Microsoft Entra ID: Passkey support for B2B users

🚨 The Signal: Microsoft Entra ID now supports phishing-resistant passkeys for B2B guest and external users in resource tenants. This closes a critical security gap, allowing these users to satisfy MFA requirements with stronger authentication methods, improving overall identity security for federated access.

The Impact

Microsoft Entra administrators are affected by the ability to enforce phishing-resistant MFA for B2B users, significantly reducing identity compromise risk.

  • Security teams: Reduced risk of B2B identity compromise via phishing.
  • Entra administrators: New options for B2B MFA policy enforcement.
  • B2B users: Improved security and user experience for resource access.

The Action

  1. Review existing Conditional Access policies for B2B users to ensure passkey usage is permitted or required.
  2. Communicate passkey registration options to B2B users, including My Security Info page and registration campaigns.
  3. Monitor Entra sign-in logs for B2B users to track passkey adoption and identify any authentication issues.

Domain: Entra · Impact: high · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907