Entra ID to auto-enable passkey profiles and add synced passkeys from March 2026

by

Starting March 2026, Entra ID will automatically enable passkey profiles and add support for synced passkeys Microsoft message center announcement announces.

KEY FACTS

  • Change Automatic enablement of passkey profiles and support for synced passkeys begin March 2026
  • Configuration New passkeyType property controls device-bound, synced, or both
  • Rollout Staged rollout with an initial opt-in window then automatic migration for non opt-in tenants
  • Migration Existing FIDO2 passkey authentication settings move into a default passkey profile

The update moves passkey profiles and synced passkeys into general availability. Administrators gain a new passkey profiles experience that supports group based configuration and lets security teams apply passkey policies to specific user groups rather than at tenant level.

A new passkeyType property lets administrators define which passkey registration types users may use: device bound passkeys, synced passkeys, or both. The setting applies at the passkey profile level giving organizations control over passkey usage.

The rollout will be staged with an initial opt-in window followed by automatic migration for tenants that do not opt in. During migration existing FIDO2 passkey authentication method settings will move into a default passkey profile and the passkeyType value will be set based on the tenant’s current attestation configuration.

Tenants that already allow synced passkeys will see managed registration campaigns update their targeting to include passkeys in the registration flow. No immediate administrative action is required. Organizations can review current FIDO2 and passkey settings ahead of March 2026 and decide whether to opt in early or allow the automatic transition.

WHY IT MATTERS

Group based passkey profiles and the passkeyType setting give administrators more control over how passkeys are deployed and registered. Synced passkey support and automatic migration may change how users enroll authenticators across tenants.