How to Plan a Passwordless Rollout With Windows Hello and Authenticator
Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.
Passwordless sign-in removes the most attacked credential and improves user experience. Here is a practical rollout plan using Windows Hello for Business, passkeys in Microsoft Authenticator and FIDO2 security keys.
Step 1: Choose methods by persona
- Office workers on managed Windows PCs: Windows Hello for Business.
- Mobile and frontline workers: passkeys in Microsoft Authenticator.
- Administrators and high-risk users: FIDO2 security keys or device-bound passkeys.
- Shared devices: FIDO2 security keys.
Step 2: Prepare prerequisites
- Enable the methods in the Entra authentication methods policy.
- Configure Windows Hello for Business through Intune (cloud Kerberos trust is the simplest model for hybrid environments).
- Enable Temporary Access Pass for bootstrapping new users and recovery.
- Check app compatibility — legacy apps that only support passwords need a plan.
Step 3: Pilot
Start with IT and a willing business team. Measure registration success, sign-in issues and help desk calls.
Step 4: Roll out by group
Use registration campaigns and communications. Provide short guides for each method.
Step 5: Enforce
Use Conditional Access authentication strengths to require passwordless or phishing-resistant methods for groups that have completed registration, starting with admins.
Step 6: Reduce password use
Over time, stop asking users for passwords at all for supported scenarios. Some organizations move to long random passwords users never see.
Common mistakes
- Forgetting account recovery — lost devices need a secure re-onboarding path.
- Leaving SMS available as a fallback that undermines the stronger methods.