The Microsoft Entra passkey policy just got a major upgrade, and admins have only days to prepare for the enforcement wave that lands July 13, 2026. In its June 2026 update, Microsoft tripled the number of passkey profiles allowed per tenant, expanded the authentication methods policy size, and rolled sensitivity labels into Entra security groups. Meanwhile, Conditional Access policies that target the “Register security information” action begin applying to Windows Hello for Business and macOS Platform SSO enrollments on July 6. For Microsoft 365 admins, that is a very short runway. This guide breaks down what changed, why it matters, and the concrete steps to take before enforcement completes.

What's New in Microsoft Entra June 2026 header banner covering the Microsoft Entra passkey policy updates
Source: Microsoft Community Hub — What’s New in Microsoft Entra: June 2026

What Changed in the Microsoft Entra Passkey Policy

Microsoft raised the maximum number of passkey profiles per tenant from three to ten. In addition, the authentication methods policy now carries a dedicated 20 KB allocation for passkey settings. Previously, passkey configuration competed with other authentication methods for a shared policy budget, which forced admins to make trade-offs.

Now, however, teams can define distinct profiles for different scenarios without hitting size caps. For example, one profile could target shared frontline devices, another could serve executive-tier laptops, and a third could cover contractor devices. As a result, large tenants can finally align passkey rules with real organizational structure instead of forcing everyone into a single policy.

The July 6 Milestone Every MS365 Admin Must Note

Starting July 6, 2026, Conditional Access policies scoped to the “Register security information” user action begin applying during Windows Hello for Business and macOS Platform SSO credential registration. Furthermore, enforcement completes by July 13, 2026. In other words, users setting up a passwordless credential will need to satisfy the Grant controls in your policy — authentication strength, trusted location, or a specific MFA method — before they can complete enrollment.

Microsoft has been clear that if you have no policy targeting this action, nothing changes for you. However, MFA is still required by default to register passwordless credentials in every scenario. Consequently, tenants that already lean on strong Conditional Access will suddenly see those rules apply to Windows Hello for Business and macOS SSO flows they may not have accounted for.

Why Microsoft Entra Passkey Profiles Matter for Enterprise Rollouts

Passkey profiles let admins scope which FIDO2 authenticators, attestation requirements, and AAGUIDs are allowed for a given group of users. Moreover, they enable the phishing-resistant credentials that Microsoft has been steering the industry toward for years. Ten profiles per tenant may sound modest, but for global enterprises, the additional headroom unlocks real design choices.

Consider a typical multinational rollout. Regional privacy rules may require different authenticator brands per country. Additionally, security-sensitive divisions often demand hardware attestation, while general knowledge workers can safely use synced passkeys. With more profile slots and a bigger policy budget, admins can encode these differences without compromise.

  • Frontline device profile — shared kiosk passkeys with tighter attestation
  • Executive profile — hardware-bound keys and stricter AAGUID allowlist
  • Developer profile — allowlist for platform-provided passkeys on macOS and Windows
  • Contractor profile — synced passkeys with time-bound access reviews
  • Guest profile — restricted keys tied to Microsoft Entra B2B collaboration flows

Sensitivity Labels Land on Entra Security Groups

The June update also brought Microsoft Purview sensitivity labels to Entra cloud security groups in public preview. Previously, sensitivity labels only governed Microsoft 365 groups. However, now the same label taxonomy already used for Teams, SharePoint sites, and mailboxes can also drive security group behavior — including guest access controls and privacy settings.

This matters because security groups underpin so much of the modern access stack. For example, license assignment, Conditional Access targeting, and role-based access frequently start with a security group. As a result, applying a single label to a security group can now propagate guardrails that used to require multiple tools and hand-off scripts.

Admins can manage these labels in the Microsoft Purview portal and apply them through the Entra admin center, the Azure portal, or Microsoft Graph. Therefore, existing automation pipelines can adopt the feature without a full rewrite.

Microsoft Entra ID security updates announcement graphic covering Conditional Access changes and passkey policy expansion
Source: Microsoft Community Hub — Microsoft Entra ID security updates

How the Microsoft Entra Passkey Push Fits the Bigger Passwordless Story

These changes are not one-offs. Instead, they are the latest step in a multi-year Entra passwordless campaign. Earlier in 2026, Microsoft auto-enabled passkey profiles for tenants that had taken no action. Then, in April, registration campaigns gained native support for prompting users to enroll passkeys during sign-in. Meanwhile, Entra passkeys on Windows reached general availability in late May.

Microsoft has cited some persuasive numbers along the way. According to the company, synced passkeys are up to 14 times faster than passwords paired with traditional MFA. Additionally, roughly 99 percent of consumers successfully complete passkey registration on the first try. For IT teams still buried in password-reset tickets, those figures are hard to ignore.

Registration Campaigns Now Nudge Users Toward Passkeys

Registration campaigns are the built-in mechanism that prompts users to enroll a stronger method after a successful sign-in. Before this year, they largely nudged users toward Microsoft Authenticator. Now, however, they can steer users directly to passkeys. Consequently, admins get a low-friction way to onboard thousands of users without a heavy training program.

Combining registration campaigns with the newly expanded passkey policy creates a compelling rollout pattern. First, define profiles that match your device fleet. Next, use a targeted registration campaign to walk employees through enrollment. Finally, lock the door behind them with Conditional Access that requires phishing-resistant authentication.

Prepping Conditional Access for the Enforcement Window

The July 6 to July 13 window applies specifically to policies scoped to the “Register security information” user action. Therefore, the first move for every tenant is a policy audit. Open the Conditional Access blade, filter by that user action, and inventory every policy that touches it.

Next, switch each policy to report-only mode and review the sign-in logs. Look for Windows Hello for Business and macOS Platform SSO registration events. If users are hitting blocks — for example, because your policy requires a trusted location that laptop-based staff cannot meet — adjust before hard enforcement kicks in. Otherwise, help desk queues will fill up fast.

Also consider communication. Users who have never seen a Conditional Access prompt during Windows Hello setup may treat the challenge as a system error. Consequently, a short internal FAQ can head off dozens of tickets.

A 7-Day Microsoft Entra Passkey Readiness Checklist

With enforcement completing by July 13, admins have roughly one work week. Here is a compact plan that any lean team can execute.

  1. Inventory every Conditional Access policy scoped to “Register security information.”
  2. Move affected policies to report-only mode and verify sign-in logs for Windows Hello and macOS SSO events.
  3. Confirm your Microsoft Entra passkey profiles align to the new 10-per-tenant, 20 KB limits.
  4. Enable a registration campaign that prompts eligible users to enroll passkeys.
  5. Pilot sensitivity labels on one or two Entra security groups and validate the guest access behavior.
  6. Publish a one-page user FAQ explaining the July 6 to July 13 changes.
  7. Schedule a July 14 review to confirm no unexpected blocks appear in the sign-in logs.

What This Means for Microsoft 365 Security Strategy

Zoom out and a clear pattern emerges. Microsoft is aligning Entra, Purview, and Conditional Access on a single passwordless foundation. Meanwhile, Security Copilot is arriving across Defender, Entra, Intune, and Purview for E5 customers, which further tightens the loop between identity signals and security response. As a result, tenants that stay on legacy password-plus-SMS flows will fall further behind on both user experience and threat resilience.

For MS365 admins, the takeaway is simple. Treat July 13 as the deadline for cleaning up “Register security information” policies. In parallel, use the newly expanded passkey policy to design a proper rollout — one that finally retires the passwords haunting your directory.

Bottom Line for Microsoft 365 Admins

The updated Microsoft Entra passkey policy delivers real breathing room for enterprise rollouts. However, the July 6 Conditional Access enforcement is the story that could bite admins who wait. Therefore, act now: audit your policies, test in report-only mode, expand your passkey profiles, and pilot the new sensitivity labels on security groups. In addition, brief your users so they know why the sign-in flow just changed.

For deeper coverage of Microsoft 365 security, Copilot governance, and passwordless rollouts, explore more guides on SharePoint Monkey. We track the changes that MS365 admins actually have to act on — so you can spend less time reading release notes and more time shipping wins.

Sources


Discover more from SharePoint Monkey

Subscribe to get the latest posts sent to your email.