Week in brief

Entra ID is enabling Authenticator passkeys for FIDO2 organizations without key restrictions

The week of 20 January 2025 contains one substantive item: a Microsoft 365 Message Center major update for Entra ID Authentication. Starting in late January 2025, organizations with an enabled passkey (FIDO2) policy and no key restrictions will have passkeys available in the Microsoft Authenticator app. The supplied evidence describes an enablement notice, not a documentation change, and does not label the capability as preview or generally available.

  • Beginning in late January 2025, passkeys in the Microsoft Authenticator app will be available to organizations that have enabled passkey (FIDO2) policy and have not configured key restrictions. Users can add the passkey through aka.ms/MySecurityInfo, and Conditional Access policy governs enforcement. This is the period’s only supplied change.

For Entra administrators

Administrators in the affected configuration should expect users to be able to add an Authenticator passkey through aka.ms/MySecurityInfo, with use enforced by Conditional Access policy. Organizations that do not want this enablement can impose key restrictions. No additional rollout scope or administrative steps are provided.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

1

Microsoft Entra: Enablement of Passkeys in Authenticator for passkey (FIDO2) organizations with no key restrictions

New

Starting late January 2025, organizations with enabled passkey (FIDO2) policy and no key restrictions will have passkeys in the Microsoft Authenticator app. Users can add this via aka.ms/MySecurityInfo, and it's enforced by Conditional Access policy. Organizations preferring not to enable this can impose key restrictions.

25 January 2025
Message CenterMC920300 on mc.merill.net ↗Major updatePlan for change