Microsoft Entra ID

Register a Microsoft Entra passkey on Windows (preview)

In brief

Learn how to register a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant sign-in.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

new file mode 100644

title: Register a Microsoft Entra passkey on Windows (preview) description: Learn how to register a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant sign-in. ms.topic: how-to ms.date: 07/05/2026 ms.reviewer: kimhana ms.collection: M365-identity-device-management ai-usage: ai-assisted ms.custom: msecd-doc-authoring-1013 # Customer intent: As a user, I want to register a Microsoft Entra passkey on Windows so I can use phishing-resistant authentication on my Windows device.

Register a Microsoft Entra passkey on Windows (preview)

This article shows how to register a Microsoft Entra passkey on Windows. A Microsoft Entra passkey on Windows is a device-bound passkey stored in the local Windows Hello container. Unlike synced passkeys, a passkey on Windows doesn't sync across devices — each device requires a separate passkey registration. This approach enables phishing-resistant sign-in with a Windows Hello biometric or PIN, without requiring the device to be Microsoft Entra joined or registered.

For an overview of Microsoft Entra passkey on Windows and how it compares with Windows Hello for Business, see Microsoft Entra passkey on Windows.

Prerequisites

Confirm these requirements before you register:

  • Your administrator enabled passkeys (FIDO2) and created a passkey profile that allows Windows Hello AAGUIDs. For configuration steps, see Configure a profile for Microsoft Entra passkey on Windows.
  • The device runs a supported version of Windows.
  • Attestation must not be enforced in the passkey profile.

For the list of supported Windows Hello passkey AAGUIDs, see Supported Windows Hello passkey AAGUIDs.

Register a passkey on Windows

To register a passkey on your Windows device, follow these steps:

  1. Open a web browser and sign in to Security info.

  2. Sign in with multifactor authentication (MFA).

  3. Tap Add sign-in method > Choose a method > Passkey.

  4. Tap Next.

  5. Select where you want to save your passkey (FIDO2).

:::image type="content" border="true" source="media/how-to-register-passkey-with-security-key/choose-where-store-passkey.png" alt-text="Screenshot of the dialog where to save your passkey (FIDO2) in My Security info.":::

After verification, Windows creates the passkey and stores it in the local Windows Hello container. You can now use this passkey to sign in to Microsoft Entra ID.

Related content