What changed on this day
13 changes were tracked across 2 Microsoft Entra products. The leading updates include Authentication Passkeys Fido2; Migrate Copilot Studio agents to Agent ID; System-preferred authentication in Microsoft Entra ID.
Daily.Entra.News13 changes were tracked across 2 Microsoft Entra products. The leading updates include Authentication Passkeys Fido2; Migrate Copilot Studio agents to Agent ID; System-preferred authentication in Microsoft Entra ID.
Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both primary and multifactor authentication.
| [Registration campaign](how-to-mfa-registration-campaign.md) | Enabled |
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
**Service category:** MFA
If a user's UPN changes, you can no longer modify passkeys (FIDO2) to account for the change. If the user has a passkey (FIDO2), they need to sign in to [Security info](https://mysignins.microsoft.com/security-info), delete the old passkey (FIDO2), and add a new one.
Users who are enabled for external MFA can use it when they sign-in and multifactor authentication is required.
Microsoft Entra determines the default MFA method for the user by priority as follows:
manager: pmwongera
manager: pmwongera
1. Leave **Redirect URI (optional)** alone for now as you configure a redirect URI in the next section.
- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.
author: shlipsey3
Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.