Microsoft Entra ID will support device-bound passkeys stored on computers and mobile devices as an authentication method in preview, in addition to the existing support for FIDO2 security keys, beginning mid-March 2024. Admins will need to enforce key restrictions to allow specified passkey providers in their FIDO2 policy. The end user sign-in option for Windows Hello for Business and FIDO2 security keys will be renamed to "Face, fingerprint, PIN, or security key" and the term "passkey" will be mentioned in the updated sign-in experience to be inclusive of passkey credentials presented from security keys, computers, and mobile devices.
Entra ID prepares a device-bound passkey preview, with FIDO2 policy and sign-in changes
The period’s sole supplied item is a Microsoft 365 Message Center notice about a substantive Entra ID authentication change, not a general-availability announcement or a documentation clarification. Beginning in mid-March 2024, Entra ID is expected to add preview support for device-bound passkeys stored on computers and mobile devices alongside existing FIDO2 security-key support. The rollout also changes FIDO2 policy handling and makes the end-user sign-in terminology cover passkeys from all supported device types.
- Device-bound passkeys enter Entra ID as a preview authentication method
Entra ID · Conditional Access
Starting in mid-March 2024, Entra ID will support device-bound passkeys stored on computers and mobile devices, in addition to its existing support for FIDO2 security keys. The notice identifies this as a preview; it does not establish general availability.
- FIDO2 policy must permit the intended passkey providers
Entra ID · Conditional Access
To allow specified passkey providers, administrators will need to enforce key restrictions in the FIDO2 policy. This is the concrete configuration impact of extending supported credentials beyond security keys.
- The Windows Hello for Business and FIDO2 sign-in label becomes more inclusive
Entra ID · Conditional Access
The end-user option will be renamed to "Face, fingerprint, PIN, or security key." The updated sign-in experience will also use the term "passkey" so the wording covers passkey credentials presented from security keys, computers, and mobile devices.
Administrators will need to enforce key restrictions in the FIDO2 policy to allow the passkey providers they intend to support. They should also expect the Windows Hello for Business and FIDO2 sign-in option to use new, broader wording. The supplied notice does not state that existing FIDO2 security-key support is being retired or that a migration is required.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
