Microsoft is auto-enabling passkeys in March 2026.
No opt-in required.
If you don’t configure it first… your tenant gets the defaults.
I sat down with Microsofty Security MVPs
@DanielatOCN and
@WelkasWorld.
We break down:
1️⃣ Passkey Profiles Are Becoming the Default
→ Starting March 2026:
→ Passkey profiles will be auto-enabled
→ Tenants that haven’t configured profiles will be migrated
→ Registration campaigns will shift from Authenticator-first to passkey-first
2️⃣ Source of Authority Conversion Is Finally GA
For years, admins used messy delete-and-restore hacks to convert synced users to cloud-only.
→ Now it’s officially supported.
→ You can convert individual users from on-premises authority to cloud-managed — without breaking hybrid entirely.
Why this matters:
→ Easier M&A transitions
→ Full access to Entra ID Governance features
→ Cleaner lifecycle management
→ Reduced dependency on legacy infrastructure
---------------------
Sponsored by: Action1
on.action1.com/entrachat
Action1 is a cloud-native patch management platform for Windows, macOS, Linux, and third-party apps — all from one place, no VPN needed. Curious how easy it is to start? You can use it on your first 200 endpoints, for free, forever, with no functional limits. It’s not a disguised free trial. No credit card required, no hidden limits, no tricks.
Visit
on.action1.com/entrachat and get started today.
---------------------
3️⃣ App Registration Deactivation (A Quietly Powerful Feature)
→ Microsoft added the ability to deactivate app registrations.
→ Instead of deleting an app (and losing configuration), you can now:
→ Immediately stop token issuance
→ Preserve metadata and permissions
→ Investigate safely
→ For incident response scenarios — especially in multi-tenant or MSP environments — this is a big step forward.
4️⃣ Conditional Access Behavior Changes
→ There’s also a change impacting tenants with Conditional Access policies targeting “All resources” but excluding certain apps.
→ Previously, certain minimal-scope apps could bypass enforcement under specific conditions.
→ That loophole is closing.
5️⃣ Sync Security Hardening (Hard Match Protection)
→ Microsoft is adding additional validation to protect against malicious hard matching scenarios in hybrid environments.
→ This reduces the risk of identity takeover via manipulated on-prem objects.
→ It’s automatic — but important to understand if you manage hybrid identity or MSP transitions.
Watch the full episode for the deep technical breakdown and real-world implications.
entra.news/p/microsoft-is-au…