2) After theThe user successfullycompletes MFA by using any method.
EnabledMicrosoft AuthenticatorThe user completes MFA by using any method.
EnabledPasskey (FIDO2)The user completes MFA by using any method.

For either campaign, a user is prompted only if they're eligible. A user's eligibility depends on the campaign state and the targeted authentication method.

|---|---|---| | Days allowed to snooze | 0–14 | 0–14 | | Limited number of snoozes | Enabled or disabled | Enabled or disabled | | Eligible users | Users who meet all of the following:
• Sign in by using voice call or text message (SMS)any MFA method
• Are enabled for Authenticator push notifications in the authentication methods policy
• Don't already have Authenticator push set up | Users who meet all of the following:
• Sign in by using any MFA method
• Are in any passkey profile configuration |

The Enabled state doesn't apply the Microsoft managed passkey-profile eligibility check. For example, use the Enabled state to deploy synced passkeys with AAGUID restrictions that aren't in scope for the Microsoft managed state.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…