Passkey Rollout Checklist: Registration, Recovery and Help Desk
Retrospective: this article looks back at events from May 2024, written in 2026 with the benefit of hindsight.
Use this checklist to roll out passkeys across your organization.
Planning
- Target personas defined (admins, executives, finance, all staff).
- Method chosen per persona (passkey in Authenticator, FIDO2 security key, Windows Hello for Business).
- Policy on device-bound vs synced passkeys decided.
- Shared and frontline device scenarios planned.
Configuration
- Passkey (FIDO2) method enabled for pilot group.
- Attestation and AAGUID restrictions decided.
- Temporary Access Pass enabled.
- Authentication strengths defined in Conditional Access.
Registration
- Registration campaign configured.
- User guides and videos prepared.
- Office hours or support sessions scheduled.
- Registration progress tracked weekly.
Recovery
- Lost-device procedure documented.
- Help desk verification uses strong methods (not easily researched personal details).
- Users encouraged to register a backup method.
Help desk
- Help desk trained on passkey registration and troubleshooting.
- Scripts updated for common issues (Bluetooth for cross-device sign-in, OS versions).
Enforcement
- Admins required to use phishing-resistant MFA.
- High-risk groups enforced after registration reaches target.
- SMS and voice reduced or removed.
Measurement
- Percentage of users with phishing-resistant methods.
- Percentage of sign-ins using passkeys.
- Help desk ticket volume related to authentication.
- Passkeys in Microsoft Authenticator Preview (May 2024): Phishing-Resistant MFA for Everyone Platform Changes
- How to Roll Out Device-Bound Passkeys in Entra ID How-To & Hardening
- CIO Brief: Passkeys Make Phishing-Resistant MFA Affordable CIO Briefings