Microsoft Entra ID

Register a synced passkey (FIDO2)

In brief

Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

Register a synced passkey (FIDO2)

This article shows how users can register a synced passkey (FIDO2) by using the Passkey flow. A synced passkey is stored in a passkey provider (such as iCloud Keychain or Google Password Manager) and syncs across the user's devices. For registration on a mobile device,an overview of synced passkeys, see Register a passkey using a mobile deviceSynced passkeys in Microsoft Entra ID.

Prerequisites

You need to configure a password manager on your mobile device to save a synced passkey.

  • On your iOS device, you need to set Set Up Codes In to Passwords to manage synced passkeys. Open Settings > General > AutoFill & Passwords. For more information about enabling passkeys in Microsoft Authenticator, see How to enable passkeys in Microsoft AuthenticatorSet Up Codes In, select Passwords.
  • On your Android device, open Settings > Security and privacy > More security settings > Passwords, passkeys, and autofill, and then select a provider.

Manual registrationRegister a passkey

  1. Users canTo register a passkey (FIDO2) as an authentication method by navigatingon your device, follow these steps:

    1. Open a web browser and completing the process from a browser at Security info.

    2. Tap Add sign-sign in method > Choose a method > Passkey > Addto Security info.

    3. Sign in with multifactor authentication (MFA) before adding a passkey, then tap.

    4. Tap Next+ Add sign-in method.

      1. If you don't have at least one MFA method registered, you must add one.
      2. An Authentication Policy Administrator can also issue a Temporary Access Pass to allow a user to strongly authenticate and register a passkey.

      :: :::image type="content" source="media/how-to-register-passkey/add-sign-in-method-ios.png" alt-text="Screenshot of the Security info page on iOS showing the Add sign-in method option." border="true" lightbox="media/how-to-register-passkey/add-sign-in-method-ios.png":::

    5. Tap Passkey.

      :::image type="content" source="media/how-to-register-passkey/choose-passkey-android-or-ios/add-passkey.ios.png" alt-text="Screenshot of the Add a passkeysign-in method page on your iOS or Android deviceshowing the Passkey option." border="true" lightbox="media/how-to-register-passkey/choose-passkey-ios.png":::

    6. A security dialog opensTap Next.

      :::image type="content" source="media/how-to-register-passkey/sign-in-faster-ios.png" alt-text="Screenshot of the Sign in faster with your face, fingerprint, or PIN page on iOS showing the Next option." border="true" lightbox="media/how-to-register-passkey/sign-in-faster-ios.png":::

    7. On iOS, tap Next.

      :::image type="content" source="media/how-to-register-passkey/setting-up-passkey-ios.png" alt-text="Screenshot of the Setting up your device and asks where to save your passkey.passkey page on iOS showing the Next option." border="true" lightbox="media/how-to-register-passkey/setting-up-passkey-ios.png":::

      On Android, tap Continue.

    :::image type="content" source="media/how-to-register-passkey/android-complete.png" alt-text="Screenshot of the Create a passkey page on Android showing the account name and Continue option." border="true" lightbox="media/how-to-register-passkey/android-complete.png":::
    
    1. Name your passkey and tap Next.

      :::image type="content" source="media/how-to-register-passkey/name-passkey.png" alt-text="Screenshot of the Let's name your passkey page showing the passkey name field and Next option." border="true" lightbox="media/how-to-register-passkey/name-passkey.png":::

    2. After the passkey is created, tap Done.

      :::image type="content" source="media/how-to-register-passkey/passkey-created-ios.png" alt-text="Screenshot of the Passkey created page showing the Done option." border="true" lightbox="media/how-to-register-passkey/passkey-created-ios.png":::

    3. You can see your passkey in Security info.

      :::image type="content" source="media/how-to-register-passkey/passkey-added-ios.png" alt-text="Screenshot of the Security info page showing the registered passkey." border="true" lightbox="media/how-to-register-passkey/passkey-added-ios.png":::

    Related content

    To register a passkey on a different type of authenticator, see: