Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Note
Please note that passkey isn't supported in Microsoft Azure operated by 21Vianet.
You can nudge users to set up a passkey or Microsoft Authenticator during sign-in. Users go through their regular sign-in, perform multifactor authentication as usual, and then get prompted to set up the targeted authentication method. You can include or exclude users or groups to control who gets nudged, and create targeted campaigns to move users from less secure authentication methods to passkeys or Authenticator.
Registration campaigns support two authentication methods:
- Passkey (FIDO2) — Nudge users to register a passkey, which includes both synced passkeys and device-bound passkeys.
- Microsoft Authenticator — Nudge users to download and set up the Authenticator app for push notifications.
Note
A registration campaign can only target one authentication method at a time. You can't run campaigns for both Microsoft Authenticator and passkeys simultaneously in the same tenant.
You can also define how many days a user can postpone, or "snooze," the nudge. If a user taps Skip for now to postpone setup, they get nudged again on the next MFA attempt after the snooze duration elapses. You can decide whether the user can snooze indefinitely or up to three times (after which registration is required).
Note
As users go through their regular sign-in, Conditional Access policies that govern security info registration apply before the user is nudged to set up an authentication method. For example, if a Conditional Access policy requires that security info updates can only occur on an internal network, users won't be prompted unless they're on the internal network.
Prerequisites
- Your organization must enable Microsoft Entra multifactor authentication. The registration campaign has no license requirements.
- For Authenticator campaigns: Users can't already have the Authenticator app set up for push notifications on their account. Enable users for the Authenticator app in the Authentication methods policy. The Authentication mode must be set to Any or Push. If the mode is set to Passwordless, users aren't eligible for the nudge.
- For passkey campaigns: The passkey (FIDO2) authentication method must be enabled in the Authentication methods policy. In addition, the Allow self-service setup toggle must be enabled in the passkey (FIDO2) method configuration.
User experience
Authenticator campaign
When you're targeted for an Authenticator registration campaign, you experience the following flow:
Authenticate using Microsoft Entra multifactor authentication (MFA).
If you're enabled for Authenticator push notifications and don't have it already set up, you get prompted to set up Authenticator to improve your sign-in experience.
Note
Other security features, such as passwordless passkey, self-service password reset, or security defaults, might also prompt you for setup.
Select Next and step through the Authenticator app setup.
If you don't want to set up the Authenticator app, you can select Skip for now to snooze the prompt for up to 14 days, which can be set by an admin. Users with free and trial subscriptions can snooze the prompt up to three times.
Passkey campaign
When you're targeted for a passkey registration campaign, you experience the following flow:
Authenticate using Microsoft Entra multifactor authentication (MFA).
If passkey is enabled for your account and you haven't already registered a passkey, you get prompted to set up a passkey.
Note
The passkey nudge evaluates whether you have a local passkey for your current device and browser combination. If you already have a local passkey for that experience, you aren't nudged. This means the nudge is per-device/browser, not account-wide.
If you don't want to set up a passkey, you can tap Skip for now to snooze the prompt.
If you encounter an error during passkey registration, you see an error screen with a skip option. Skips from the error screen don't count toward your limited skip count, so registration errors don't block your sign-in.
Enable the registration campaign policy using the Microsoft Entra admin center
To enable a registration campaign in the Microsoft Entra admin center, complete the following steps:
Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
Browse to Entra ID > Authentication methods > Registration campaign and select Edit.
For State:
- Select Enabled to enable the registration campaign for all users. When the state is set to Enabled, you can configure the target authentication method, snooze duration, limited number of snoozes, and include/exclude targets.
- Select Microsoft managed to enable the registration campaign with Microsoft-recommended defaults. When Microsoft managed is selected, the target authentication method, snooze duration, and limited number of snoozes are set automatically and can't be configured. You can still configure include/exclude targets. For more information, see Protecting authentication methods in Microsoft Entra ID.
Note
When the state is set to Microsoft managed, Microsoft determines the optimal campaign settings based on best practices for your tenant. The following changes are incrementally rolled out to tenants:
- Targeted authentication method changes from Microsoft Authenticator to passkeys (FIDO2).
- Days allowed to snooze changes to 1 day. This setting is no longer configurable.
- Limited number of snoozes changes to Disabled (unlimited snoozes). This setting is no longer configurable.
- User targeting changes from voice call or text message users to all multifactor authentication (MFA) capable users.
If your tenant targets specific AAGUIDs in the passkey (FIDO2) policy, the targeted authentication method won't update to passkeys under Microsoft managed mode. You can still switch to Enabled and configure passkey targeting manually. Once the changes take effect, targeted users receive passkey registration nudges during sign-in after they complete multifactor authentication.
If you want passkeys enabled but don't want the registration campaign to target passkeys, you can switch the state to Enabled and target Microsoft Authenticator, or set the state to Disabled. For more information about how Microsoft managed values are set, see Microsoft managed values.
If the registration campaign state is set to Enabled, you can configure the experience for end users by using Limited number of snoozes:
- If Limited number of snoozes is Enabled, users can skip the interrupt prompt 3 times, after which they're forced to register the targeted authentication method.
- If Limited number of snoozes is Disabled, users can snooze an unlimited number of times and avoid registration.
Note
When Limited number of snoozes is enabled, the snooze count is tracked per user and persists across campaign restarts or configuration changes (including targeted method updates). This ensures a consistent and predictable registration experience.
Days allowed to snooze sets the period between two successive interrupt prompts. For example, if it's set to 3 days, users who skipped registration don't get prompted again until after 3 days.
For Authentication method, select the method to target:
- Microsoft Authenticator — Nudge users to set up the Authenticator app.
- Passkey — Nudge users to register a passkey (includes both synced passkeys and device-bound passkeys).
Select any users or groups to exclude from the registration campaign, and then select Save.
Limitations
Important
The passkey nudge is evaluated on a per-user basis under Microsoft managed mode. When a user signs in and is scoped into the registration campaign, their passkey profile is checked for restrictions. If the user's passkey profile has any of the following restrictions, they don't see a nudge upon MFA completion:
- Synced only
- Device-bound only
- Attestation enforced
- AAGUID restrictions
Frequently asked questions
Can users be nudged within an application?
Yes. Registration campaigns support embedded browser views in certain applications. The campaign doesn't nudge users in out-of-the-box experiences or in browser views embedded in Windows settings.
Can users be nudged within a single sign-on (SSO) session?
The nudge doesn't trigger if the user is already signed in with SSO.
Can users be nudged on a mobile device?
The registration campaign isn't available on mobile devices.
How long does the campaign run for?
You can enable the campaign for as long as you like. Whenever you want to be done running the campaign, use the admin center or APIs to disable the campaign.
Can each group of users have a different snooze duration?
No. The snooze duration for the prompt is a tenant-wide setting and applies to all groups in scope.
Can users be nudged to set up passwordless phone sign-in?
The registration campaign feature supports nudging users to set up MFA using the Authenticator app or to register a passkey. Passwordless phone sign-in isn't a targeted method for registration campaigns.
Will a user who signs in with a third-party authenticator app see the nudge?
Yes. If a user is enabled for the registration campaign and doesn't have the targeted authentication method set up (Microsoft Authenticator for push notifications, or a passkey), the user is nudged.
Will a user who has Authenticator set up only for TOTP codes see the nudge?
Yes. If a user is enabled for an Authenticator registration campaign and the Authenticator app isn't set up for push notifications, the user is nudged to set up push notification with Authenticator.
Will a user who already has a passkey see the nudge?
The passkey nudge evaluates whether a user has a local passkey for their current device and browser combination. If the user already has a local passkey for that experience, they aren't nudged. This means a user might be nudged on one device but not another.
Can I run registration campaigns for both Authenticator and passkeys at the same time?
No. A registration campaign can only target one authentication method at a time. You can either target Microsoft Authenticator or passkeys, but not both simultaneously in the same tenant.
If a user just went through MFA registration, are they nudged in the same sign-in session?
No. To provide a good user experience, users won't be nudged to set up the Authenticator in the same session that they registered other authentication methods.
Can I nudge my users to register another authentication method?
Yes. Registration campaigns support nudging users to set up Microsoft Authenticator or to register a passkey (FIDO2). Select the targeted authentication method when you configure the campaign.
Is there a way for me to hide the snooze option and force my users to set up the Authenticator app?
Set the Limited number of snoozes to Enabled such that users can postpone the app setup up to three times, after which setup is required.
Will I be able to nudge my users if I'm not using Microsoft Entra multifactor authentication?
No. The nudge only works for users who are doing MFA using the Microsoft Entra multifactor authentication service.
Will Guest/B2B users in my tenant be nudged?
Yes, if they're included in the registration campaign policy.
What if the user closes the browser?
It's the same as snoozing. If setup is required for a user after they snoozed three times, the user is nudged when they next sign in.
Why don't some users see a nudge when there is a Conditional Access policy for "Register security information"?
A nudge won't appear if a user is in scope for a Conditional Access policy that blocks access to the Register security information page.
Do users see a nudge when there is a terms of use (ToU) screen presented to the user during sign-in?
A nudge won't appear if a user is presented with the terms of use (ToU) screen during sign-in.
Do users see a nudge when Conditional Access custom controls are applicable to the sign-in?
A nudge won't appear if a user is redirected during sign-in due to Conditional Access custom controls settings.
Are there any plans to discontinue SMS and Voice as methods usable for MFA?
No, there are no such plans.