Entra IDHow-to

Rolling out passkeys in Microsoft Authenticator: policy, registration and the errors users hit

Configure the Passkey (FIDO2) policy and a passkey profile for Authenticator, pick the right registration flow, roll out in rings and fix the registration and sign-in failures users report.

Passkeys in Microsoft Authenticator give you phishing-resistant sign-in on the phone people already carry, without buying security keys. The policy side has changed quite a bit with passkey profiles, and most of the support tickets come from the registration flow rather than from sign-in. In this post I'll walk through the prerequisites, the profile configuration, the three ways a user can register, a ring-based rollout and the failures you should expect to see along the way.

How this guide is organised: Prerequisites → Step-by-step → Verify → Tips and gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (5 steps: Opt in to passkey profiles; Create a profile for Authenticator; Enable and target in rings; Choose the registration flow you will document for users; Enforce with Conditional Access, without the loop). 3. Verify. 4. Tips and gotchas. Toolbox: Passwords › Password Options, Users › Authentication methods, cable.ua5v.com, cable.auth.com, app-site-association.cdn-apple.com.1Prerequisites2Step-by-step3Verify4Tips and gotchas1Opt in to passkeyprofiles2Create a profile forAuthenticator3Enable and targetin rings4Choose theregistration flow y…5Enforce withConditional Acces…TOOLBOXPasswords › Password OptionsUsers › Authentication methodscable.ua5v.comcable.auth.comapp-site-association.cdn-apple.comHow this guide is organised: Prerequisites → Step-by-step → Verify → Tips and gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (5 steps: Opt in to passkey profiles; Create a profile for Authenticator; Enable and target in rings; Choose the registration flow you will document for users; Enforce with Conditional Access, without the loop). 3. Verify. 4. Tips and gotchas. Toolbox: Passwords › Password Options, Users › Authentication methods, cable.ua5v.com, cable.auth.com, app-site-association.cdn-apple.com.1Prerequisites2Step-by-step1Opt in to passkey profiles2Create a profile for Authenticator3Enable and target in rings4Choose the registration flow you will documentfor users5Enforce with Conditional Access, without theloop3Verify4Tips and gotchasTOOLBOXPasswords › Password OptionsUsers › Authentication methodscable.ua5v.comcable.auth.comapp-site-association.cdn-apple.com
At a glance: how this guide is organised · 5 steps · 5 key settings and tools

Prerequisites#

  • Phones running Android 14 or later or iOS 17 or later. If one profile allows both device-bound and synced passkeys, Authenticator must be at least version 6.8.37 on iOS or 6.2507.4749 on Android.
  • An account with the Authentication Policy Administrator role to edit the Authentication methods policy, and Conditional Access Administrator plus Microsoft Entra ID P1 if you want to enforce the method. Passkeys themselves need no extra licence; they are available in every edition, including Free.
  • For cross-device registration or sign-in (phone plus laptop): Bluetooth and internet on both devices, and these endpoints reachable without proxy interception: cable.ua5v.com for Android, and cable.auth.com, app-site-association.cdn-apple.com and app-site-association.networking.apple for iOS.
  • Users must have completed MFA within the previous five minutes to register a passkey. For new starters or people who lost their only method, that means a Temporary Access Pass.

Step-by-step#

1. Opt in to passkey profiles#

Go to Entra ID › Authentication methods › Policies › Passkey (FIDO2) and follow the banner link to enable passkey profiles. Your existing tenant-wide settings are copied into a Default passkey profile, and you cannot opt out again. On the Configure tab make sure Allow self-service set up is Yes; it is a global switch, and with No nobody can register from Security info even when the method is enabled.

2. Create a profile for Authenticator#

Still on Configure, select + Add passkey profile and set:

  • Enforce attestation: Yes if you want Entra ID to verify that a genuine Authenticator created the key. On iOS this uses Apple's App Attest service; on Android it uses Play Integrity plus key attestation to prove the key is hardware-backed. Attestation is checked at registration only, and attested keys can be created only inside the app, not through the cross-device flow.
  • Passkey types: Device-bound. Authenticator stores device-bound keys; Synced is for iCloud Keychain, Google Password Manager and similar providers, and synced keys cannot be attested.
  • Target specific AAGUIDs with Behavior set to Allow, then + Add AAGUID › Microsoft Authenticator. If you prefer to type them: de1e552d-db1d-4423-a619-566b625cdc84 (Android) and 90a3ccdf-635c-4729-a248-9b709135078f (iOS).

Watch out: key restrictions apply to sign-in as well as registration. Removing an AAGUID you previously allowed locks out everyone who already registered with it.

3. Enable and target in rings#

On the Enable and target tab, switch Enable on, choose Select targets and assign the Authenticator profile to your pilot group. A user in several groups can register or sign in as long as the passkey satisfies at least one profile, while membership in an excluded group blocks the method completely. Microsoft's own example for a targeted rollout is a good template:

ProfileTargetPasskey typesAttestationKey restrictions
Device-bound passkeys, no Authenticator yetAll usersDevice-boundEnabledBlock the two Authenticator AAGUIDs
Passkeys in Microsoft AuthenticatorPilot group 1, then pilot group 2Device-boundEnabledAllow the two Authenticator AAGUIDs

Widen the target group ring by ring. The how-to article still describes a limit of three profiles including the default, while the May 2026 What's new entry says the limit was raised to ten and the passkey policy got its own dedicated 20 KB of storage; check what your tenant shows before you design around a number.

4. Choose the registration flow you will document for users#

  • Inside Authenticator (recommended): add the work or school account, complete MFA, tap Create a passkey, and on iOS turn Authenticator on as a passkey provider (iOS 18: Settings › General › Autofill & Passwords; iOS 17: Settings › Passwords › Password Options). This is the only flow that produces an attested key.
  • From Security info: + Add sign-in method › Passkey in Microsoft Authenticator. The wizard hands the user to the app and confirms the key when they return.
  • Cross-device WebAuthn: on Security info choose Having trouble, then create your passkey a different way, pick iPhone or Android and scan the QR code. Needs Bluetooth and the endpoints above, and does not work if attestation is enforced.

5. Enforce with Conditional Access, without the loop#

Use the built-in Phishing-resistant MFA strength, or create a custom strength under Entra ID › Authentication methods › Authentication strengths that contains Passkeys (FIDO2) and, under Advanced options, the Authenticator AAGUIDs. Do not point a phishing-resistant strength at All resources on every platform before people have registered: Authenticator itself is one of those resources, so users are asked for a passkey while trying to create one. Microsoft's workaround is two policies, one for desktop operating systems requiring the passkey strength, and one for Android and iOS that accepts a Temporary Access Pass or the passkey. Any policy on the Register security information user action must also be satisfiable, and grants of Require approved client app or Require app protection policy on All resources block Authenticator registration outright; swap them for Require device to be marked as compliant or scope them to specific apps.

Tip: since May 2026 registration campaigns can nudge users to register a passkey at sign-in. It is a lighter touch than a hard Conditional Access requirement for the early rings.

Verify#

  • The user's Security info page lists the new passkey, and in Entra ID › Users › Authentication methods it appears as Passkey (device-bound); the method details show the AAGUID, which is handy when a key was created by the wrong provider.
  • In Entra ID › Monitoring & health › Sign-in logs, open a sign-in and check the Authentication details tab: the passkey should be the method that satisfied the requirement, and the Conditional Access tab should show your strength policy as Success.
  • Use the authentication methods usage reports to track how many users in each ring have registered before you move to the next one.

Tips and gotchas#

What users reportLikely causeWhat to do
"The passkey already exists" on retryThe key was stored locally in the app but never registered with Entra ID, for example after a timeout or because the provider was not allowedIn Authenticator open the account, Settings › Delete passkey, then register again
Registration fails only when attestation is onApple App Attest or Google Play Integrity is slow or downRetry later; check the Apple System Status and Google Play Status pages
QR code scanned, nothing happensBluetooth off, the cable.* or Apple endpoints intercepted by a proxy, or attestation enforced (no attested cross-device registration)Fix connectivity or send the user through the in-app flow
Passkey works on the phone's browser but not in the work appsOn Android the key lives in either the personal or the work profile and is only usable from that profileCreate a passkey in Authenticator in each profile the user needs
Cannot add the work account at allSince June 2026 Authenticator blocks work or school accounts on rooted or jailbroken devices; there is no admin overrideMove the user to a compliant device
Stuck asking for a passkey while trying to register onePhishing-resistant strength on All resources, or an approved-app grantSplit the policies as described in step 5, or issue a TAP
Passkey stops working after a UPN changeExisting passkeys cannot be updated for a new UPNDelete the old passkey in Security info and register a new one
Firefox on Linux will not accept the passkeyNot supported for Authenticator passkeysUse another browser
  • Guest and B2B users cannot register passkeys in your tenant.
  • Native Windows apps need Windows 11 22H2 or later to accept an Authenticator passkey; on iOS, native apps need iOS 16 without the Enterprise SSO plug-in or iOS 17.1 with it.
  • From August 2026 iOS users restoring Authenticator on a new phone get an improved restore flow for device-bound passkeys when iCloud Keychain backup is on; Android is to follow. Until then, treat a phone swap as a re-registration event.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)