Entra ID & IdentityHow-To & HardeningRetrospectives

Passwordless Readiness Checklist for Windows and Mobile

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.

Use this checklist to check whether your organization is ready to roll out passwordless sign-in.

Licensing and platform

  • Entra ID tenant with authentication methods policy migrated from legacy MFA and SSPR settings.
  • Windows 10/11 devices managed by Intune or Group Policy for Windows Hello for Business.
  • Mobile devices able to run Microsoft Authenticator with passkey support.
  • Budget approved for FIDO2 security keys where needed.

Identity configuration

  • Passwordless methods enabled for a pilot group.
  • Temporary Access Pass enabled for onboarding and recovery.
  • Conditional Access authentication strengths defined.
  • Break-glass accounts configured with FIDO2 keys and excluded appropriately.

Applications

  • Inventory of apps that still require passwords (legacy protocols, on-prem apps without modern auth).
  • Plan for each: modernize, put behind an identity-aware proxy, or accept temporarily.

Users and support

  • Personas defined with a chosen method for each.
  • Short user guides and videos prepared.
  • Help desk trained on registration and recovery.
  • Identity verification procedure for recovery requests documented.

Measurement

  • Baseline: percentage of users with any passwordless or phishing-resistant method.
  • Target and timeline for each persona.
  • Monthly reporting on registration progress and sign-in method usage.

Risk

  • SMS and voice phased out or limited.
  • Admins required to use phishing-resistant methods first.
passwordless readiness checklistIgnite 2018 passwordless2018

More on this story