MondayMon
TuesdayTue
WednesdayWed
ThursdayThu
FridayFri
SaturdaySat
SundaySun
22232425261Entra ID272829303112345678910111213141516171819201Entra ID212223242526272829123
Month in brief

Entra ID plans a mid-March preview of device-bound passkeys, with FIDO2 policy and sign-in changes

February’s substantive Entra item is a Microsoft 365 Message Center notice, not a general-availability announcement or a documentation clarification. It says Microsoft Entra ID will begin preview support in mid-March 2024 for device-bound passkeys stored on computers and mobile devices, alongside existing FIDO2 security-key support. The change also introduces FIDO2 policy handling requirements and broadens end-user sign-in terminology.

  • Device-bound passkeys enter preview as an additional authentication methodMicrosoft Entra ID authentication

    Beginning in mid-March 2024, Microsoft Entra ID is expected to support passkeys stored on computers and mobile devices in preview. This adds to, rather than replaces, the existing support for FIDO2 security keys; the supplied notice does not describe this as a general-availability release.

  • FIDO2 key restrictions will control permitted passkey providersMicrosoft Entra ID FIDO2 policy

    The notice says administrators will need to enforce key restrictions in the FIDO2 policy to allow specified passkey providers. It does not identify the providers or provide additional policy parameters.

  • Windows Hello and FIDO2 sign-in wording becomes broaderWindows Hello for Business and FIDO2 sign-in experience

    The end-user option for Windows Hello for Business and FIDO2 security keys will be renamed to “Face, fingerprint, PIN, or security key.” The updated experience will also mention “passkey” so the terminology covers credentials presented from security keys, computers, and mobile devices.

For Entra administrators

Administrators will need to enforce key restrictions in the FIDO2 policy to allow the passkey providers they intend to support. They should also expect the Windows Hello for Business and FIDO2 sign-in option to be renamed and the sign-in experience to use broader passkey terminology. The notice does not state that existing FIDO2 security-key support is being retired or that migration is required.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

1 updates by product

Authentication

1

Prepare for device-bound passkeys in Microsoft Entra ID (changes to FIDO2 and Windows Hello for Business)

New

Microsoft Entra ID will support device-bound passkeys stored on computers and mobile devices as an authentication method in preview, in addition to the existing support for FIDO2 security keys, beginning mid-March 2024. Admins will need to enforce key restrictions to allow specified passkey providers in their FIDO2 policy. The end user sign-in option for Windows Hello for Business and FIDO2 security keys will be renamed to "Face, fingerprint, PIN, or security key" and the term "passkey" will be mentioned in the updated sign-in experience to be inclusive of passkey credentials presented from security keys, computers, and mobile devices.

20 February 2024
Message CenterMC690185 on mc.merill.net ↗Stay informed