Why is Microsoft pushing passkey enrollment even when we use Authenticator?

0
2
Asked By MellowCedar47 On

Our company recently started pushing passkey enrollment, and the messaging has created a lot of confusion. We initially understood that employees using the Microsoft Authenticator app could bypass passkeys, while people using SMS or voice authentication would be required to enroll. However, several users who only use Authenticator are still being prompted to create a Windows Hello PIN or begin passkey setup.

Is passkey enrollment actually mandatory for certain users, or can Authenticator still be used as an alternative? Does merely having SMS or voice enabled on an account trigger the enrollment prompt, even if the user never uses those methods? Also, once Windows Hello or another passkey is configured, can users continue selecting "Sign-in options" and choosing password or Authenticator instead?

We need to explain this clearly to nontechnical staff and avoid creating unnecessary support work. Any practical guidance on how these authentication methods interact would be appreciated.

4 Answers

Answered By BluePineapple22 On

Having SMS or voice enabled can make an account eligible for passkey registration prompts, even if the user normally signs in with Authenticator. In some rollouts, users must be removed from those legacy methods to avoid the prompt. However, reports can vary depending on the policy and rollout stage, so it is worth checking the actual authentication method policy and registration campaign rather than relying only on the email wording.

CrispLemon5 -

That may explain some of the mixed results, but users should verify whether SMS is merely enabled as a fallback or actually registered on each account. Those settings can affect who receives the prompt.

Answered By QuartzHarbor8 On

Authenticator and passkeys are not automatically the same thing. A normal Authenticator approval or number match is a multifactor method, while a passkey is designed to be phishing-resistant. Microsoft may prompt users to register a passkey based on the authentication methods enabled by tenant policy, device eligibility, or the rollout settings. The prompt does not necessarily mean that every user must immediately stop using Authenticator, but the exact behavior depends on the policies configured in Entra ID.

MellowCedar47 -

That distinction helps. Our problem is that the rollout emails make it sound as if Authenticator users are completely exempt, which may not match the actual tenant settings.

Answered By LunarMaple30 On

For a company rollout, first document exactly which methods are enabled: Authenticator approval, passwordless Authenticator, SMS, voice, Windows Hello for Business, FIDO2 security keys, and passkeys in password managers are different options. Then test with accounts representing each combination. Check the Entra authentication methods policy, registration campaign, Conditional Access rules, and any Windows Hello for Business policy. That will give you a definitive answer for your tenant instead of assuming the behavior is universal.

Answered By CopperMoth61 On

The PIN prompt is often for Windows Hello or for the local credential store used by a passkey. The PIN unlocks the credential on that specific device; it is not the user's Microsoft 365 password and is not normally sent to the service as the authentication secret. Once Hello or another passkey is registered, users may still be able to choose another sign-in method through “Sign-in options,” but administrators can restrict or require methods through tenant policy.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.