Mandatory passkeys guidance

Jack Halpern 20 Reputation points
2026-07-23T17:42:57.54+00:00

I have been told that my ID uses an external sign-in. A recent email I received said passkeys will be required. I need some guidance and assistance. I have had authentication issues in the past (unable to access resources) which makes me very nervous and gunshy.I log in with an @outlook.com email address but within Azure my principal name contains the characters #EXT# which I'm told means the authentication is external.

A few other questions: Does this affect Azure only? Or will Office 365, Visual Studio, GitHub, etc. also be affected?

Thanks

Jack

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. Jerald Felix 18,200 Reputation points Volunteer Moderator
    2026-07-31T02:02:15.16+00:00

    Hello Jack Halpern,

    Greetings! Thanks for raising this question in Q&A forum.

    Based on your description, the key point is that the account contains #EXT#, which indicates you are using a guest/external identity in another organization's tenant. In this scenario, sign-in methods such as passkeys are usually managed by your home identity provider (the account you use to authenticate), not by the resource tenant where the guest account exists.

    1. Identify which account is actually performing authentication. If you sign in using your personal @outlook.com account, check the security settings for that Microsoft account first.
    2. Review the passkey announcement carefully to determine whether it applies to your Microsoft personal account, your organization account, or a specific tenant where you access resources.
    3. If you access Azure, Microsoft 365, Visual Studio, GitHub, or other services through the same Microsoft account, any authentication method changes implemented on that account may affect all services that rely on it for sign-in.
    4. Consider registering a passkey before enforcement begins and keep at least one alternate sign-in method (such as authenticator app, recovery phone, or recovery email) configured to avoid lockout.
    5. If the email came from an organization where you are a guest user, contact that tenant's administrator and ask whether the passkey requirement applies to guest accounts and whether any exceptions or migration guidance are available.

    If you are unsure whether the notification came from Microsoft personal accounts or from a specific organization tenant, the next action is with the tenant administrator or support contact who sent the communication. They can confirm the exact scope of the passkey requirement and whether guest accounts are included.

    If this answer helps you kindly accept the answer which will help others who have similar questions

    Best Regards,

    Jerald Felix.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.