The roadmap lists the feature as "In development," with general availability planned for October 2026 in Worldwide (Standard Multi-Tenant) and GCC. The rollout is staged, though, and the October date doesn't apply to everyone.
What problem this solves
Passkeys are already supported for member users in their home tenant. Until now, B2B users could not use a resource tenant passkey when that tenant required MFA and did not trust the home tenant's MFA.
Some background on B2B sign-in helps here. Ourcloudnetwork explains that a B2B collaboration user normally authenticates in their home tenant before the resource tenant applies its own Conditional Access policies. Inbound cross-tenant access settings can trust an MFA claim from another Microsoft Entra tenant. Without that trust, the guest must complete an MFA challenge in the resource tenant. In that case, guests who must complete MFA there have instead depended on methods such as Authenticator push, SMS or software OATH.
This was a documented restriction. Microsoft's current "How to enable passkeys (FIDO2)" page on Microsoft Learn still lists a known issue saying passkey registration isn't supported for internal or external guest users, including B2B collaboration users in the resource tenant. That page describes the situation before the rollout. MC1459133 is what changes it.
One point to be clear on: the new passkey belongs to the resource tenant. The user's home-tenant passkey is not transferred or shared. The new credential is registered in the resource tenant, where its administrators can investigate its use or remove it when they offboard the guest. That gives resource-tenant admins visibility into the credential and a clean way to remove it when offboarding a guest.
Summary: B2B users who can't rely on trusted home-tenant MFA get a phishing-resistant option, and the resource tenant issues and manages that credential.
How guests will register
Microsoft lists three registration routes: B2B users can register a resource tenant passkey from the resource tenant's My Security Info page, during a proof-up prompt, or through a passkey registration campaign. Once registered, the passkey can satisfy the resource tenant's MFA requirements during sign-in.
Prompts won't appear for everyone automatically. According to the updated Message Center text, sign-in prompts from proof-up or registration campaigns only appear if those experiences are configured in the tenant. Users can always register directly from the resource tenant's My Security Info page.
Supported passkey types differ between the two B2B groups: Microsoft Authenticator app passkeys will be supported for internal guest users but not for external users. External users will need another passkey type. Microsoft's FIDO2 documentation describes device-bound passkeys on FIDO2 security keys and synced passkeys from providers such as Apple iCloud Keychain or Google Password Manager. The B2B announcement doesn't say exactly which types each external user will be offered, so your passkey profiles will decide that in practice.
Rollout timeline
| Population | Rollout window |
|---|---|
| General availability (Worldwide, GCC) | Early October 2026 to late February 2027 |
| Internal guest users | Early October 2026 to late October 2026 |
| External users (no Authenticator app passkeys) | Not announced yet |
The source for that table is MC1459133, which says external users (excluding Microsoft Authenticator app passkeys): Rollout timing will be communicated in a future Message center post update. If your tenant mostly hosts outside collaborators, treat "October 2026" as the start of internal-guest support, not the date everything is done.
On by default: what admins should check
The roadmap says the change is on by default and needs no action to enable. B2B users already in scope for passkeys in your Authentication methods policy are included automatically. As ourcloudnetwork puts it, any B2B user already included in your Passkey (FIDO2) authentication method policy will become eligible, so the scope of that policy decides who gets access.
If your passkey policy targets "All users," guests are probably in scope already. Microsoft's pre-rollout checklist from the Message Center post:
- Review the Authentication methods policy. Confirm which users, including guests and external users, are in scope for passkeys. Exclude them if you don't want this behaviour.
- Review the passkey registration campaign. Make sure its user scope includes the people you intend to prompt.
- Review Conditional Access. Microsoft advises admins to confirm that MFA and authentication strength requirements will apply as intended for B2B users when resource tenant passkeys become available.
- Check user scoping across all authentication policies. Group and user-type targeting should match how you want to treat guests and external users.
- Tell the help desk. Eligible B2B users may start seeing registration prompts once the rollout reaches them.
Microsoft's FIDO2 documentation adds a detail that matters here. If a user is in an excluded group in the Passkey (FIDO2) policy, they're blocked from passkey registration and sign-in entirely, and the exclusion overrides any included group. The same page notes that users must have completed MFA within the past five minutes before they can register a passkey.
Summary: Nothing needs to be switched on, but your existing policy scope now decides who gets the feature, so check it before the rollout reaches your tenant.
How this interacts with the SMS and voice retirement
The September 14 update to MC1459133 added an important warning: This rollout intersects with the previously announced retirement of SMS and voice authentication. As described in Message Center posts MC1426371 and MC1434201, any user enabled for SMS or voice in the Authentication methods policy or legacy MFA policies will be automatically enabled for all passkey types. This will include eligible B2B users when B2B passkey support becomes available.
In practice, excluding a B2B user from the passkey policy won't stop automatic enablement if that user is still enabled for SMS or voice. Microsoft says to move those users off SMS and voice in every applicable policy, including legacy MFA settings, if you don't want them auto-enabled for passkeys.
The dates in Microsoft Learn's SMS and voice retirement guidance show why this matters for guests:
- September 1, 2026: Users enabled for SMS or voice are auto-enabled for passkeys and prompted to register after MFA sign-in.
- February 1, 2027: Microsoft-provided SMS and voice is retired for all users except Global Administrators and external users. Internal guests are included in this February date.
- July 1, 2027: Retirement applies to Global Administrators and external users.
After the applicable date, users whose only MFA method is SMS or voice get a blocking prompt to register a passkey, and there's no opt-out from that enforcement. The same guidance describes a temporary Microsoft Graph beta opt-out (optOutSettings.passkeyDynamicMigration: true) that delays automatic enablement between September 1, 2026 and February 1, 2027. That control belongs to the SMS and voice migration. Microsoft hasn't documented it as a switch for the B2B passkey feature specifically.
For internal guests, the passkey rollout (October 2026) comes only a few months before SMS and voice retirement (February 2027). For many tenants, B2B passkeys will be the practical way to keep guests signing in once SMS stops working.
Analysis: good security, but expect some support load
On security, this is clearly a positive change. Organizations enforcing phishing-resistant MFA for their own users couldn't extend the same standard to external collaborators. Guest accounts are a known way into a tenant, so leaving them on SMS codes didn't make much sense.
There are trade-offs, though.
- More credentials for users to manage. A consultant working with five client tenants may end up with five resource-tenant passkeys plus a home-tenant one. Synced passkey providers handle that better than people do, but labelling and recovery can still get confusing.
- Recovery falls to you. A guest who loses a resource-tenant passkey will call your help desk, not their own IT team.
- Cross-tenant trust is still the cleaner option where it fits. If you trust a partner's MFA claims through inbound cross-tenant access settings, their users never need a passkey in your tenant at all. Resource-tenant passkeys are for situations where you don't trust the partner's MFA, or can't.
- External users have to wait. Without an announced date or Authenticator app support, organisations with many outside collaborators still have to plan for the uncertainty.
That's an opinion based on general identity-management experience, not a Microsoft statement. Either way, a quick audit of policy scope before October is worth the effort.
Quick checklist for October
- Find your guests: run Microsoft's SMS/voice user discovery and filter for internal guests and external users.
- Open Entra ID > Authentication methods > Policies > Passkey (FIDO2) and confirm who's in scope and which passkey profiles apply.
- Check SMS/voice assignments in the Authentication methods policy and legacy MFA settings.
- Make sure Conditional Access authentication strengths for guests accept passkeys where you want them to.
- Give the help desk a short guide to registering a passkey through My Security Info.
Microsoft is pushing phishing-resistant sign-in to every account type, and guest accounts are now included. Internal guest support is due to roll out through October. External users will follow at a date Microsoft hasn't announced yet.
References
- Microsoft Entra ID: Passkey support for B2B users Microsoft 365 Roadmap · 2026-10-01T23:00:07.038613Z
- Microsoft Entra brings passkeys to B2B guest users ourcloudnetwork.com
- Passkeys by default and retirement of Microsoft-provided SMS and voice authentication - Microsoft Entra ID | Microsoft Learn learn.microsoft.com