Passkeys in Microsoft Authenticator give you phishing-resistant sign-in on the phone people already carry, without buying security keys. The policy side has changed quite a bit with passkey profiles, and most of the support tickets come from the registration flow rather than from sign-in. In this post I'll walk through the prerequisites, the profile configuration, the three ways a user can register, a ring-based rollout and the failures you should expect to see along the way.
Prerequisites#
- Phones running Android 14 or later or iOS 17 or later. If one profile allows both device-bound and synced passkeys, Authenticator must be at least version 6.8.37 on iOS or 6.2507.4749 on Android.
- An account with the Authentication Policy Administrator role to edit the Authentication methods policy, and Conditional Access Administrator plus Microsoft Entra ID P1 if you want to enforce the method. Passkeys themselves need no extra licence; they are available in every edition, including Free.
- For cross-device registration or sign-in (phone plus laptop): Bluetooth and internet on both devices, and these endpoints reachable without proxy interception:
cable.ua5v.comfor Android, andcable.auth.com,app-site-association.cdn-apple.comandapp-site-association.networking.applefor iOS. - Users must have completed MFA within the previous five minutes to register a passkey. For new starters or people who lost their only method, that means a Temporary Access Pass.
Step-by-step#
1. Opt in to passkey profiles#
Go to Entra ID › Authentication methods › Policies › Passkey (FIDO2) and follow the banner link to enable passkey profiles. Your existing tenant-wide settings are copied into a Default passkey profile, and you cannot opt out again. On the Configure tab make sure Allow self-service set up is Yes; it is a global switch, and with No nobody can register from Security info even when the method is enabled.
2. Create a profile for Authenticator#
Still on Configure, select + Add passkey profile and set:
- Enforce attestation: Yes if you want Entra ID to verify that a genuine Authenticator created the key. On iOS this uses Apple's App Attest service; on Android it uses Play Integrity plus key attestation to prove the key is hardware-backed. Attestation is checked at registration only, and attested keys can be created only inside the app, not through the cross-device flow.
- Passkey types: Device-bound. Authenticator stores device-bound keys; Synced is for iCloud Keychain, Google Password Manager and similar providers, and synced keys cannot be attested.
- Target specific AAGUIDs with Behavior set to Allow, then + Add AAGUID › Microsoft Authenticator. If you prefer to type them:
de1e552d-db1d-4423-a619-566b625cdc84(Android) and90a3ccdf-635c-4729-a248-9b709135078f(iOS).
Watch out: key restrictions apply to sign-in as well as registration. Removing an AAGUID you previously allowed locks out everyone who already registered with it.
3. Enable and target in rings#
On the Enable and target tab, switch Enable on, choose Select targets and assign the Authenticator profile to your pilot group. A user in several groups can register or sign in as long as the passkey satisfies at least one profile, while membership in an excluded group blocks the method completely. Microsoft's own example for a targeted rollout is a good template:
| Profile | Target | Passkey types | Attestation | Key restrictions |
|---|---|---|---|---|
| Device-bound passkeys, no Authenticator yet | All users | Device-bound | Enabled | Block the two Authenticator AAGUIDs |
| Passkeys in Microsoft Authenticator | Pilot group 1, then pilot group 2 | Device-bound | Enabled | Allow the two Authenticator AAGUIDs |
Widen the target group ring by ring. The how-to article still describes a limit of three profiles including the default, while the May 2026 What's new entry says the limit was raised to ten and the passkey policy got its own dedicated 20 KB of storage; check what your tenant shows before you design around a number.
4. Choose the registration flow you will document for users#
- Inside Authenticator (recommended): add the work or school account, complete MFA, tap Create a passkey, and on iOS turn Authenticator on as a passkey provider (iOS 18: Settings › General › Autofill & Passwords; iOS 17: Settings › Passwords › Password Options). This is the only flow that produces an attested key.
- From Security info: + Add sign-in method › Passkey in Microsoft Authenticator. The wizard hands the user to the app and confirms the key when they return.
- Cross-device WebAuthn: on Security info choose Having trouble, then create your passkey a different way, pick iPhone or Android and scan the QR code. Needs Bluetooth and the endpoints above, and does not work if attestation is enforced.
5. Enforce with Conditional Access, without the loop#
Use the built-in Phishing-resistant MFA strength, or create a custom strength under Entra ID › Authentication methods › Authentication strengths that contains Passkeys (FIDO2) and, under Advanced options, the Authenticator AAGUIDs. Do not point a phishing-resistant strength at All resources on every platform before people have registered: Authenticator itself is one of those resources, so users are asked for a passkey while trying to create one. Microsoft's workaround is two policies, one for desktop operating systems requiring the passkey strength, and one for Android and iOS that accepts a Temporary Access Pass or the passkey. Any policy on the Register security information user action must also be satisfiable, and grants of Require approved client app or Require app protection policy on All resources block Authenticator registration outright; swap them for Require device to be marked as compliant or scope them to specific apps.
Tip: since May 2026 registration campaigns can nudge users to register a passkey at sign-in. It is a lighter touch than a hard Conditional Access requirement for the early rings.
Verify#
- The user's Security info page lists the new passkey, and in Entra ID › Users › Authentication methods it appears as Passkey (device-bound); the method details show the AAGUID, which is handy when a key was created by the wrong provider.
- In Entra ID › Monitoring & health › Sign-in logs, open a sign-in and check the Authentication details tab: the passkey should be the method that satisfied the requirement, and the Conditional Access tab should show your strength policy as Success.
- Use the authentication methods usage reports to track how many users in each ring have registered before you move to the next one.
Tips and gotchas#
| What users report | Likely cause | What to do |
|---|---|---|
| "The passkey already exists" on retry | The key was stored locally in the app but never registered with Entra ID, for example after a timeout or because the provider was not allowed | In Authenticator open the account, Settings › Delete passkey, then register again |
| Registration fails only when attestation is on | Apple App Attest or Google Play Integrity is slow or down | Retry later; check the Apple System Status and Google Play Status pages |
| QR code scanned, nothing happens | Bluetooth off, the cable.* or Apple endpoints intercepted by a proxy, or attestation enforced (no attested cross-device registration) | Fix connectivity or send the user through the in-app flow |
| Passkey works on the phone's browser but not in the work apps | On Android the key lives in either the personal or the work profile and is only usable from that profile | Create a passkey in Authenticator in each profile the user needs |
| Cannot add the work account at all | Since June 2026 Authenticator blocks work or school accounts on rooted or jailbroken devices; there is no admin override | Move the user to a compliant device |
| Stuck asking for a passkey while trying to register one | Phishing-resistant strength on All resources, or an approved-app grant | Split the policies as described in step 5, or issue a TAP |
| Passkey stops working after a UPN change | Existing passkeys cannot be updated for a new UPN | Delete the old passkey in Security info and register a new one |
| Firefox on Linux will not accept the passkey | Not supported for Authenticator passkeys | Use another browser |
- Guest and B2B users cannot register passkeys in your tenant.
- Native Windows apps need Windows 11 22H2 or later to accept an Authenticator passkey; on iOS, native apps need iOS 16 without the Enterprise SSO plug-in or iOS 17.1 with it.
- From August 2026 iOS users restoring Authenticator on a new phone get an improved restore flow for device-bound passkeys when iCloud Keychain backup is on; Android is to follow. Until then, treat a phone swap as a re-registration event.