A cloud-based identity and access management service for securing user authentication and resource access
The supported scope is this:
- September 1, 2026 behavior is explicitly tied to MFA sign-in. Users enabled for SMS or voice are auto-enabled for passkeys and nudged to register upon MFA sign-in.
- After February 1, 2027, the documented enforcement says users whose only available MFA method is SMS or voice are required to register a passkey during sign-in before they can continue accessing the account, and that the prompt is blocking with no opt out.
- The same retirement guidance also states that if those users have not been moved to another phishing-resistant method and no customer-managed telecom provider is configured, they can no longer use SMS or voice to satisfy MFA requirements and continue signing in.
The documentation in scope does not explicitly state whether the February 1, 2027 blocking passkey-registration prompt is triggered on every sign-in, including a sign-in where no MFA challenge is required, or only when an MFA-related sign-in event occurs.
What is explicitly supported is:
- The pre-February nudge is tied to MFA sign-in.
- The post-February experience is a blocking sign-in-time registration requirement for users whose only MFA method is SMS or voice.
- There is no opt out of that February 1, 2027 enforcement.
The context does not provide a definitive statement for the exact edge case of a non-MFA sign-in with no CA MFA requirement.