Microsoft Entra ID will support device-bound passkeys stored on computers and mobile devices as an authentication method in preview, in addition to the existing support for FIDO2 security keys, beginning mid-March 2024. Admins will need to enforce key restrictions to allow specified passkey providers in their FIDO2 policy. The end user sign-in option for Windows Hello for Business and FIDO2 security keys will be renamed to "Face, fingerprint, PIN, or security key" and the term "passkey" will be mentioned in the updated sign-in experience to be inclusive of passkey credentials presented from security keys, computers, and mobile devices.
Entra ID plans a mid-March preview of device-bound passkeys, with FIDO2 policy and sign-in changes
February’s substantive Entra item is a Microsoft 365 Message Center notice, not a general-availability announcement or a documentation clarification. It says Microsoft Entra ID will begin preview support in mid-March 2024 for device-bound passkeys stored on computers and mobile devices, alongside existing FIDO2 security-key support. The change also introduces FIDO2 policy handling requirements and broadens end-user sign-in terminology.
- Device-bound passkeys enter preview as an additional authentication methodMicrosoft Entra ID authentication
Beginning in mid-March 2024, Microsoft Entra ID is expected to support passkeys stored on computers and mobile devices in preview. This adds to, rather than replaces, the existing support for FIDO2 security keys; the supplied notice does not describe this as a general-availability release.
- FIDO2 key restrictions will control permitted passkey providersMicrosoft Entra ID FIDO2 policy
The notice says administrators will need to enforce key restrictions in the FIDO2 policy to allow specified passkey providers. It does not identify the providers or provide additional policy parameters.
- Windows Hello and FIDO2 sign-in wording becomes broaderWindows Hello for Business and FIDO2 sign-in experience
The end-user option for Windows Hello for Business and FIDO2 security keys will be renamed to “Face, fingerprint, PIN, or security key.” The updated experience will also mention “passkey” so the terminology covers credentials presented from security keys, computers, and mobile devices.
Administrators will need to enforce key restrictions in the FIDO2 policy to allow the passkey providers they intend to support. They should also expect the Windows Hello for Business and FIDO2 sign-in option to be renamed and the sign-in experience to use broader passkey terminology. The notice does not state that existing FIDO2 security-key support is being retired or that migration is required.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
