Sign In With Passkey
In brief
The documentation now describes a sample where signed-in customers list and register their own passkeys. It warns that the deletion flow uses high-privilege permissions and a client secret, so the sample is for test tenants only.
What Entra admins need to know
No action is required. Administrators should not deploy this sample to production.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
ms.topic: how-to
author: mmacy-msft
ms.author: marshmacy
ms.date: 10/02/05/2026
ai-usage: ai-assisted
ms.custom: it-pro, msecd-doc-authoring-1030
#Customer intent: As a developer or IT admin, I want to enable passkey (FIDO2) sign-in for my external tenant so that customers can use phishing-resistant, passwordless authentication.
- View their registered passkeys.
- Delete a passkey.
TheTo support passkey management in your app, use the passkey credential management sample app demonstrates administrator-controlled provisioning with high-privilege application permissions.. The sample is intended for testing onlydemonstrates how signed-in customers can list and isnregister their own passkeys by using the credential management API with delegated permissions. Follow the sample't an implementation model for customer self-service.s README to configure and run the app.
User experience
User experience
@@ -5,7 +5,7 @@ ms.service: entra-external-id ms.topic: how-to author: mmacy-msft ms.author: marshmacy-ms.date: 10/02/2026+ms.date: 10/05/2026 ai-usage: ai-assisted ms.custom: it-pro, msecd-doc-authoring-1030 #Customer intent: As a developer or IT admin, I want to enable passkey (FIDO2) sign-in for my external tenant so that customers can use phishing-resistant, passwordless authentication.@@ -85,7 +85,10 @@ The credential management experience should enable customers to: - View their registered passkeys. - Delete a passkey. -The [Microsoft Graph passkey sample](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/tree/main/passkey-sample) demonstrates administrator-controlled provisioning with high-privilege application permissions. The sample is intended for testing only and isn't an implementation model for customer self-service.+To support passkey management in your app, use the [passkey credential management sample app](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/tree/main/passkey-sample). The sample demonstrates how signed-in customers can list and register their own passkeys by using the credential management API with delegated permissions. Follow the sample's README to configure and run the app.++> [!IMPORTANT]+> The sample's deletion flow still uses Microsoft Graph with high-privilege application permissions and a client secret in browser code. Run the sample only in a test tenant. Don't deploy it to production. ## User experience 