How to Roll Out Device-Bound Passkeys in Entra ID
Retrospective: this article looks back at events from May 2024, written in 2026 with the benefit of hindsight.
Passkeys in Microsoft Authenticator give users phishing-resistant MFA on their phones. Here is how to roll them out in Entra ID.
Step 1: Prerequisites
- Microsoft Authenticator current version on iOS or Android.
- Users have an existing MFA method (or use Temporary Access Pass) to register.
- Authentication methods policy migrated (legacy MFA and SSPR settings retired).
Step 2: Enable passkeys
In the Entra admin center, Authentication methods → Passkey (FIDO2):
- Enable for a pilot group.
- Allow self-service setup.
- Decide on attestation enforcement and whether to restrict to specific authenticator models (AAGUIDs). For device-bound passkeys in Authenticator, include Microsoft Authenticator's AAGUIDs if restricting.
- Configure passkey profiles if available in your tenant, to allow different policies for different groups.
Step 3: Register users
Users go to My Security Info → Add sign-in method → Passkey and follow the prompts in Authenticator. A registration campaign can nudge users.
Step 4: Require phishing-resistant MFA
Create Conditional Access policies with authentication strength: Phishing-resistant MFA — first for admins, then high-risk users, then everyone who has registered.
Step 5: Plan recovery
- Temporary Access Pass for re-registration.
- Help desk verification procedure for lost devices.
- Encourage registering a second phishing-resistant method (another device, Windows Hello or a security key).
Step 6: Communicate
Short guides showing the registration and sign-in experience.
Measure
Track phishing-resistant method registration and the percentage of sign-ins using them.