Entra ID & IdentityHow-To & HardeningRetrospectives

How to Roll Out Device-Bound Passkeys in Entra ID

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2024, written in 2026 with the benefit of hindsight.

Passkeys in Microsoft Authenticator give users phishing-resistant MFA on their phones. Here is how to roll them out in Entra ID.

Step 1: Prerequisites

  • Microsoft Authenticator current version on iOS or Android.
  • Users have an existing MFA method (or use Temporary Access Pass) to register.
  • Authentication methods policy migrated (legacy MFA and SSPR settings retired).

Step 2: Enable passkeys

In the Entra admin center, Authentication methods → Passkey (FIDO2):

  • Enable for a pilot group.
  • Allow self-service setup.
  • Decide on attestation enforcement and whether to restrict to specific authenticator models (AAGUIDs). For device-bound passkeys in Authenticator, include Microsoft Authenticator's AAGUIDs if restricting.
  • Configure passkey profiles if available in your tenant, to allow different policies for different groups.

Step 3: Register users

Users go to My Security Info → Add sign-in method → Passkey and follow the prompts in Authenticator. A registration campaign can nudge users.

Step 4: Require phishing-resistant MFA

Create Conditional Access policies with authentication strength: Phishing-resistant MFA — first for admins, then high-risk users, then everyone who has registered.

Step 5: Plan recovery

  • Temporary Access Pass for re-registration.
  • Help desk verification procedure for lost devices.
  • Encourage registering a second phishing-resistant method (another device, Windows Hello or a security key).

Step 6: Communicate

Short guides showing the registration and sign-in experience.

Measure

Track phishing-resistant method registration and the percentage of sign-ins using them.

roll out passkeys entra idEntra passkeys2024

More on this story