Microsoft Entra External ID
Authentication

Sign In With Passkey

In brief

The documentation now describes a sample where signed-in customers list and register their own passkeys. It warns that the deletion flow uses high-privilege permissions and a client secret, so the sample is for test tenants only.

What Entra admins need to know

No action is required. Administrators should not deploy this sample to production.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.topic: how-to author: mmacy-msft ms.author: marshmacy ms.date: 10/02/05/2026 ai-usage: ai-assisted ms.custom: it-pro, msecd-doc-authoring-1030 #Customer intent: As a developer or IT admin, I want to enable passkey (FIDO2) sign-in for my external tenant so that customers can use phishing-resistant, passwordless authentication.

  • View their registered passkeys.
  • Delete a passkey.

TheTo support passkey management in your app, use the passkey credential management sample app demonstrates administrator-controlled provisioning with high-privilege application permissions.. The sample is intended for testing onlydemonstrates how signed-in customers can list and isnregister their own passkeys by using the credential management API with delegated permissions. Follow the sample't an implementation model for customer self-service.s README to configure and run the app.

User experience

User experience

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…