Microsoft Entra ID
Standards

Single Sign On Saml Protocol

In brief

The documentation now labels synced passkeys as phishing-resistant MFA and clarifies that this designation for certificate-based authentication applies to multi-factor CBA. The associated SAML mappings are unchanged.

What Entra admins need to know

Use the updated terminology when interpreting SAML authentication context values; no administrator action is indicated.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

| Email | MobileOneFactorUnregistered, or MobileTwoFactorContract when another factor is also completed | One-time passcode delivered by email. | | FIDO2 security key (phishing-resistant MFA) | SmartcardPKI | A FIDO2 security key, reported as a smartcard-backed certificate with a private key and PIN. | | Passkey - device-bound (phishing-resistant MFA) | SmartcardPKI | A device-bound passkey. | | Passkey - synced (phishing-resistant MFA)| SoftwarePKI | A synced passkey, reported as a software-based PKI credential. | | Windows Hello for Business (phishing-resistant MFA) | SmartcardPKI | Windows Hello for Business. | | Certificate-based authentication (phishing-resistant MFA)MFA for multi-factor CBA) | SmartcardPKI when used as MFA; X509 for single-factor CBA | Certificate-based authentication (CBA). | | Temporary Access Pass (TAP) | Unspecified | A Temporary Access Pass. | | Windows Integrated Authentication (Kerberos) | Kerberos | Windows Integrated Authentication. | | Device based X509 authentication | X509 | A certificate on the device proves the device's identity | | Email | otp, plus multipleauthn when MFA is completed with another factor | One-time passcode delivered by email. | | FIDO2 security key (phishing-resistant MFA) | fido, multipleauthn | A FIDO2 security key. | | Passkey - device-bound (phishing-resistant MFA) | fido, multipleauthn | A device-bound passkey. | | Passkey - synced (phishing-resistant MFA)| fido, multipleauthn | A synced passkey. | | Windows Hello for Business (phishing-resistant MFA) | hwk, multipleauthn | Windows Hello for Business, reported as a hardware-bound key. | | Certificate-based authentication (phishing-resistant MFA)MFA for multi-factor CBA) | x509, plus multipleauthn (default for multifactor CBA, or when MFA is completed with another factor for single-factor CBA) | Certificate-based authentication. | | Temporary Access Pass (TAP) | otp, multipleauthn | A Temporary Access Pass. | | Windows Integrated Authentication (Kerberos) | wia | Windows Integrated Authentication. | | Device based X509 authentication | x509 | A certificate on the device proves the device's identity |

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…