Microsoft Entra External ID
Authentication

Sign In With Passkey

In brief

The documentation now directs applications to use the credential management API, with low-privilege delegated permissions, so signed-in customers can list and register their own passkeys.

What Entra admins need to know

No administrator action is required. Application teams can use the new API guidance for customer passkey management.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Step 3: Build a passkey management experience for your application

Your application needs a credential management experience so signed-in customers can register and manage their own passkeys. Use the FIDO2 provisioning APIscredential management API to build this into your app.experience with low-privilege delegated permissions.

The credential management experience should enable customers to:

Are there low-privilege APIs for building a credential management experience?

Not yet. Low-privilege credential management APIs forYes. Use the credential management API to let signed-in customers list and register their own passkeys are on the roadmap. Currently, use the FIDO2 provisioning APIs to build your credential management experience.with delegated permissions.

Can I use the same passkey across multiple domains (related origins)?

Is there an out-of-box passkey registration experience?

No. Microsoft doesn't currently provide a built-in passkey registration experience for external tenants. Build a credential management experience in your application by using the FIDO2 provisioning APIscredential management API.

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…