Entra Passkey Registration Campaign
By John Savill's Technical Training
Key Concepts
- Passkeys: A passwordless authentication standard based on public-key cryptography that is resistant to phishing and credential stuffing.
- Public Key Cryptography: An authentication method where the server stores only a public key, rendering stolen server-side data useless to attackers.
- Proximity Requirement: A security feature ensuring the user is physically present (via NFC, Bluetooth, USB, or TPM) to authenticate, preventing remote social engineering.
- Passkey Profiles: Tenant-level configurations defining constraints (e.g., device-bound vs. synced, attestation requirements, and allowed AAGUIDs) for specific user groups.
- Registration Campaign: A feature that "nudges" users to set up passkeys during their login flow.
- AAGUID (Authenticator Attestation GUID): A unique identifier for a specific model of authenticator, used to restrict or allow specific hardware/software types.
- Conditional Access: An additional layer of security that evaluates device health and management status (e.g., Intune compliance) alongside passkey authentication.
1. The Security Value of Passkeys
Passkeys are presented as the preferred authentication mechanism due to their balance of usability and high security:
- Usability: Eliminates the need to remember passwords or wait for SMS/authenticator app codes. Users authenticate via biometrics or device passcodes.
- Phishing Resistance: Passkeys are bound to the specific domain they were created for. If a user is directed to a fraudulent site (e.g., "RN Microsoft" instead of "Microsoft"), the browser will refuse to use the passkey, preventing credential theft.
- Credential Stuffing Protection: Because passkeys are not shared across sites and rely on public-key cryptography, they cannot be reused or "stuffed" into other services if a database is breached.
2. Configuring Passkey Profiles
Organizations must define how passkeys are used within their tenant via Passkey Profiles:
- Constraints: Administrators can mandate whether passkeys must be device-bound (tied to a specific hardware chip) or synced (stored in cloud ecosystems like iCloud or Google Password Manager).
- Attestation: Admins can enforce attestation to verify the authenticity of the authenticator hardware.
- AAGUID Filtering: Admins can restrict authentication to specific, approved authenticator types (e.g., Windows Hello, specific security keys).
- Assignment: These profiles are assigned to specific Entra ID groups, allowing for different security postures for standard users versus high-privileged administrators.
3. Registration Campaigns (The "Nudge")
The registration campaign is a mechanism to drive user adoption by prompting them to create a passkey during the sign-in process.
- Microsoft Managed vs. Manual:
- Microsoft Managed: The system automatically decides whether to nudge users toward the Authenticator app or passkeys. It only selects passkeys if the tenant configuration has no restrictions (i.e., allows both synced and device-bound keys).
- Manual Enablement: Admins can explicitly force a passkey campaign.
- Snooze Functionality: Admins can configure how many times a user can "snooze" the prompt and for how many days.
- Current Limitations: The registration campaign is currently "blind" to specific user profile restrictions. If a user is nudged to create a passkey but their assigned profile only allows "device-bound" keys, the setup may fail if they attempt to use a "synced" method.
- Recommendation: Target the campaign only to groups that have no restrictive AAGUID or sync policies, or provide clear internal communication to users regarding which methods are permitted.
4. Nudge Suppression Logic
The system will not prompt a user to create a passkey if it detects an existing, compatible authentication method on that specific device/browser combination. Examples of suppression include:
- Windows Hello for Business on Windows devices.
- Synced Google Password Manager passkeys on Chrome/Android.
- iCloud Keychain passkeys on iOS/macOS.
- Samsung Pass on supported devices.
5. Synthesis and Conclusion
Passkeys represent a significant leap forward in authentication security by combining cryptographic strength with physical proximity requirements. While the Registration Campaign is a powerful tool for increasing adoption, administrators must be cautious: the current implementation does not automatically align the "nudge" with specific user-group restrictions.
Key Takeaway: Organizations should audit their user base and passkey profiles before enabling broad registration campaigns. When implemented correctly, passkeys—especially when combined with Conditional Access (e.g., requiring a healthy, Intune-managed device)—provide a robust defense against modern identity-based attacks.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Is there a Chinese cyber threat to EU solar energy? | DW News
DW News

i f**k'd up
Meet Kevin

3 AI Stocks Insiders Are Selling. Most Aren't Ready for What Happens Next.
MarketBeat

From Know Your Customer to Know Your Reality in the Age of AI | Mr. Smarak Swain | TEDxKPRCAS
TEDx Talks

OpenAI's New GPT Cyber Beats Mythos 5
AI Revolution

Top Stocks I'm Buying For Huge Growth In July 2026
Ticker Symbol: YOU

Michael Saylor's Bitcoin buying machine just sputtered
Yahoo Finance