Microsoft is bringing Passkeys to B2B guest users in Microsoft Entra ID and the timing is right. 😁

Until now, B2B guests couldn’t register a Passkey directly in the resource tenant.

If you wanted to require phishing-resistant authentication for guests, one option was to configure Cross-Tenant Access Settings and trust MFA from the user’s home tenant. This allowed a guest to authenticate with a Passkey or another strong authentication method in their own tenant and have that MFA claim trusted by the resource tenant.

That model still makes sense for organizations you trust, but it also means part of your security depends on another tenant’s authentication configuration.

With the change announced in MC1459133, B2B guests will be able to register Passkeys themselves.

And this becomes even more relevant when looking at Microsoft’s broader authentication changes.

Starting February 1, 2027, Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID. Microsoft is clearly pushing organizations away from phishable authentication methods and toward phishing-resistant methods such as Passkeys.

Microsoft also specifically states that B2B users and internal guest users are included in the scope of the SMS and voice retirement.

Allowing B2B guests to register Passkeys is therefore not just a nice new feature, it fills an important gap before SMS and voice are retired.

Some of the security benefits are:

  • Phishing-resistant authentication for external users
  • Less dependency on MFA configuration in another tenant
  • Better control over authentication for sensitive applications
  • A stronger alternative to SMS, voice and other phishable MFA methods

There is another side to it though.

External users may end up with Passkeys registered across several organizations, which makes credential lifecycle, lost devices, access reviews and guest offboarding even more important.

And this doesn’t mean every type of external identity suddenly gets a Passkey. Microsoft’s current guidance specifically mentions B2B users and internal guest users. B2B Direct Connect and Microsoft Entra External ID customer identities are different identity models.

For me, the interesting part of MC1459133 is that organizations now get another choice:

Trust phishing-resistant authentication from the guest’s home tenant or manage strong authentication directly for the guest in your own tenant.

Reference: MC1459133

Microsoft Entra Passkeys are coming to B2B guests