Enable and support passkeys in Authenticator for Microsoft Entra ID
In brief
Learn about Authenticator-specific requirements, configuration, and troubleshooting for passkeys in Microsoft Authenticator for Microsoft Entra ID.
What Entra admins need to know
Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.
Enable passkeys in Authenticator
This article lists steps to enablecovers Authenticator-specific requirements and enforce use ofconfiguration for passkeys in Microsoft Authenticator for Microsoft Entra ID. First,
Before you updatefollow the Authentication methods policy to allow users to registersteps in this article, enable passkeys and sign in withcreate a passkey profile. For steps, see Enable passkeys (FIDO2) in Microsoft Entra ID.
Prerequisites for passkeys in Authenticator. Then you can use Conditional Access authentication strengths policies to enforce passkey sign-in when users access a sensitive resource.RequirementsAuthenticator
Microsoft Entra multifactor authentication (MFA).An account with at least Authentication Policy Administrator permissions to configure authentication methods.- You need to enable passkey sign-in in the Passkey (FIDO2) policy in Authentication methods in the Microsoft Entra admin center.
- Android 14 and later or iOS 17 and later.
- For cross-device registration and authentication:
- Make sure that Bluetooth and an active internet connection are enabled on both devices.
- Make sure that Bluetooth and an active internet connection are enabled on both devices.
To learn more about FIDO2 support, see Support for FIDO2 authentication with Microsoft Entra ID.
Configure a profile for passkeys in Authenticator
Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator
as at least an Authentication Policy Administrator.Browse to Entra ID > Authentication methods.
On the Authentication methods | Policies page, select Passkey (FIDO2) > Configure.
Select + Add profile.
:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-passkey-profile.png" alt-text="Screenshot that shows how to add a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/add-passkey-profile.png":::
Enter a Name for the profile, such as Authenticator passkeys.
Choose whether to Enforce attestation. For more information, see Authenticator attestation.
For Passkey types, select Device-bound.
Select Target specific AAGUIDS and set Behavior to Allow.
Select + Add AAGUID > Microsoft Authenticator and Save.
:::image type="content" border="true" source="media/how-to-enable-authenticator-passkey/authenticator-passkey-profile.png" alt-text="Screenshot that shows the Add passkey profile settings for Authenticator passkeys." lightbox="media/how-to-enable-authenticator-passkey/authenticator-passkey-profile.png":::
Enable and target groups for a profile for passkeys in Authenticator
Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
Browse to Entra ID > Authentication
method policymethods.UnderOn the
methodAuthentication methods | Policies page, select Passkey (FIDO2) > Enable and target.On the Enable and Target tab, make sure Enable is On.
Select Add target,
selectand choose All users orAdd groupsSelect targets toselectchoose specific groups.Only security groups are supported.On theConfiguretab:SetAllow self-service set up:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-target.png" alt-text="Screenshot that shows how toYes. If it's set toNo, users can't registeradd a target for a passkeyby using Security info, even if passkeys (FIDO2) are enabled by the Authentication methods policy.profile." lightbox="media/how-to-authentication-passkey-profiles/add-target.png":::SetSelect the profile for passkeys in Authenticator andEnforce attestationSave.:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/enable-target-authenticator.png" alt-text="Screenshot that shows how to
YesorNo. Users can only register attestedenable and target a profile for passkeysdirectlyinthe Authenticator app. Cross-device registration flows don't support registration of attested passkeys.Authenticator." lightbox="media/how-to-authentication-passkey-profiles/enable-target-authenticator.png":::
Authenticator attestation
When you enable passkeys and create a passkey profile in the Microsoft Entra admin center, you can choose whether to enforce attestation. For general steps to configure passkey profiles, see Enable passkeys (FIDO2).
When attestation is enabled in the passkey (FIDO2) policy,enabled, Microsoft Entra ID tries to verifyverifies the legitimacy of the passkey being created. When the user is registering a passkey in the Authenticator, attestation verifies that the legitimate Authenticator app created the passkey by using Apple and Google services. Here are more details:services:
iOS: Authenticator attestation uses the iOS App Attest service to ensure the legitimacy of the Authenticator app before registering the passkey.
Android:
- For Play Integrity attestation, Authenticator attestation uses the Play Integrity API to ensure the legitimacy of the Authenticator app before registering the passkey.
- For Key attestation, Authenticator attestation uses key attestation by Android to verify that the passkey being registered is hardware-backed.
Key restrictionsset the usability of specific passkeys for both registration and authentication. YouUsers cansetEnforce key restrictionstoNoto allow users toonly registerany supported passkey, including passkey registrationattested passkeys directly in the Authenticator app.If you setEnforce key restrictionsCross-device registration flows don't support registration of attested passkeys.Authenticator AAGUIDs
You can restrict users to
Yesand already have activeuse Authenticator passkeys by targeting the Authenticator Attestation Globally Unique Identifier (AAGUID) in the passkeyusage, you should collect and add the AAGUIDs of the passkeys being used today.profile.If you
setRestrict specific keystoAllow,prefer, you can also selectMicrosoft Authenticator+ Add AAGUIDto automatically add the Authenticator app AAGUIDs to the key restrictions list. You can alsoand manually add the followingAAGUIDs to allow users to register passkeys in Authenticator by signing in to the Authenticator app or by going through a guided flow onSecurity info:AAGUIDs:- Authenticator for Android:
de1e552d-db1d-4423-a619-566b625cdc84 - Authenticator for iOS:
90a3ccdf-635c-4729-a248-9b709135078f
If you
change key restrictions andremove an AAGUID that you previously allowed, users who previously registered an allowed method can no longer use it for sign-in.- Authenticator for Android:
:::image type="content" border="true" source="media/how-to-enable-authenticator-passkey/optional-settings.png" alt-text="Screenshot that shows Authenticator enabled for passkey."lightbox="media/how-to-enable-authenticator-passkey/optional-settings.png":::
After you finish the configuration, selectSave.If you see an error when you try to save, replace multiple groups with a single group in one operation, and then selectSaveagain.
Enable passkeys in Authenticator by using Graph Explorer
In addition to using the Microsoft Entra admin center, you can To configure the policy by using Graph Explorer:
Users can't register passkeys in Authenticator if they're included in the following Conditional Access policy:
The policy forces users to sign in to all cloud applications by using an app that supports Microsoft Intune app protection policies. Authenticator doesn't support this policy on either Android or iOS. Here are some workarounds: You can filter for applications and transition the policy target from All resources (formerly 'All cloud apps') to specific applications. Start with a review of applications that are used in your tenant. Use filters to tag appropriate applications. You can use mobile device management (MDM) and the Require device to be marked as compliant control. Authenticator can satisfy this grant control if MDM fully manages the device and it's compliant. For example: You can grant users a temporary exemption from the Conditional Access policy. Consider using one or more compensating controls: After an admin enables passkeys in Authenticator, users can register a passkey in the app on their iOS or Android device.
For registration steps, see Register a passkey in Microsoft Authenticator. After registration, users can sign in to For sign-in also enable passkeys in Authenticator by using Graph Explorer. If you're assigned at least the Authentication Policy Administrator role, you can update the Authentication methods policy to allow the AAGUIDs for Authenticator.
1. To disableenable attestation enforcement and enforce key restrictions to allow only AAGUIDs for Authenticator, perform a `PATCH` operation by using the following request body:
```json
PATCH https://graph.microsoft.com/v1.0/authenticationMethodsPolicy/authenticationMethodConfigurations/FIDO2
Some organizations restrict Bluetooth usage, which includes the use of passkeys. In such cases, organizations can allow passkeys by permitting Bluetooth pairing exclusively with passkey-enabled FIDO2 authenticators. For more information about how to configure Bluetooth usage only for passkeys, see [Passkeys in Bluetooth-restricted environments](/windows/security/identity-protection/passkeys/?tabs=windows%2Cintune#passkeys-in-bluetooth-restricted-environments).
## DeleteTroubleshoot passkeys in Authenticator
This section covers issues that users might see when they use passkeys in Authenticator and possible ways for administrators to resolve them.
### Store passkeys in Android profiles
Passkeys on Android are used only from the profile where they're stored. If a passkey is stored in an Android Work profile, it's used from that profile. If a user deletespasskey is stored in an Android Personal profile, it's used from that profile. To make sure that users can access and use the passkey they need, users with both an Android Personal profile and an Android Work profile should create their passkeys in Authenticator for each profile.
### Workarounds for an authentication strength Conditional Access policy loop
Users can get in a loop when they try to add a passkey in Authenticator,Authenticator if a Conditional Access policy requires phishing-resistant authentication to access **All resources (formerly 'All cloud apps')**. For example:
- Condition: **All devices (Windows, Linux, macOS, Windows, Android)**
- Targeted resource: **All resources (formerly 'All cloud apps')**
- Grant control: **Authentication strength – Require passkey in Authenticator**
The policy forces targeted users to use a passkey to sign in to all cloud applications, which includes the Authenticator app. It requires users to use a passkey is also removedwhen they try to add a passkey in Authenticator on either Android or iOS.
Here are some workarounds:
- You can [filter for applications](~/identity/conditional-access/concept-filter-for-applications.md) and transition the policy target from **All resources (formerly 'All cloud apps')** to specific applications. Start with a review of applications that are used in your tenant. Use filters to tag Authenticator and other applications.
- To further reduce support costs, you can run an internal campaign to help users adopt passkeys before you enforce them. When you're ready to enforce passkey usage, create two Conditional Access policies:
- A policy for mobile operating system (OS) versions
- A policy for desktop OS versions
Require a different authentication strength for each policy, and configure other policy settings listed in the following table. You can enable a [Temporary Access Pass (TAP)](howto-authentication-temporary-access-pass.md) for users or enable other authentication methods to help users register the passkey.
A TAP limits the time when users can register a passkey. You can accept it only on mobile platforms where you allow passkey registration.
| Conditional Access policy | Desktop OS | Mobile OS |
|---------------------------|----------------|---------------|
| Name | Require a passkey in Authenticator to access a desktop OS. | Require a TAP, a phishing-resistant credential, or any other specified authentication method to access a mobile OS. |
| Condition | Specific devices (desktop operating systems). | Specific devices (mobile operating systems). |
| Devices | N/A. | Android, iOS. |
| Exclude devices | Android, iOS. | N/A. |
| Targeted resource | All resources. | All resources. |
| Grant control | Authentication strength. | Authentication strength.<sup>1</sup> |
| Methods | Passkey in Authenticator. |TAP, passkey in Authenticator. |
| Policy result | Users who can't sign in with a passkey in Authenticator are directed to the **My Sign-ins** wizard mode. After registration, they're asked to sign in to Authenticator on their mobile device. | Users who sign in to Authenticator with a TAP or another allowed method can register a passkey directly in Authenticator. No loop occurs because the user meets the authentication requirements. |
<sup>1</sup>For users to register new sign-in methods, your grant control for the mobile policy needs to match your Conditional Access policy to register [Security info](https://mysignins.microsoft.com/security-info).
Users who can't register passkeys because of Require approved client app or Require app protection policy Conditional Access grant controls
s sign-re allowed to register a passkey. Remove the exemption after the time period. Then direct users to call the help desk if they missed their time.Register a passkey in Authenticator
Sign in
methods. An Authentication Policy Administrator can also follow these steps to deletewith a passkey from the user's authentication methods, but it won't remove the passkey from Authenticator.
1. Signin Authenticatorthe [MicrosoftMicrosoft Entra admin center](https://entra.microsoft.com), and search for the user whose passkey must be removed.
1. Select **Authentication methods**, right-click **Passkey**, and select **Delete**.
Unless the user initiated the passkey deletion themselves in Authenticator, they need to also removeID by using the passkey in Authenticator on their device.
## Enforcewith passkeys in Authenticator
To make users sign in with a passkey when they access a sensitive resource, use the built-in phishing-resistant authentication strength, or create a custom authentication strength by following these steps:
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a Conditional Access Administrator.
1. Browse to **Entra ID** > **Authentication methods** > **Authentication strengths**steps, see Sign in with passkeys in Authenticator.
1. Select **New authentication strength**.
1. Provide a descriptive name for your new authentication strength.
1. Optionally, provide a description.
1. Select **Passkeys (FIDO2)**, and then select **Advanced options**.
1. Select **Phishing-resistant MFA strength** or add AAGUIDs for passkeys in Authenticator:
- **Authenticator for Android**: `de1e552d-db1d-4423-a619-566b625cdc84`
- **Authenticator for iOS**: `90a3ccdf-635c-4729-a248-9b709135078f`
1. Select **Next**, and review the policy configuration.
## Related content
- [Support for passkey in Windows](/windows/security/identity-protection/passkeys)
@@ -1,19 +1,24 @@ ----title: Enable passkeys in Authenticator for Microsoft Entra ID-description: Learn about how to enable passkeys in Microsoft Authenticator for Microsoft Entra ID.+title: Enable and support passkeys in Authenticator for Microsoft Entra ID+description: Learn about Authenticator-specific requirements, configuration, and troubleshooting for passkeys in Microsoft Authenticator for Microsoft Entra ID. ms.topic: how-to-ms.date: 06/05/2026-ms.reviewer: mjsantani-ms.custom: sfi-ga-nochange, sfi-image-nochange-# Customer intent: As a Microsoft Entra administrator, I want to learn how to enable and enforce passkeys in Microsoft Authenticator sign-in for users.+ms.date: 07/05/2026+ms.reviewer: mjsantani, calui, tilarso+ms.collection: M365-identity-device-management+ms.custom: sfi-ga-nochange, sfi-image-nochange, msecd-doc-authoring-1013+ai-usage: ai-assisted+# Customer intent: As a Microsoft Entra administrator, I want to learn about Authenticator-specific requirements for passkeys so I can enable and support them for my users. --- # Enable passkeys in Authenticator -This article lists steps to enable and enforce use of passkeys in Authenticator for Microsoft Entra ID. First, you update the Authentication methods policy to allow users to register and sign in with passkeys in Authenticator. Then you can use Conditional Access authentication strengths policies to enforce passkey sign-in when users access a sensitive resource.+This article covers Authenticator-specific requirements and configuration for passkeys in Microsoft Authenticator for Microsoft Entra ID. -## Requirements+Before you follow the steps in this article, enable passkeys and create a passkey profile. For steps, see [Enable passkeys (FIDO2) in Microsoft Entra ID](how-to-authentication-passkeys-fido2.md). -- [Microsoft Entra multifactor authentication (MFA)](howto-mfa-getstarted.md).+## Prerequisites for passkeys in Authenticator++- An account with at least [Authentication Policy Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-policy-administrator) permissions to configure authentication methods.+- You need to [enable passkey sign-in](how-to-authentication-passkeys-fido2.md#enable-passkey-profiles) in the **Passkey (FIDO2)** policy in **Authentication methods** in the Microsoft Entra admin center. - Android 14 and later or iOS 17 and later. - For cross-device registration and authentication: - Make sure that Bluetooth and an active internet connection are enabled on both devices. @@ -29,55 +34,79 @@ This article lists steps to enable and enforce use of passkeys in Authenticator > [!NOTE] > Users can't use cross-device registration if you enable attestation. -To learn more about FIDO2 support, see [Support for FIDO2 authentication with Microsoft Entra ID](fido2-compatibility.md).+To learn more about FIDO2 support, see [Support for FIDO2 authentication with Microsoft Entra ID](concept-fido2-compatibility.md). > [!NOTE] > If you grant the **Require device to be marked as compliant** control as part of a Conditional Access policy, it doesn't block Microsoft Authenticator app access to the UserAuthenticationMethod.Read scope. Authenticator needs access to the UserAuthenticationMethod.Read scope during Authenticator registration to determine which credentials a user can configure. Authenticator needs access to UserAuthenticationMethod.ReadWrite to register credentials, which doesn't bypass the **Require device to be marked as compliant** check. -## Enable passkeys in Authenticator in the admin center+## Configure a profile for passkeys in Authenticator++1. Sign in to the Microsoft Entra admin center as at least an [Authentication Policy Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-policy-administrator).+1. Browse to **Entra ID** > **Authentication methods**.+1. On the **Authentication methods | Policies** page, select **Passkey (FIDO2)** > **Configure**.+1. Select **+ Add profile**.++ :::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-passkey-profile.png" alt-text="Screenshot that shows how to add a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/add-passkey-profile.png":::++1. Enter a **Name** for the profile, such as **Authenticator passkeys**.+1. Choose whether to **Enforce attestation**. For more information, see [Authenticator attestation](#authenticator-attestation).+1. For **Passkey types**, select **Device-bound**.+1. Select **Target specific AAGUIDS** and set **Behavior** to **Allow**.+1. Select **+ Add AAGUID** > **Microsoft Authenticator** and **Save**.++ :::image type="content" border="true" source="media/how-to-enable-authenticator-passkey/authenticator-passkey-profile.png" alt-text="Screenshot that shows the Add passkey profile settings for Authenticator passkeys." lightbox="media/how-to-enable-authenticator-passkey/authenticator-passkey-profile.png":::++## Enable and target groups for a profile for passkeys in Authenticator++1. Sign in to the Microsoft Entra admin center as at least an [Authentication Policy Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-policy-administrator).+1. Browse to **Entra ID** > **Authentication methods**.+1. On the **Authentication methods | Policies** page, select **Passkey (FIDO2)** > **Enable and target**.+1. On the **Enable and Target** tab, make sure **Enable** is **On**.+1. Select **Add target**, and choose **All users** or **Select targets** to choose specific groups.++ :::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-target.png" alt-text="Screenshot that shows how to add a target for a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/add-target.png":::++1. Select the profile for passkeys in Authenticator and **Save**. -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).-1. Browse to **Entra ID** > **Authentication methods** > **Authentication method policy**.-1. Under the method **Passkey (FIDO2)**, select **All users** or **Add groups** to select specific groups. *Only security groups are supported*.-1. On the **Configure** tab:- - Set **Allow self-service set up** to **Yes**. If it's set to **No**, users can't register a passkey by using [Security info](https://mysignins.microsoft.com/security-info), even if passkeys (FIDO2) are enabled by the Authentication methods policy.- - Set **Enforce attestation** to **Yes** or **No**. Users can only register attested passkeys directly in the Authenticator app. Cross-device registration flows don't support registration of attested passkeys.+ :::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/enable-target-authenticator.png" alt-text="Screenshot that shows how to enable and target a profile for passkeys in Authenticator." lightbox="media/how-to-authentication-passkey-profiles/enable-target-authenticator.png"::: - When attestation is enabled in the passkey (FIDO2) policy, Microsoft Entra ID tries to verify the legitimacy of the passkey being created. When the user is registering a passkey in the Authenticator, attestation verifies that the legitimate Authenticator app created the passkey by using Apple and Google services. Here are more details:+ > [!NOTE]+ > A target group (for example, Engineering) can be scoped for multiple passkey profiles. When a user is scoped for multiple passkey profiles, registration and authentication with a passkey are allowed if the passkey fully satisfies the requirements of at least one of the scoped passkey profiles. There's no particular order to the check. If a user is a member of an excluded group in the **Passkey (FIDO2)** policy, they're blocked from passkey (FIDO2) registration or sign-in entirely. The block takes precedence over membership in any included groups. - - **iOS**: Authenticator attestation uses the [iOS App Attest service](https://developer.apple.com/documentation/devicecheck/preparing-to-use-the-app-attest-service) to ensure the legitimacy of the Authenticator app before registering the passkey.- - - **Android**:- - For Play Integrity attestation, Authenticator attestation uses the [Play Integrity API](https://developer.android.com/google/play/integrity/overview) to ensure the legitimacy of the Authenticator app before registering the passkey.- - For Key attestation, Authenticator attestation uses [key attestation by Android](https://developer.android.com/privacy-and-security/security-key-attestation) to verify that the passkey being registered is hardware-backed.+## Authenticator attestation - > [!NOTE]- > For both iOS and Android, Authenticator attestation relies upon Apple and Google services to verify the authenticity of the Authenticator app. Heavy service usage can make passkey registration fail, and users might need to try again. If Apple and Google services are down, Authenticator attestation blocks registration that requires attestation until services are restored. To monitor the status of Google Play Integrity service, see [Google Play Status Dashboard](https://status.play.google.com/). To monitor the status of the iOS App Attest service, see [System Status](https://developer.apple.com/system-status/).- +When you enable passkeys and create a passkey profile in the Microsoft Entra admin center, you can choose whether to enforce attestation. For general steps to configure passkey profiles, see [Enable passkeys (FIDO2)](how-to-authentication-passkeys-fido2.md). +When attestation is enabled, Microsoft Entra ID verifies the legitimacy of the passkey being created. When the user is registering a passkey in the Authenticator, attestation verifies that the legitimate Authenticator app created the passkey by using Apple and Google services: - - **Key restrictions** set the usability of specific passkeys for both registration and authentication. You can set **Enforce key restrictions** to **No** to allow users to register any supported passkey, including passkey registration directly in the Authenticator app. If you set **Enforce key restrictions** to **Yes** and already have active passkey usage, you should collect and add the AAGUIDs of the passkeys being used today. +- **iOS**: Authenticator attestation uses the [iOS App Attest service](https://developer.apple.com/documentation/devicecheck/preparing-to-use-the-app-attest-service) to ensure the legitimacy of the Authenticator app before registering the passkey. +- **Android**:+ - For Play Integrity attestation, Authenticator attestation uses the [Play Integrity API](https://developer.android.com/google/play/integrity/overview) to ensure the legitimacy of the Authenticator app before registering the passkey.+ - For Key attestation, Authenticator attestation uses [key attestation by Android](https://developer.android.com/privacy-and-security/security-key-attestation) to verify that the passkey being registered is hardware-backed. - If you set **Restrict specific keys** to **Allow**, select **Microsoft Authenticator** to automatically add the Authenticator app AAGUIDs to the key restrictions list. You can also manually add the following AAGUIDs to allow users to register passkeys in Authenticator by signing in to the Authenticator app or by going through a guided flow on **Security info**:+> [!NOTE]+> For both iOS and Android, Authenticator attestation relies upon Apple and Google services to verify the authenticity of the Authenticator app. Heavy service usage can make passkey registration fail, and users might need to try again. If Apple and Google services are down, Authenticator attestation blocks registration that requires attestation until services are restored. To monitor the status of Google Play Integrity service, see [Google Play Status Dashboard](https://status.play.google.com/). To monitor the status of the iOS App Attest service, see [System Status](https://developer.apple.com/system-status/).++Users can only register attested passkeys directly in the Authenticator app. Cross-device registration flows don't support registration of attested passkeys. - - **Authenticator for Android**: `de1e552d-db1d-4423-a619-566b625cdc84`- - **Authenticator for iOS**: `90a3ccdf-635c-4729-a248-9b709135078f`- - If you change key restrictions and remove an AAGUID that you previously allowed, users who previously registered an allowed method can no longer use it for sign-in.+## Authenticator AAGUIDs - > [!NOTE]- > If you turn off key restrictions, make sure you clear the **Microsoft Authenticator** checkbox so that users aren't prompted to set up a passkey in the Authenticator app on [Security info](https://mysignins.microsoft.com/security-info).+You can restrict users to use Authenticator passkeys by targeting the Authenticator Attestation Globally Unique Identifier (AAGUID) in the passkey profile. - :::image type="content" border="true" source="media/how-to-enable-authenticator-passkey/optional-settings.png" alt-text="Screenshot that shows Authenticator enabled for passkey."lightbox="media/how-to-enable-authenticator-passkey/optional-settings.png":::+If you prefer, you can also select **+ Add AAGUID** and manually add the following AAGUIDs: -1. After you finish the configuration, select **Save**.+- **Authenticator for Android**: `de1e552d-db1d-4423-a619-566b625cdc84`+- **Authenticator for iOS**: `90a3ccdf-635c-4729-a248-9b709135078f` - If you see an error when you try to save, replace multiple groups with a single group in one operation, and then select **Save** again.+If you remove an AAGUID that you previously allowed, users who previously registered an allowed method can no longer use it for sign-in. ## Enable passkeys in Authenticator by using Graph Explorer -In addition to using the Microsoft Entra admin center, you can also enable passkeys in Authenticator by using Graph Explorer. If you're assigned at least the [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator) role, you can update the Authentication methods policy to allow the AAGUIDs for Authenticator.+In addition to using the Microsoft Entra admin center, you can enable passkeys in Authenticator by using Graph Explorer. If you're assigned at least the [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator) role, you can update the Authentication methods policy to allow the AAGUIDs for Authenticator.++> [!NOTE]+> The following example uses the tenant-level FIDO2 configuration endpoint. For the profile-based approach to passkey management, see [Enable passkeys (FIDO2)](how-to-authentication-passkeys-fido2.md). To configure the policy by using Graph Explorer: @@ -89,7 +118,7 @@ To configure the policy by using Graph Explorer: GET https://graph.microsoft.com/v1.0/authenticationMethodsPolicy/authenticationMethodConfigurations/FIDO2 ``` -1. To disable attestation enforcement and enforce key restrictions to allow only AAGUIDs for Authenticator, perform a `PATCH` operation by using the following request body:+1. To enable attestation enforcement and enforce key restrictions to allow only AAGUIDs for Authenticator, perform a `PATCH` operation by using the following request body: ```json PATCH https://graph.microsoft.com/v1.0/authenticationMethodsPolicy/authenticationMethodConfigurations/FIDO2@@ -122,32 +151,95 @@ To configure the policy by using Graph Explorer: Some organizations restrict Bluetooth usage, which includes the use of passkeys. In such cases, organizations can allow passkeys by permitting Bluetooth pairing exclusively with passkey-enabled FIDO2 authenticators. For more information about how to configure Bluetooth usage only for passkeys, see [Passkeys in Bluetooth-restricted environments](/windows/security/identity-protection/passkeys/?tabs=windows%2Cintune#passkeys-in-bluetooth-restricted-environments). -## Delete a passkey+## Troubleshoot passkeys in Authenticator++This section covers issues that users might see when they use passkeys in Authenticator and possible ways for administrators to resolve them.++### Store passkeys in Android profiles++Passkeys on Android are used only from the profile where they're stored. If a passkey is stored in an Android Work profile, it's used from that profile. If a passkey is stored in an Android Personal profile, it's used from that profile. To make sure that users can access and use the passkey they need, users with both an Android Personal profile and an Android Work profile should create their passkeys in Authenticator for each profile.++### Workarounds for an authentication strength Conditional Access policy loop++Users can get in a loop when they try to add a passkey in Authenticator if a Conditional Access policy requires phishing-resistant authentication to access **All resources (formerly 'All cloud apps')**. For example: -If a user deletes a passkey in Authenticator, the passkey is also removed from the user's sign-in methods. An Authentication Policy Administrator can also follow these steps to delete a passkey from the user's authentication methods, but it won't remove the passkey from Authenticator.+- Condition: **All devices (Windows, Linux, macOS, Windows, Android)**+- Targeted resource: **All resources (formerly 'All cloud apps')**+- Grant control: **Authentication strength – Require passkey in Authenticator** -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com), and search for the user whose passkey must be removed.-1. Select **Authentication methods**, right-click **Passkey**, and select **Delete**.+The policy forces targeted users to use a passkey to sign in to all cloud applications, which includes the Authenticator app. It requires users to use a passkey when they try to add a passkey in Authenticator on either Android or iOS.++Here are some workarounds:++- You can [filter for applications](~/identity/conditional-access/concept-filter-for-applications.md) and transition the policy target from **All resources (formerly 'All cloud apps')** to specific applications. Start with a review of applications that are used in your tenant. Use filters to tag Authenticator and other applications.+- To further reduce support costs, you can run an internal campaign to help users adopt passkeys before you enforce them. When you're ready to enforce passkey usage, create two Conditional Access policies:++ - A policy for mobile operating system (OS) versions+ - A policy for desktop OS versions++ Require a different authentication strength for each policy, and configure other policy settings listed in the following table. You can enable a [Temporary Access Pass (TAP)](howto-authentication-temporary-access-pass.md) for users or enable other authentication methods to help users register the passkey.+ + A TAP limits the time when users can register a passkey. You can accept it only on mobile platforms where you allow passkey registration.++ | Conditional Access policy | Desktop OS | Mobile OS |+ |---------------------------|----------------|---------------|+ | Name | Require a passkey in Authenticator to access a desktop OS. | Require a TAP, a phishing-resistant credential, or any other specified authentication method to access a mobile OS. |+ | Condition | Specific devices (desktop operating systems). | Specific devices (mobile operating systems). |+ | Devices | N/A. | Android, iOS. | + | Exclude devices | Android, iOS. | N/A. |+ | Targeted resource | All resources. | All resources. |+ | Grant control | Authentication strength. | Authentication strength.<sup>1</sup> |+ | Methods | Passkey in Authenticator. |TAP, passkey in Authenticator. |+ | Policy result | Users who can't sign in with a passkey in Authenticator are directed to the **My Sign-ins** wizard mode. After registration, they're asked to sign in to Authenticator on their mobile device. | Users who sign in to Authenticator with a TAP or another allowed method can register a passkey directly in Authenticator. No loop occurs because the user meets the authentication requirements. |++ <sup>1</sup>For users to register new sign-in methods, your grant control for the mobile policy needs to match your Conditional Access policy to register [Security info](https://mysignins.microsoft.com/security-info).++> [!NOTE]+> With either workaround, users must also satisfy any Conditional Access policy that targets **Register security info** or they can't register the passkey. If you have other conditions set up with the **All resources** policies, those conditions must be met when the passkey is registered.++### Users who can't register passkeys because of Require approved client app or Require app protection policy Conditional Access grant controls++Users can't register passkeys in Authenticator if they're included in the following Conditional Access policy:++- Condition: **All devices (Windows, Linux, macOS, Windows, Android)**+- Targeted resource: **All resources (formerly 'All cloud apps')**+- Grant control: **Require approved client app** or **Require app protection policy**++The policy forces users to sign in to all cloud applications by using an app that supports [Microsoft Intune app protection policies](/mem/intune/apps/app-protection-policy). Authenticator doesn't support this policy on either Android or iOS.++Here are some workarounds:++- You can [filter for applications](~/identity/conditional-access/concept-filter-for-applications.md) and transition the policy target from **All resources (formerly 'All cloud apps')** to specific applications. Start with a review of applications that are used in your tenant. Use filters to tag appropriate applications.+- You can use mobile device management (MDM) and the **Require device to be marked as compliant** control. Authenticator can satisfy this grant control if MDM fully manages the device and it's compliant. For example:++ - Condition: **All devices (Windows, Linux, macOS, Windows, Android)**+ - Targeted resource: **All resources (formerly 'All cloud apps')**+ - Grant control: **Require approved client app**, or **Require app protection policy**, or **Require device to be marked as compliant**++- You can grant users a temporary exemption from the Conditional Access policy. Consider using one or more compensating controls:+ - Allow the exemption for only a limited period of time. Communicate to the user when they're allowed to register a passkey. Remove the exemption after the time period. Then direct users to call the help desk if they missed their time.+ - Use another Conditional Access policy to require that users register only from a specific network location or a compliant device.++> [!NOTE]+> With any proposed workaround, users must also satisfy any Conditional Access policy that targets **Register security info** or they can't register the passkey. If you have other conditions set up with the **All resources** policies, they also must be met before users can register a passkey. - Unless the user initiated the passkey deletion themselves in Authenticator, they need to also remove the passkey in Authenticator on their device.+## Register a passkey in Authenticator -## Enforce sign-in with passkeys in Authenticator+After an admin enables passkeys in Authenticator, users can register a passkey in the app on their iOS or Android device. -To make users sign in with a passkey when they access a sensitive resource, use the built-in phishing-resistant authentication strength, or create a custom authentication strength by following these steps:+For registration steps, see [Register a passkey in Microsoft Authenticator](how-to-register-passkey-authenticator.md). -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a Conditional Access Administrator.-1. Browse to **Entra ID** > **Authentication methods** > **Authentication strengths**.-1. Select **New authentication strength**.-1. Provide a descriptive name for your new authentication strength.-1. Optionally, provide a description.-1. Select **Passkeys (FIDO2)**, and then select **Advanced options**.-1. Select **Phishing-resistant MFA strength** or add AAGUIDs for passkeys in Authenticator:+## Sign in with a passkey in Authenticator - - **Authenticator for Android**: `de1e552d-db1d-4423-a619-566b625cdc84`- - **Authenticator for iOS**: `90a3ccdf-635c-4729-a248-9b709135078f`+After registration, users can sign in to Microsoft Entra ID by using the passkey in Authenticator on their device. -1. Select **Next**, and review the policy configuration.+For sign-in steps, see [Sign in with passkeys in Authenticator](how-to-sign-in-passkey-authenticator.md). ## Related content +- [Enable passkeys (FIDO2) in Microsoft Entra ID](how-to-authentication-passkeys-fido2.md)+- [Register a passkey in Microsoft Authenticator](how-to-register-passkey-authenticator.md)+- [Sign in with passkeys in Authenticator](how-to-sign-in-passkey-authenticator.md)+- [Microsoft Authenticator authentication method](concept-authentication-authenticator-app.md)+- [Support for FIDO2 authentication with Microsoft Entra ID](concept-fido2-compatibility.md) - [Support for passkey in Windows](/windows/security/identity-protection/passkeys) 