decoded365
← All changes
NewMicrosoft Entra · Microsoft Entra ID

Microsoft Entra ID: Passkey support for B2B users

B2B users (internal guests and external users) can now register and use passkeys in resource tenants to satisfy MFA requirements. The feature is enabled by default for users already in scope; admins should review authentication method policies and Conditional Access settings if they want to adjust B2B passkey eligibility before rollout.

Microsoft's description

B2B users, including internal guest users and external users, will be able to register and sign in with passkeys issued by a resource tenant to meet that tenant's multifactor authentication (MFA) requirements. Today, passkeys are supported for member users in their home tenant. With this update, B2B users can register a resource tenant passkey from the resource tenant's My Security Info page, or in-line during a proof-up prompt or passkey registration campaign, and then use it to satisfy the resource tenant's MFA requirements. This change is on by default. B2B users already in scope for passkeys in your Authentication methods policy will be enabled automatically. No action is required to turn it on. If you want to review or adjust who's affected, update your Authentication methods policy, passkey registration campaign, Conditional Access policies, and user scoping before rollout.

View on Microsoft roadmap →