A cloud-based identity and access management service for securing user authentication and resource access
Yes. There are prerequisites and tenant settings to check.
For a passkey registration campaign, the required Entra configuration is:
- Enable Passkey (FIDO2) in Authentication methods policy.
- Enable Allow self-service setup in the passkey (FIDO2) method configuration.
- Ensure the targeted users are in scope for that authentication method.
- Configure Entra ID > Authentication methods > Registration campaign.
The registration campaign can target only one authentication method at a time, and it nudges users during an interactive sign-in with MFA.
For tenants with users enabled for SMS or voice, Microsoft states that on September 1, 2026 those users are auto-enabled for passkeys in the Authentication Methods Policy, and the Registration Campaign is updated to Microsoft managed so those users are brought into scope automatically. When they next sign in and complete MFA, they are nudged to register a passkey. By default, the nudge can be snoozed an unlimited number of times.
For the macOS users described, the most relevant checks are:
- In Microsoft Entra admin center, go to Entra ID > Authentication methods and confirm Passkey (FIDO2) is enabled.
- Open the Passkey (FIDO2) configuration and confirm Allow self-service setup is enabled.
- Verify the macOS users are included in the passkey-enabled authentication methods policy scope.
- Go to Entra ID > Authentication methods > Registration campaign and confirm the campaign is either:
- Microsoft managed, or
- explicitly enabled and targeted to the intended users/groups.
About why nudges may not appear:
- Microsoft is still rolling out the updated registration campaign experience, with rollout expected to finish by the end of September 2026. Until then, tenant behavior can differ.
- The campaign performs a platform-specific evaluation before showing a nudge. A user is not nudged on a given OS/browser combination if they already have a compatible passkey for that platform.
- For Windows users already registered with Windows Hello for Business, the nudge is suppressed on Windows.
- For macOS users, if they do not already have a compatible macOS passkey type, they can still be nudged.
- Linux users are not nudged by passkey registration campaigns.
Based on the described state, no separate Conditional Access requirement is documented for triggering the passkey registration campaign. The documented prerequisites are in Authentication methods policy and Registration campaign.
For Microsoft 365 Business Premium, no Business Premium-specific limitation is stated in the provided material. The key requirement is the Entra configuration above, not a separate Business Premium-only switch.
If the goal is to proactively drive adoption instead of waiting for Microsoft-managed behavior, configure the registration campaign directly and target the macOS user group after confirming passkeys are enabled for them.
- Run a registration campaign to set up a passkey or Microsoft Authenticator
- Run a registration campaign to set up a passkey or Microsoft Authenticator
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Frequently asked questions about SMS and voice retirement