October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
FIDO2

Passkeys in Microsoft Entra ID: What’s Generally Available and How to Roll Them Out

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Entra ID’s passkey capabilities have expanded, but “available” does not mean every passkey feature is generally available or enabled for every user. As of August 18, 2026, passkey profiles, synced passkeys, and passkey registration campaigns are generally available; Entra passkeys on Windows remain in public preview. Administrators can configure who may register which credentials, but they still need to plan for Conditional Access, user-device compatibility, and account recovery.

What a Microsoft Entra passkey is

Entra passkeys use FIDO2 and WebAuthn public-key cryptography. When a user registers a passkey, the authenticator or passkey provider protects the private key; Entra stores and later verifies the corresponding public-key credential. Sign-in uses the authenticator’s local unlock step—such as a fingerprint, face scan, PIN, or security-key gesture—instead of asking the user to type a password for that authentication.

Passkeys are designed to resist phishing, but the label covers credentials with different storage, portability, policy, and recovery characteristics. A synced passkey is held by a provider and may be available on several devices. A device-bound passkey remains tied to one device or authenticator. A physical FIDO2 security key is a hardware authenticator; it is not operationally interchangeable with a credential synchronized through a personal cloud account.

Windows Hello for Business and macOS Platform SSO also support passwordless identity experiences, but they are not synonyms for every Entra passkey flow. Windows Hello for Business is oriented around managed Windows identity and device sign-in. Microsoft documents Secure Enclave-backed credentials and device-bound passkey capabilities in its macOS Platform SSO announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Which Entra passkey features are available?

Microsoft’s release information through June 2026 distinguishes generally available management and synced-credential features from the Windows-specific preview. Availability can change, so check the linked release notes for the latest tenant and cloud status.

Feature Status and what it means
Passkey profiles Generally available. Administrators can apply different passkey policies to users or groups.
Synced passkeys Generally available. Credentials can be stored with a supported passkey provider and made available across devices.
Passkeys in registration campaigns Generally available. Campaigns can prompt eligible users to register; a prompt does not enroll them automatically.
Entra passkeys on Windows Public preview in Microsoft’s June 2026 release information. The credential is stored in the local Windows Hello container and unlocked with Windows Hello biometrics or PIN.
FIDO2 security keys An established FIDO2 option. Their physical custody, replacement, and recovery requirements differ from provider-synced passkeys.

Microsoft’s Entra release notes document the feature status, the increase in the tenant maximum from three to 10 passkey profiles, and a dedicated 20-KB passkey policy allocation. Microsoft’s June 2026 update describes registration-campaign support and the Windows preview. Its March 2026 roundup covers synced passkeys and profiles.

How passkey profiles affect policy

A passkey profile lets an administrator target a passkey configuration to particular users or groups. Depending on the supported options, the profile can control permitted passkey types, authenticators, and attestation requirements. This is useful when administrators or other high-risk users need tighter rules than the rest of the workforce.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Microsoft documents migration of existing FIDO2 settings into a default passkey profile. Before editing a tenant’s policy, inspect that profile and confirm that its prior assignments, allowed authenticators, and attestation settings reflect the intended configuration. Do not assume a newly visible profile means the prior policy has been discarded—or that the migrated settings are exactly what the organization wants now.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Synced credentials shift part of the trust and recovery model to the provider. Decide whether personal-provider synchronization is permitted, which providers are acceptable, how provider accounts are protected, and what happens when a user loses access to one. If that model is not acceptable for a group, configure a profile around approved device-bound credentials or hardware keys where supported.

Synced and device-bound passkeys compared

Consideration Synced passkey Device-bound passkey
Portability Can be available on supported devices through its provider. Tied to one device or authenticator.
Replacement device May be easier if the user can recover the provider account and synchronized credential. Usually requires a new enrollment or a separately registered backup authenticator.
Administrative control Depends on which providers policy permits and how they manage synchronization. More directly associated with the approved device or hardware.
User convenience Often convenient across devices, subject to provider support. Depends on access to the specific device or key.
Primary recovery concern Provider account access and its recovery controls. Loss or failure of the device or key.
Governance fit May conflict with rules against personal cloud synchronization. Often a better fit where credentials must stay tied to approved hardware.
Hardware expense May use an existing supported device and provider. Built-in hardware may avoid a separate purchase; physical keys add procurement and replacement costs.

Neither category is universally safer. Choose based on the threat model, device ownership and management, regulatory obligations, and the organization’s ability to recover credentials securely.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Prerequisites to check before enabling passkeys

  • Confirm that the tenant’s authentication-method policy and administrative permissions allow the configuration you intend to make.
  • Check supported browsers, operating systems, and authenticators against Microsoft’s current passkey configuration guidance; support differs by platform and flow.
  • Decide how users will complete initial registration, including any existing MFA or Conditional Access requirements.
  • Review authentication strengths, device-compliance requirements, risk controls, and reauthentication rules before treating a passkey as sufficient for a sign-in.
  • Set a policy for personal devices and synchronized credentials, and define an exception for people who cannot or should not use a personal phone.
  • Keep an alternative authentication and recovery route available during migration, and test it before broad enrollment.
  • Review licensing for the surrounding features you plan to use. Passkey authentication is not equivalent to every Conditional Access, Identity Protection, governance, reporting, or device-management capability; consult Microsoft Entra licensing and the current Entra pricing page.

Enable passkeys in the Entra admin center

Portal labels and feature availability can change. Microsoft’s live configuration procedure is the reference for current options.

  1. Sign in to the Microsoft Entra admin center with an account that has appropriate administrative permissions.
  2. Go to Protection > Authentication methods, then open Passkey (FIDO2).
  3. Enable the authentication method and review any existing or migrated default passkey profile.
  4. Create or edit a profile. Set the permitted passkey types and any authenticator or attestation restrictions available for the tenant.
  5. Assign the profile to a limited user or group scope and save the policy.
  6. If you want Entra to prompt users, configure a registration campaign using Microsoft’s registration campaign guidance.
  7. Test enrollment and sign-in with the pilot group, review relevant registration and authentication activity, then expand the assignment in stages.

Enabling an authentication method makes it available under policy; it does not create passkeys for users. A registration campaign is a prompt, not automatic enrollment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What users see when they register and sign in

  1. The user starts from an Entra registration or security-information flow and chooses to add a passkey.
  2. The browser or operating system asks where to create or save the credential. Depending on policy and platform, choices may include a device authenticator, synced provider, Microsoft Authenticator option, or security key.
  3. The user completes the authenticator’s local verification, for example with a fingerprint, face scan, PIN, or security-key gesture.
  4. Entra registers the credential’s public key. At a later sign-in, the user selects the passkey and unlocks it locally.

Prompt wording is not uniform. A user may see options such as “Passkey,” “Security key,” “Windows Hello,” “Use another device,” or “Use a phone or tablet,” depending on the browser, operating system, and authenticator. Provide instructions for the platforms your organization actually supports rather than promising one universal screen.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Passkeys, MFA, and Conditional Access

Microsoft describes passkeys and other FIDO2 credentials as phishing-resistant authentication methods. Whether a particular passkey satisfies an Entra authentication-strength requirement depends on the configured policy and credential type; do not assume that enabling passkeys automatically replaces every MFA requirement. See Microsoft’s discussion of phishing-resistant authentication.

Passwordless sign-in does not remove other controls. Conditional Access may still require a compliant device, restrict access by location or risk, or require reauthentication. A passkey also does not by itself protect an already stolen session token, a compromised endpoint, or an unsafe account-recovery process. Device security, session controls, and appropriate token protections remain relevant.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Windows Entra passkeys: what the preview does and does not do

In Microsoft’s June 2026 release information, Entra passkeys on Windows are a public preview. The passkey is stored in the local Windows Hello container and used with Windows Hello biometrics or PIN. Microsoft says the cited Entra authentication flow does not require the device to be Microsoft Entra joined or registered.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

This preview is not a general replacement for Windows device sign-in: interactive Windows console sign-in is not supported. Check Microsoft’s June 2026 announcement and the current release notes before designing around preview behavior.

Roll out in stages

  1. Start with identity and IT administrators. Validate the policy, enrollment, sign-in, account recovery, and emergency access paths before asking a broad user population to enroll.
  2. Add a small representative pilot. Include the platforms and conditions your organization actually uses: managed and unmanaged devices, Windows, macOS, iOS, and Android where applicable, users with and without biometrics, and remote workers.
  3. Exercise lifecycle cases. Test replacement phones, lost or reset devices, multiple passkey providers, restrictive networks, and users who cannot use a personal phone.
  4. Communicate choices and exceptions. Explain that a prompt is for registration, identify approved authenticators, and give users a support route if the offered method is unsuitable.
  5. Expand only after review. Check registration and sign-in outcomes, help-desk issues, and Conditional Access failures, then widen profile assignments in manageable groups.
  6. Enforce only when ready. Do not make a passkey the sole route until recovery, replacement-device enrollment, help-desk identity verification, and emergency administrator access have been tested.

For privileged accounts, require independent recovery options and keep break-glass access separately controlled and regularly tested. A shared administrator passkey is not a safe substitute for an individual recovery design.

Recover access and troubleshoot failures

If a user loses a phone, computer, or key

  • Use a second registered passkey or security key where the user’s risk warrants it, especially for privileged accounts.
  • Require help-desk staff to verify identity before removing or replacing credentials, and document who can perform that action.
  • Remove or revoke a lost credential when appropriate. If compromise is suspected, review active sessions and token risk as well as the credential itself.
  • Keep an approved temporary authentication method for onboarding or recovery when needed, with a defined exception process.

A passkey is not a backup strategy by itself. Recovery depends on the additional methods, provider-account recovery, administrative process, and emergency access the organization has actually tested.

If users cannot register

  • Check that the user is assigned to the intended passkey profile and is not excluded by another group assignment.
  • Confirm that the chosen passkey type and authenticator are allowed by that profile.
  • Verify browser and operating-system support, and whether the user can satisfy any MFA or Conditional Access condition required for registration.
  • Distinguish a registration-campaign prompt from permission to register: the profile and authentication-method policy must also allow the method.

If registration succeeds but sign-in fails

  • Confirm that the credential was registered to the intended Entra tenant and that the user has selected the right account and browser profile.
  • For cross-device flows, check the device handoff, QR, or Bluetooth experience and retry with a supported platform combination.
  • Review authentication-strength, device-compliance, risk, and session requirements that may block access after credential verification.
  • Check whether the user is selecting a different provider or authenticator from the one used at registration.

If existing FIDO2 users see a change

Review the default passkey profile created from the prior FIDO2 configuration. Confirm assignments and restrictions before changing policy or telling users that their credentials have been removed.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choosing among Entra passkeys and related options

Option Best fit Trade-off to plan for
Synced Entra passkey Users who need supported credentials across several devices and whose provider meets organizational policy. Provider security, personal-device rules, and provider-account recovery become part of the organization’s trust model.
Device-bound passkey Organizations that want a credential tied to a particular device or authenticator. Replacement or loss normally requires another registered credential or a new enrollment.
Microsoft Authenticator passkey Organizations seeking a mobile authenticator option where the Entra flow and platform are supported. Phone availability, supported-platform requirements, and device-replacement procedures matter.
Windows Hello for Business Managed Windows environments integrating passwordless authentication with device management. It is a Windows-oriented identity and device experience, not identical to every general Entra WebAuthn passkey.
Physical FIDO2 security key Administrators, high-risk users, or environments that prohibit personal cloud-synced credentials. Procurement, distribution, inventory, replacement, and loss support add operational work.
macOS Platform SSO Managed Mac fleets using Microsoft Intune and Entra integration. It is a managed platform sign-in capability with its own deployment and device requirements.
Certificate-based authentication Organizations with an established PKI, smart-card use, or certificate lifecycle capability. Issuance, renewal, revocation, device support, and operations require ongoing management.

Before choosing, weigh the threat model, user devices, ownership rules, credential portability, recovery maturity, regulatory requirements, hardware budget, application coverage, and Conditional Access design. For organizations already centered on Microsoft 365, native Entra policy may be the simplest starting point; adding a separate identity provider is a broader architecture decision, not a prerequisite for enabling passkeys.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.