Microsoft Entra ID
Authentication

Deploy Phishing Resistant Passwordless Authentication

In brief

The documentation corrects an internal section link and improves grammar, spelling, punctuation, and wording throughout the rollout guidance.

What Entra admins need to know

No administrator action is indicated; existing guidance and configurations are unchanged.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create this policy as early as possible in your rollout, preferably before even beginning your enrollment campaigns. This will ensure that you have a good historical dataset of which users and sign-ins would have been blocked by the policy if it was enforced.

Next, use the workbook to analyze where user/device pairs are ready for enforcement. Download lists of users who are ready for enforcement and add them to groups created in alignment with your enforcement policiesenforcement policies. Begin by selecting the read-only Conditional Access policy in the policy filter:

:::image type="content" border="true" source="media/how-to-deploy-phishing-resistant-passwordless-authentication/workbook-enforcement-policy-selection-1.png" alt-text="Screenshot of the Enforcement phase of the Phishing-Resistant Passwordless workbook with a report-only Conditional Access policy selected." lightbox="media/how-to-deploy-phishing-resistant-passwordless-authentication/workbook-enforcement-policy-selection-1.png":::

  1. 7 days out from enforcement: repeat message, inform them of how to contact the help desk
  2. 1 day out from enforcement: inform them enforcement will occur in 24 hours, inform them of how to contact the help desk

Microsoft recommends communicating towith users through other channels beyond just email. Other options may include Microsoft Teams messages, break room posters, and champion programs where select employees are trained to advocate for the program to their peers.

Reporting and monitoring

Use the previously covered Phishing-Resistant Passwordless Workbook to assist with monitoring and reporting on your rollout. AdditionallyAdditionally, use the reports discussed below, or rely on them if you cannot use the Phishing-Resistant Passwordless Workbook.

Microsoft Entra ID reports (such as Authentication Methods Activity and Sign-in event details for Microsoft Entra multifactor authentication) provide technical and business insights that can help you measure and drive adoption.

From the Authentication methods activity dashboard, you can view registration and usage.

  • Registration shows the number of users capable of phishing-resistant passwordless authentication, and other authentication methods. You can see graphs that show which authentication methods users registered, and recent registrationregistrations for each method.
  • Usage shows which authentication methods were used for sign-in.

Business and technical application owners should own and receive reports based on organization requirements.

  • Track phishing-resistant passwordless credentials rollout with Authentication Methods registration activity reports.
  • Track user adoption of phishing-resistant passwordless credentials with Authentication Methods sign sign-in activity reports and sign sign-in logs.
  • Use the sign-in activity report to track the authentication methods used to sign in to the various applications. Select the user row; select Authentication Details to view the authentication method and its corresponding sign-in activity.

Microsoft Entra ID adds entries to audit logs when these conditions occur:

  1. Any other user on iOS and Android

Microsoft recommends that you build a report of all your user/device pairs by using sign-in data from your tenant. You can use querying tools like Azure Monitor and Workbooks. At a minimum, try to identify all user/device pairs that match these categories.

Use the previously covered Phishing-Resistant Passwordless Workbook to assist with the enforcement phase, if possible.

Create a set of Microsoft Entra ID groups to roll out enforcement gradually. Reuse the groups from the previous step if you used the wave-based rollout approach.

Recommended enforcement of Conditional Access policies

Target each group with a specific Conditional Access policy. This approach helps you roll out your enforcement controls gradually by user/device pair.

Microsoft Entra ID Protection helps organizations detect, investigate, and remediate identity-based risks. Microsoft Entra ID Protection provides important and useful detections for your users even after they switch to using phishing-resistant passwordless credentials. For example, some relevant detections for phishing-resistant users include:

  • Activity from an anonymous IP address
  • Admin confirmed user compromised
  • Anomalous Token
  • Malicious IP address
  1. Review the Microsoft Entra ID Protection deployment guidance: Plan an ID Protection deployment
  2. Configure your risk logs to export to a SIEM
  3. Investigate and act on any medium user risk
  4. Configure a Conditional Access policy to block high high-risk users

After you deploy Microsoft Entra ID Protection, consider using Conditional Access token protection. As users sign in with phishing-resistant passwordless credentials, attacks and detections continue to evolve. For example, when user credentials can no longer be easily phished, attackers may move on to try to exfiltrate tokens from user devices. Token protection helps mitigate this risk by binding tokens to the hardware of the device they were issued to.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…