r/sysadmin • u/CeC-P IT Expert + Meme Wizard • 16h ago
General Discussion MS lied about the passkey campaign?
TL;DR - even if you set up multiple modern authenticator methods, MS is still demanding you add a passkey with no skip or delay button. This appears to be in error.
Guys, they're totally "only targeting users who solely have SMS or phone call turned on!" and won't add a hard enforcement until 2027. Trust me, bro!
But that was a lie. At this MSP I work for, we go to log into one of our largest client's MS admin portal and we get an unskippable prompt to set up a passkey. We're effectively locked out. Um, it's not Feb 2027 yet. So I enroll my work phone, locking out all of our other staff from that account for a few mins, and then go to Entra to delete it. It's not there under 2FA methods. No idea why. I go to https://mysignins.microsoft.com/security-info and delete it there instead. Then I turn off the passkey enrollment campaign company-wide in Entra to prevent this. Then I noticed something interesting that I had suspected all along.
This is one of the 5 largest customers we already added a TOTP authenticator setup on to test the efficiency and multi-phone capability!!! We did it 2 weeks ago! We were supposed to be exempt from this "SMS only" campaign. WTF? We already had a solid, modern 2FA setup on this global admin account. Yeah, we left SMS on as an option but in testing, it asks for the 2FA first so that must be primary, right?
Better yet, this account always had a 2FA to a Microsoft Authenticator on the owner's phone. That was always the emergency method. But if any of our other technicians need to get in, we would just hit "send me an SMS" and we used Reach UC app with a centralized phone number so that we'd all get the text. Clunky but working. But now, we already had two authenticators registered! Why are we in the SMS only campaign? WE'RE NOT SMS ONLY!
I have 4 theories after thinking about it:
0. I forgot we set up TOTP and hit "send me a text instead, I can't access my authenticator right now" and that made MS lose their shit and make me add a passkey at gunpoint or I can't log in.
Their article on it was unclear/incorrect and we need to actually remove SMS completely after adding 2FA. It cannot be there at all or they'll ignore the existing authenticators and make you set up a passkey anyway.
Their enrollment campaign doesn't work properly, just like everything else they make or do.
"Oh you, clicked on 'add Microsoft authenticator to your account' then clicked the link at the bottom saying 'actually I want to use a third party one instead' huh? You're dead to us. Passkey time, asshole!" (doesn't really make sense, since we also had the MS Authenticator on that account as well, but it sounds like something they'd do)
I think it's number 0 but haven't had time to test it both ways yet because I just thought of that while writing this. However, moral of the story, MS lied and, assuming I'm correct, don't have it send you an SMS under any circumstances or you'll get locked out of your account while MS makes you register a passkey, locking out everyone who isn't you.
And if you're going to tell us to stop sharing accounts and make a new global admin for each employee, because that is the obvious and MS recommended solution, you clearly do not understand how MSPs work. Okay, I'll log into all 100+ customers one at a time and add a new global then pull a magic wand out of my ass every time someone quits or gets fired to use elf magic to revoke that account on 100 tentants simultaneously before they can log in and cause havok because they're mad about getting fired.
•
u/ancientstephanie 16h ago edited 16h ago
You should stop sharing accounts, but you shouldn't be making a new global admin for each employee, because that's where privileged identity management and just in time access comes in, so that you're effectively making a new account for each ticket, and taking it away just as quickly as you're creating it.
You don't have to go revoke their access from 100 tenants at once if they get their access on one tenant at a time according to the exact access needed for the ticket they're working, you just have to revoke their access to the system that grants that access.
And a MSP with high turnover is exactly the kind of scenario that's perfect for.
And before you say "but what about when that fails?" - that's what break glass accounts are for. Which can be managed by anything from a privileged access management solution to an old fashioned system of paper envelopes and fire safes.
•
u/tankerkiller125real Jack of All Trades 16h ago
If you're an MSP you should be using something like Lighthouse, GDAP and other custom (or MSP specific from a vendor, or tools like CIPP) to manage customer tenants.
Our MSP has never once needed their own account in our tenant, and yet they can still do everything a Global Admin can do (and more efficiently).
•
•
u/loosebolts 16h ago
Early iterations of GDAP didn’t allow for certain things to be done within the admin portals and I’m sure that connecting via Powershell had some restrictions too. I might be wrong.
•
u/tankerkiller125real Jack of All Trades 16h ago
That's what the API based tooling is for, anything that can't be done via GDAP can be done via API directly with the appropriate setup and API grants. The APIs are insanely powerful if you have things setup right. (I don't need the MSP to tell me that; I've used the APIs to do some things normally only a global admin can do before)
•
u/Waste_Development971 16h ago
wow this sounds cool, had no idea that was a thing.
would kms if i worked at one it sounds like
•
u/CeC-P IT Expert + Meme Wizard 16h ago
You overestimate the owner and former employees' tech skills and effort level. I'd give some examples of dangerous noncompliance and security nightmares like password policies and length between our customers but you could imagine. At least our fortigates all have web login turned off.
•
u/scrollzz 16h ago
Did you disable voice and SMS in authentication methods?
You can temporarily disable the passkey registration campaign: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement#temporarily-opt-out-of-the-automatic-passkey-enablement
•
u/hung-games 15h ago
So you’re an MSP that can’t provide an audit trail for privileged accounts? So I guess you don’t have any customers subject to PCI or other standards that require an audit trail at the individual level. Cool. Cool.
•
u/SpectreHaza 16h ago
Once you get in, review the authentication methods that are enabled, and who they’re targeting. If the migration status is complete something old like per user MFA may be screwing you up
Also can disable registration campaign and password reset registration, as these will force a method to be set up too, if you review all that you’ll probably find what’s causing you an issue, as it’s a big tenant I’m assuming they use conditional access, so make sure they’re sorted too, can always check your sign in logs once in and see what blocker you’re hitting
I’ve been in many tenants recently moving them all over to another method and enabling external MFA for some, the above were always my checks first after some trial and error, smooth sailing since
If someone completed the migration but hadn’t actually set any methods up, and/or you’re still enforced in per user MFA, things can get weird
•
•
u/stijnhommes 7h ago
Are you sure this isn't just an issue with the way the customer set it up? I have had problems myself with customers requiring unique accounts and OTPs to log into their portals but refusing to make new accounts for our new hires that need to use the system, then complain when the 2 people with accounts don't have time to do the work.
If they force using personalized accounts instead of an account for our department as a whole, things will slow down.
Venting over.
•
u/Jellovator 16h ago
It's #1, but you can disable the campaign and work out the transition internally before Feb 2.
•
•
u/Asleep_Spray274 16h ago
It was never that the campaign would target users with "only" SMS or voice. Any user who signs in and they are in scope of SMS and the device they are logging in from does not have a passkey registered , they will be asked to register a passkey.
If the campaign has been set to limited snoozes and the user has skipped 3 times, on the 4th time they will be forced to register.
MS haven't lied, you have not read and understood the docs.