Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If Microsoft 365 users are seeing passkey setup prompts, first determine whether they come from Microsoft Entra’s registration campaign or from a separate sign-in requirement. An administrator can disable the campaign or configure how often users may snooze it. Disabling the campaign will not remove an independent requirement, such as a Conditional Access policy that requires phishing-resistant multifactor authentication (MFA).

Identify what is prompting users

Microsoft Entra can prompt users through a registration campaign that encourages them to set up a passkey or Microsoft Authenticator. But a prompt may also appear because a policy requires a passkey or phishing-resistant MFA in a particular sign-in scenario. Check which applies before changing tenant-wide settings. Microsoft describes both causes in its passkey FAQs.

A registration campaign controls the nudge and its snooze behavior. Authentication-method policies and Conditional Access authentication strengths govern whether users can register or use particular methods to meet sign-in requirements. These are separate controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disable the registration campaign

  1. In the Microsoft Entra admin center, go to Entra ID > Authentication methods > Registration campaign.
  2. Set State to Disabled.
  3. Save the change and check whether the prompt stops for affected users.

This turns off the registration campaign; it does not cancel a separate authentication or Conditional Access requirement. Microsoft’s instructions for campaign states and configuration are in Run a registration campaign to set up a passkey or Microsoft Authenticator.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Keep the campaign but let users snooze it

If you want users to retain the setup reminder but need to give them time, set the campaign to Enabled and configure its audience and snooze settings. Microsoft documents a snooze interval of 0 to 14 days. With Limited number of snoozes enabled, users can snooze up to three times before registration is required; with it disabled, snoozes are unlimited. After the configured interval, a user is prompted again at a later sign-in after MFA.

In the campaign settings, review the target method, included and excluded users or groups, Days allowed to snooze, and Limited number of snoozes. These settings apply to an enabled, administrator-configured campaign. Snoozing delays the campaign prompt; it does not exempt a user from a separate authentication policy.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Understand Microsoft-managed campaign settings

Microsoft managed is different from an administrator-configured Enabled campaign: Microsoft selects the campaign settings based on tenant method configuration, and those defaults can change. Microsoft documents a transition in managed defaults toward passkeys, one day between prompts, unlimited snoozes, and broader targeting of MFA-capable users, subject to passkey-profile eligibility and rollout. Do not assume every tenant has the same settings; inspect the live campaign configuration. See Microsoft’s guidance on protecting authentication methods in Microsoft Entra ID.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If prompts continue after you disable the campaign

Check sign-in and Conditional Access requirements

Review the policies that apply to the affected users and sign-in scenarios. A Conditional Access authentication strength can require phishing-resistant MFA, which may lead users to register an eligible method. Authentication strengths control which methods can satisfy a requirement; turning off a registration campaign does not change them. Microsoft explains these controls in Manage authentication methods.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Review passkey registration and profile settings

Inspect the Passkey (FIDO2) authentication-method policy and any passkey profiles. Microsoft’s passkey setup guidance says the global policy’s Allow self-service setup setting controls whether users can register passkeys through Security info. Changing a profile is not merely a way to hide a prompt: disabling a passkey type can prevent targeted users from signing in with an already-registered passkey of that type. This warning also appears in Microsoft’s guidance on FIDO2 security key sign-in to Windows.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What happened to the announced SMS and voice transition?

Microsoft’s article on passkeys by default and retirement of Microsoft-provided SMS and voice authentication described September 1, 2026, as a milestone for automatically enabling passkey registration campaigns for SMS- and voice-enabled users. It also described an opt-out, requiring the Microsoft Graph permission Policy.ReadWrite.AuthenticationMethod, to delay enablement while an organization completed transition activities.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

That announced date has passed. It is not proof that a particular tenant’s settings changed on that date, nor does the announcement establish that every tenant can still use the opt-out. Check the current tenant configuration and Microsoft’s current guidance before relying on a delay. Treat this transition separately from the campaign’s ordinary snooze controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.