Week in brief

Entra ID prepares a device-bound passkey preview, with FIDO2 policy and sign-in changes

The period’s sole supplied item is a Microsoft 365 Message Center notice about a substantive Entra ID authentication change, not a general-availability announcement or a documentation clarification. Beginning in mid-March 2024, Entra ID is expected to add preview support for device-bound passkeys stored on computers and mobile devices alongside existing FIDO2 security-key support. The rollout also changes FIDO2 policy handling and makes the end-user sign-in terminology cover passkeys from all supported device types.

For Entra administrators

Administrators will need to enforce key restrictions in the FIDO2 policy to allow the passkey providers they intend to support. They should also expect the Windows Hello for Business and FIDO2 sign-in option to use new, broader wording. The supplied notice does not state that existing FIDO2 security-key support is being retired or that a migration is required.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

1

Prepare for device-bound passkeys in Microsoft Entra ID (changes to FIDO2 and Windows Hello for Business)

New

Microsoft Entra ID will support device-bound passkeys stored on computers and mobile devices as an authentication method in preview, in addition to the existing support for FIDO2 security keys, beginning mid-March 2024. Admins will need to enforce key restrictions to allow specified passkey providers in their FIDO2 policy. The end user sign-in option for Windows Hello for Business and FIDO2 security keys will be renamed to "Face, fingerprint, PIN, or security key" and the term "passkey" will be mentioned in the updated sign-in experience to be inclusive of passkey credentials presented from security keys, computers, and mobile devices.

20 February 2024
Message CenterMC690185 on mc.merill.net ↗Stay informed