(Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants

🚨 The Signal: Microsoft Entra ID is introducing passkey profiles, allowing granular, group-based configuration of device-bound or synced passkeys. Existing FIDO2 tenants will be automatically migrated to this new schema, potentially enabling synced passkeys if attestation enforcement is disabled.

The Impact

Security teams and Entra ID administrators are affected, with a moderate risk of unintended exposure if synced passkeys are automatically enabled without review.

  • Security Teams: Risk of weakened authentication if synced passkeys are enabled by default.
  • Entra ID Admins: Need to review and reconfigure passkey profiles post-migration.
  • Users: May experience changes in authentication method registration prompts.

The Action

  1. Review current FIDO2 attestation settings in Microsoft Entra ID before March 2026.
  2. Plan to opt-in to passkey profiles early to control migration settings.
  3. After migration, review the 'Default passkey profile' for appropriate passkeyType settings.
  4. Configure new passkey profiles for groups to enforce device-bound or synced passkeys as required.
  5. Update Authentication Methods Registration Campaigns to align with new passkey profile settings.

Domain: Entra · Impact: medium · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907