Managing external identities to enable secure access for partners, customers, and other non-employees
Hello Jack Halpern,
Greetings! Thanks for raising this question in Q&A forum.
Based on your description, the key point is that the account contains #EXT#, which indicates you are using a guest/external identity in another organization's tenant. In this scenario, sign-in methods such as passkeys are usually managed by your home identity provider (the account you use to authenticate), not by the resource tenant where the guest account exists.
- Identify which account is actually performing authentication. If you sign in using your personal
@outlook.comaccount, check the security settings for that Microsoft account first. - Review the passkey announcement carefully to determine whether it applies to your Microsoft personal account, your organization account, or a specific tenant where you access resources.
- If you access Azure, Microsoft 365, Visual Studio, GitHub, or other services through the same Microsoft account, any authentication method changes implemented on that account may affect all services that rely on it for sign-in.
- Consider registering a passkey before enforcement begins and keep at least one alternate sign-in method (such as authenticator app, recovery phone, or recovery email) configured to avoid lockout.
- If the email came from an organization where you are a guest user, contact that tenant's administrator and ask whether the passkey requirement applies to guest accounts and whether any exceptions or migration guidance are available.
If you are unsure whether the notification came from Microsoft personal accounts or from a specific organization tenant, the next action is with the tenant administrator or support contact who sent the communication. They can confirm the exact scope of the passkey requirement and whether guest accounts are included.
If this answer helps you kindly accept the answer which will help others who have similar questions
Best Regards,
Jerald Felix.