Microsoft Entra Passkeys: A Beginner's Deep Dive

A Beginner's Deep Dive Guide to Entra Passkeys

Microsoft Entra Passkeys: A Beginner's Deep Dive

This guide explains how Microsoft Entra supports both device-bound and synced passkeys, now generally available. It covers the WebAuthn protocol, how passkeys satisfy MFA, configuration steps for Entra, creating authentication strengths and conditional access policies, and the upcoming support for passkeys on Windows via Windows Hello. Ideal for IT admins planning a passkey rollout.

Passkeys are phishing-resistant. Attackers can no longer trick users into authenticating on fake websites because passkeys are bound to the legitimate service provider’s domain.
  1. rf15

    In my experience, for most basic services, Passkeys are absolute overkill: Your ability to recover your account without too much hassle usually beats having a key explicitely tied to physical hardware (even worse, your phone that you carry around in public). Besides, passkeys are also often used by companies like Microsoft to peddle their apps, because of course you have to have specific apps for it.

    Makes me all feel like passkeys are largely a convenient security excuse for vendor lock-in and siphoning personal information. OTP-Generators seem to be more generally applicable and less phone or company-bound.

  2. throw7

    "Something you have"/"device bound" is not what I want if I don't control it. In the case of passkeys, I don't have access to the private key, so I consider that not controllable by me.

    I'm happy to be wrong if I am able to extract and import the private keys (it's what I do with TOTP now), but my understanding is designers of passkeys explicitly don't want users access to their own privkeys so they can tie them to physical objects. I get that, I don't want that.

    So passkeys are not something I'll ever use or useful or convenient to me.

  3. VCFundedGenYer

    Passkeys are a solid idea in theory - in practice they are a confusing mess. Basic users are incredibly confused by them. My recommendation still continues to be a very strong password + app based MFA.

More from this day

2026-09-02