All news
Security
2 October 2026

Microsoft Entra ID adds passkey support for guest users

Microsoft is extending passkey authentication to B2B guest users, allowing external partners to use secure hardware or device-based credentials. This update will be enabled by default for organisations currently using passkeys for internal staff.

What this means for your business

Businesses that collaborate with external guests in Microsoft 365 can now require those guests to use passkeys for stronger security. Administrators should review their authentication method policies to ensure guest access remains functional while meeting security standards.

Update to Guest Authentication

Microsoft has announced that passkey support is being extended to B2B (business-to-business) users within Microsoft Entra ID. This includes both internal guest accounts and external partners who access your organisation's data or applications.

Previously, passkeys—a method of signing in using a physical security key, facial recognition, or a fingerprint—were restricted to members of their own 'home' tenant. Under the new update, a guest user can register a passkey directly within your business environment (the resource tenant) to satisfy your specific multifactor authentication (MFA) requirements.

Why Passkeys Matter

A passkey is a digital credential that replaces traditional passwords. They are designed to be phishing-resistant because they rely on public-key cryptography and local device verification. For a business owner, this means that even if an external partner’s password is stolen, a third party cannot easily access your shared files without the physical device or biometric data linked to the passkey.

Implementation and Default Settings

This change is scheduled to be enabled by default. If your organisation already has an Authentication Methods policy that includes passkeys, your guest users will automatically fall into this scope when the update rolls out.

Guests will be able to register their passkeys through the 'My Security Info' page or when prompted during a sign-in attempt. Microsoft has not provided a specific date for General Availability in this notice, but typically these rollouts occur over several weeks across different regions.

Recommended Actions

For most UK small businesses, no immediate technical intervention is required. However, it is advisable to:

  1. Review who is currently permitted to use passkeys in your Entra ID settings.
  2. Check your Conditional Access policies—these are the rules that dictate when a user must provide MFA—to see if you wish to mandate passkeys for external guests handling sensitive data.
  3. Update any internal documentation provided to regular contractors or partners regarding how they sign in to your systems.

If you do not wish for guests to use this method, you will need to adjust your user scoping within the Entra ID portal before the rollout is complete.

Worried this could affect you?

Cyber Essentials is the quickest way for a small business to close the gaps attackers use most.

See Cyber Essentials

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.