Entra ID & IdentityPlatform ChangesRetrospectives

Passkeys in Microsoft Authenticator Preview (May 2024): Phishing-Resistant MFA for Everyone

By OnCloudSec Research Team · Published Oct 6, 2026 · 5 min read

Facts in this article were checked against the sources listed below as of Oct 5, 2026.

Retrospective: this article looks back at events from May 2024, written in 2026 with the benefit of hindsight.

Around World Password Day in May 2024, Microsoft announced a public preview of device-bound passkeys in the Microsoft Authenticator app for iOS and Android, aimed at organizations with high security requirements. At the same time, it introduced passkey support for consumer Microsoft accounts.

How it unfolded
  1. Phishing outpaces MFAAdversary-in-the-middle and device code phishing kits relay codes and steal sessions.
  2. Passkeys in AuthenticatorMay 2024: Microsoft previews device-bound passkeys in Microsoft Authenticator for iOS and Android.
  3. Origin-bound sign-inThe passkey only works on the legitimate site, so fake sign-in pages get nothing usable.
  4. Policy enforcementConditional Access authentication strengths require phishing-resistant methods for chosen users.
  5. Broader rolloutOrganizations extend passkeys from admins to high-risk roles, then everyone.

For businesses, the significance was practical. Phishing-resistant MFA had existed for years through FIDO2 security keys and Windows Hello for Business, but buying and managing hardware keys for every employee was expensive. Passkeys on the phones employees already carry removed much of that barrier.

Why traditional MFA stopped being enough

By 2024, phishing kits routinely defeated common MFA:

  • Adversary-in-the-middle (AiTM) kits proxy the real Microsoft sign-in page. The user enters their password and approves MFA; the kit captures the session cookie and the attacker reuses it. Microsoft reported one such campaign hitting more than 10,000 organizations in 2022.
  • MFA fatigue floods users with push prompts until they approve one.
  • SMS interception and SIM swapping redirect one-time codes.
  • Device code phishing, which surged in 2026 through kits such as EvilTokens, tricks users into completing sign-in for an attacker's session.

All of these exploit the same weakness: the user can be convinced to authenticate on the attacker's behalf.

One caveat matters here. Passkeys stop attacks that rely on a fake site or on relaying codes — AiTM proxies, fatigue prompts and SMS interception. Device code phishing is different: the victim signs in on Microsoft's genuine page, so a passkey will happily approve the attacker's session. The defense for that technique is to block device code flow with Conditional Access for everyone who doesn't need it, alongside passkeys.

How passkeys work

A passkey is a FIDO2 credential — a cryptographic key pair. The private key stays on the user's device (in Microsoft Authenticator, for device-bound passkeys, it is stored in the app and removed if the app is reinstalled). Signing in requires the device plus a local gesture such as a face scan, fingerprint or PIN.

Crucially, the credential is bound to the legitimate website's domain. A fake sign-in page on another domain can't request a valid signature, and a proxy can't relay one. There's no code to type and nothing reusable for the attacker to capture.

Device-bound or synced?

  • Device-bound passkeys (in Microsoft Authenticator or on FIDO2 security keys) stay on one device. They suit regulated environments and administrators.
  • Synced passkeys (stored in platforms such as iCloud Keychain or Google Password Manager) roam across a user's devices. They're convenient, but their security depends on the consumer account that syncs them.

Microsoft has since expanded passkey options in Entra ID, including passkey profiles that let organizations apply different policies to different groups. Choose by risk: device-bound for admins and high-risk roles, with synced passkeys considered for broader populations where policy allows.

What to do now

  1. Migrate to the authentication methods policy if you haven't already, retiring legacy MFA and SSPR method settings.
  2. Enable Passkey (FIDO2) for a pilot group in the Entra admin center, with self-service setup. Decide whether to enforce attestation and restrict to approved authenticator models (AAGUIDs) — include Microsoft Authenticator's AAGUIDs if you restrict.
  3. Enable Temporary Access Pass so users can register passkeys securely and recover lost devices.
  4. Run a registration campaign and publish short guides for each method.
  5. Enforce with Conditional Access authentication strengths. Require "Phishing-resistant MFA" for directory roles first, then executives, finance and IT support, then everyone who has registered.
  6. Design recovery carefully. A lost phone needs a secure path back: strong help desk verification (not easily researched personal details) and a Temporary Access Pass. Encourage a second phishing-resistant method.
  7. Reduce weaker methods. Phase out SMS and voice for users who have passkeys.
  8. Measure. Track the percentage of users with a phishing-resistant method and the percentage of sign-ins that use one.

How to verify passkeys are working

After rollout, confirm the protection is real:

  • Sign-in logs. Entra ID sign-in details show which authentication method satisfied MFA. Track the share of sign-ins completed with passkeys or other phishing-resistant methods, by department.
  • Authentication strength coverage. Use Conditional Access report-only results and the What If tool to confirm phishing-resistant requirements apply to every privileged role.
  • Registration gaps. The authentication methods registration report shows who still relies on SMS, voice or push only.
  • Recovery events. Monitor Temporary Access Pass creation and MFA method changes, since attackers now target recovery processes instead of sign-in.

Common mistakes

  • Leaving weaker fallbacks enabled. If SMS remains available, attackers will steer users toward it. Remove weaker methods for users who have passkeys.
  • Weak recovery. A passkey rollout is only as strong as the help desk process that re-enrolls someone who lost their phone.
  • Starting with everyone. Begin with administrators and high-risk roles, learn, then expand.
  • Ignoring shared and frontline devices. FIDO2 security keys often work better than phones for shared workstations.
  • Not measuring. Without a target and a monthly metric, rollouts stall at the pilot stage.

Where passkeys fit in a 2026 identity strategy

Passkeys are one layer, not the whole defense. In 2026, phishing-as-a-service platforms such as EvilTokens and Kali365 made token theft and device code phishing available to low-skilled criminals. A complete approach combines passkeys with Conditional Access that requires compliant devices for sensitive resources, blocks device code flow for users who don't need it, and uses token protection where supported, plus monitoring that detects sessions used from unexpected locations.

Questions for leadership

  • What percentage of our employees can sign in with a phishing-resistant method today?
  • Do all administrators use one?
  • What's our target for next quarter, and what's blocking it?

Key takeaways

  • Passkeys in Microsoft Authenticator made phishing-resistant MFA practical on existing phones.
  • Passkeys are bound to the real site, defeating AiTM proxies, fatigue attacks and code relay.
  • Device-bound passkeys suit admins; synced passkeys trade some control for convenience.
  • Roll out by risk, protect recovery, and measure adoption every month.

Sources

  1. Microsoft Entra Blog: Public preview — expanding passkey support in Microsoft Entra ID
  2. Microsoft Learn: Enable passkeys (FIDO2) for your organization
  3. Microsoft Security Blog: New passkey support for Microsoft consumer accounts (May 2, 2024)
entra passkeys2024

More on this story