Enable Microsoft Entra passkey on Windows (preview)
In brief
Learn how Microsoft Entra passkey on Windows enables phishing-resistant authentication with work or school accounts by using Windows Hello as a FIDO2 passkey provider.
Documentation change
Enable Microsoft Entra passkey on Windows
Enable Microsoft Entra passkey on Windows (preview)
This article describes Microsoft Entra passkey on Windows. It covers how they work, how they differ from Windows Hello for Business, and how to configure passkey profiles to allow Windows Hello as a passkey provider.
This article describes Microsoft Entra passkey on Windows, how it works, and how it differs from Windows Hello for Business.
To configure passkey profiles that allow Windows Hello as a FIDO2 passkey provider, see Configure a profile for Microsoft Entra passkey on Windows.
Overview
Microsoft Entra passkey on Windows allows users to register passkeys (FIDO2) directly into their device's local Windows Hello container and use them to sign in to Microsoft Entra ID. Microsoft Entra passkey on Windows enables phishing-resistant sign-in by using a Windows Hello biometric or PIN without requiring the device to be Microsoft Entra joined or registered.
Microsoft Entra passkey on Windows allows users to register passkeys (FIDO2) directly into their device's local Windows Hello container. Users can then use these passkeys to sign in to Microsoft Entra ID. Microsoft Entra passkey on Windows enables phishing-resistant sign-in by using a Windows Hello biometric or PIN without requiring the device to be Microsoft Entra joined or registered.
By using Microsoft Entra passkey on Windows:
Microsoft Entra passkey on Windows allows passkeys (FIDO2) to be created and stored inside this Windows Hello container and used for authentication to Microsoft Entra ID.
This behavior also applies when the device is governed by Windows Hello for Business policies configured through Microsoft Intune. However, passkeys (FIDO2) are distinct from the Windows Hello for Business credentials that may be automatically registered during device registration to Microsoft Entra ID.
This behavior also applies when the device is governed by Windows Hello for Business policies configured through Microsoft Intune. However, passkeys (FIDO2) are distinct from the Windows Hello for Business credentials that might be automatically registered during device registration to Microsoft Entra ID.
How Microsoft Entra passkey on Windows compares with Windows Hello for Business
Although both features use Windows Hello, Microsoft Entra passkey on Windows and Windows Hello for Business have different purposes and behavior.
Windows Hello for Business
- Windows Hello for Business credentials are automatically provisioned on some Microsoft Entra joined or registered devices during device registration.
- The credential is tied only to the Microsoft Entra account used to register the device.
- Windows Hello for Business credentials are passkeys using a first-party (1P) protocol, but not FIDO2 passkeys.
- Windows Hello for Business enables device sign-in using facial recognition, fingerprint, or PIN protected by Windows Hello.
- Windows Hello for Business provides single sign-on (SSO) to Microsoft Entra-integrated resources after device sign-in.
- Windows Hello for Business is primarily a device-bound sign-in method linked to device trust.
- Registration and authentication aren't controlled by the Microsoft Entra Authentication Methods Passkey (FIDO2) policy.
Microsoft Entra passkey on Windows
- Microsoft Entra passkey on Windows is a FIDO2 passkey.
- They can be registered without device join or registration.
- Users can register multiple passkeys for multiple Microsoft Entra accounts on the same device.
- Registration and authentication are managed by the Passkey (FIDO2) policy in Microsoft Entra ID Authentication methods.
- They can't be used for device sign-in.
| Feature | Microsoft Entra passkey on Windows | Windows Hello for Business |
|---|---|---|
| Standard base | FIDO2 | FIDO2 for authentication, first-party (1P) protocol for device sign-in |
| Credential binding | Bound to the device and stored in the local Windows Hello container. Users can register multiple passkeys for multiple work or school accounts on the same device. | Primarily a device-bound sign-in method linked to device trust. The credential is tied only to the work or school account used to register the device. |
| Management | Microsoft Entra ID Authentication methods policy | Microsoft Intune Group Policy |
Attestation support
Prerequisites for Microsoft Entra passkey on Windows
Attestation isn't supported for Microsoft Entra passkey on Windows. As a result, if Enforce attestation is selected in a passkey profile, passkey registration attempts to Windows Hello will fail.
- An account with at least Authentication Policy Administrator permissions to configure authentication methods.
- You need to enable passkey sign-in in the Passkey (FIDO2) policy in Authentication methods in the Microsoft Entra admin center.
- Windows 10 or Windows 11
- Device must support Windows Hello
Supported Windows Hello passkey Authenticator Attestation GUIDs (AAGUIDs)
Supported Windows Hello passkey AAGUIDs
During public preview, Windows Hello passkeys are identified and controlled by using the following AAGUIDs. These AAGUIDs must be explicitly allowed in a passkey profile to enable registration.
Windows Hello passkeys are identified and controlled by using the following AAGUIDs. These AAGUIDs must be explicitly allowed in a passkey profile to enable registration.
| Windows Hello authenticator | AAGUID | Description |
|---|---|---|
| Windows Hello Hardware Authenticator | 08987058-cadc-4b81-b6e1-30de50dcbe96 | Private key stored in a hardware-based Trusted Platform Module (TPM). |
| Windows Hello Hardware Authenticator | 08987058-cadc-4b81-b6e1-30de50dcbe96 | Private key stored in a hardware-based TPM. |
| Windows Hello VBS Hardware Authenticator | 9ddd1817-af5a-4672-a2b9-3e3dd95000a9 | Virtualization-based Security (VBS) uses hardware virtualization and the Windows hypervisor to store private keys in the host machine's TPM. |
| Windows Hello Software Authenticator | 6028b017-b1d4-4c02-b4b3-afcdafc96bb2 | Private key stored in a software-based TPM. |
These AAGUIDs represent Windows Hello passkey providers and are used in passkey profiles to allow or block registration.
How to configure passkeys on Windows
Configure a profile for Microsoft Entra passkey on Windows
To enable registration, you need to meet all of the following prerequisites and configuration requirements.
Microsoft Entra passkey on Windows requires an Authentication Policy Administrator to configure a passkey profile with the following settings:
Prerequisites
- The profile must target the specific Windows Hello AAGUIDs.
- The profile can't Enforce attestation.
- Windows 10 or Windows 11
- Device must support Windows Hello
- Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
- Browse to Entra ID > Authentication methods.
- On the Authentication methods | Policies page, select Passkey (FIDO2) > Configure.
- Select + Add profile.
Required configuration
:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-passkey-profile.png" alt-text="Screenshot that shows how to add a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/add-passkey-profile.png":::
- Enforce attestation can't be selected.
- Passkey types must include Device-bound.
- Enter a Name for the profile, such as Entra passkey on Windows.
- For Passkey types, select Device-bound.
- Select Target specific AAGUIDS and set Behavior to Allow.
- Select + Add AAGUID > Windows Hello and Save.
:::image type="content" border="true" source="media/how-to-authentication-entra-passkeys-on-windows/passkey-on-windows-profile.png" alt-text="Screenshot of the Add passkey profile settings showing Enforce attestation cleared and Passkey types set to Device-bound.":::
:::image type="content" source="media/how-to-authentication-passkey-profiles/select-windows-hello.png" alt-text="Screenshot of the passkey profile configuration settings showing Windows Hello AAGUIDs configuration options." lightbox="media/how-to-authentication-passkey-profiles/select-windows-hello.png":::
Example: Allow Microsoft Authenticator and Windows Hello passkeys
- Select Target specific AAGUIDs.
- Set Behavior to Allow.
- Under Model/Provider AAGUIDs, add the AAGUIDs for both Microsoft Authenticator and Windows Hello:
| Authenticator | AAGUID |
|----|----|
| Microsoft Authenticator for Android | de1e552d-db1d-4423-a619-566b625cdc84 |
| Microsoft Authenticator for iOS | 90a3ccdf-635c-4729-a248-9b709135078f |
| Windows Hello Hardware Authenticator | 08987058-cadc-4b81-b6e1-30de50dcbe96 |
| Windows Hello VBS Hardware Authenticator | 9ddd1817-af5a-4672-a2b9-3e3dd95000a9 |
| Windows Hello Software Authenticator | 6028b017-b1d4-4c02-b4b3-afcdafc96bb2 |
- Select + Add AAGUID > Windows Hello and Save. Select + Add AAGUID > Microsoft Authenticator and Save.
With this configuration, users can register passkeys with Microsoft Authenticator or with Windows Hello on Windows because both sets of AAGUIDs are in the allowed list.
:::image type="content" border="true" source="media/how-to-authentication-entra-passkeys-on-windows/authenticator-windows-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Microsoft Authenticator and Windows Hello AAGUIDs added.":::
:::image type="content" source="media/how-to-authentication-entra-passkeys-on-windows/authenticator-windows-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Microsoft Authenticator and Windows Hello AAGUIDs added." lightbox="media/how-to-authentication-entra-passkeys-on-windows/authenticator-windows-passkey-profile.png":::
Example: Allow only Windows Hello Hardware Authenticators
- Select Target specific AAGUIDs.
- Set Behavior to Allow.
- Under Model/Provider AAGUIDs, add the AAGUIDs for Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator.
- Under Model/Provider AAGUIDs, add the AAGUIDs for Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator, and Save.
With this configuration, users can register passkeys on Windows only when their device supports hardware-backed Windows Hello. Because the Windows Hello Software Authenticator AAGUID isn't in the allowed list, software-only registrations are blocked.
:::image type="content" border="true" source="media/how-to-authentication-entra-passkeys-on-windows/high-assurance-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator AAGUIDs added.":::
:::image type="content" source="media/how-to-authentication-entra-passkeys-on-windows/high-assurance-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator AAGUIDs added." lightbox="media/how-to-authentication-entra-passkeys-on-windows/high-assurance-passkey-profile.png":::
Enable and target groups for a profile for Microsoft Entra passkeys on Windows
Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
Browse to Entra ID > Authentication methods.
On the Authentication methods | Policies page, select Passkey (FIDO2) > Enable and target.
On the Enable and Target tab, make sure Enable is On.
Select Add target, and choose All users or Select targets to choose specific groups.
:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-target.png" alt-text="Screenshot that shows how to add a target for a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/add-target.png":::
Select the profile for Microsoft Entra passkey on Windows, and select Save.
:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/enable-target-windows.png" alt-text="Screenshot that shows how to enable and target a profile for Microsoft Entra passkey on Windows." lightbox="media/how-to-authentication-passkey-profiles/enable-target-windows.png":::
FAQ
Answer: No. Microsoft Entra passkey on Windows doesn't replace Windows Hello for Business. Windows Hello for Business remains the recommended solution for signing into corporate managed, Microsoft Entra joined or registered devices. Microsoft Entra passkey on Windows complements Windows Hello for Business by enabling passkeys (FIDO2) on Windows in scenarios where devices aren't joined or registered. Microsoft Entra passkey on Windows doesn't support device sign-in.
Question: Are Microsoft Entra passkeys synced?
Answer: No. Microsoft Entra passkey on Windows is device-bound and stored in the local Windows Hello container. It isn't synced across devices. Each device requires a separate passkey registration for each Microsoft Entra account.
Register a Microsoft Entra passkey on Windows
After an admin creates the Windows passkey profile, users can register a passkey directly into the local Windows Hello container on their device.
For registration steps, see Register a Microsoft Entra passkey on Windows.
Sign in with a Microsoft Entra passkey on Windows
After registration, users can sign in to Microsoft Entra ID by using the passkey stored in Windows Hello on their device.
For sign-in steps, see Sign in with a Microsoft Entra passkey on Windows.
Related content
diff --git a/docs/identity/authentication/how-to-authentication-entra-passkeys-on-windows.md b/docs/identity/authentication/how-to-authentication-entra-passkeys-on-windows.md index fad4a1d23cd..46c6440014e 100644 --- a/docs/identity/authentication/how-to-authentication-entra-passkeys-on-windows.md +++ b/docs/identity/authentication/how-to-authentication-entra-passkeys-on-windows.md @@ -1,24 +1,27 @@ --- -title: Enable Microsoft Entra passkey on Windows devices -description: Learn how to enable Microsoft Entra passkey on Windows devices for phishing-resistant multifactor authentication with work or school accounts. -#customer intent: As an administrator, I want to enable Microsoft Entra passkeys so users with work and school accounts can sign in by using phishing-resistant multifactor authentication. -ms.reviewer: kimhana -ms.date: 02/18/2026 +title: Enable Microsoft Entra passkey on Windows (preview) +description: Learn how Microsoft Entra passkey on Windows enables phishing-resistant authentication with work or school accounts by using Windows Hello as a FIDO2 passkey provider. +#customer intent: As an administrator, I want to understand Microsoft Entra passkeys on Windows so users with work and school accounts can sign in by using phishing-resistant multifactor authentication. +author: hanki71 +ms.author: justinha +ms.date: 07/05/2026 ms.topic: how-to ms.service: entra-id ms.subservice: authentication ms.collection: msec-ai-copilot -ms.custom: msecd-doc-authoring-106 +ms.custom: msecd-doc-authoring-1013 ai-usage: ai-assisted --- -# Enable Microsoft Entra passkey on Windows +# Enable Microsoft Entra passkey on Windows (preview) -This article describes Microsoft Entra passkey on Windows. It covers how they work, how they differ from Windows Hello for Business, and how to configure passkey profiles to allow Windows Hello as a passkey provider. +This article describes Microsoft Entra passkey on Windows, how it works, and how it differs from Windows Hello for Business. + +To configure passkey profiles that allow Windows Hello as a FIDO2 passkey provider, see [Configure a profile for Microsoft Entra passkey on Windows](#configure-a-profile-for-microsoft-entra-passkey-on-windows). ## Overview -Microsoft Entra passkey on Windows allows users to register passkeys (FIDO2) directly into their device's local Windows Hello container and use them to sign in to Microsoft Entra ID. Microsoft Entra passkey on Windows enables phishing-resistant sign-in by using a Windows Hello biometric or PIN without requiring the device to be Microsoft Entra joined or registered. +Microsoft Entra passkey on Windows allows users to register passkeys (FIDO2) directly into their device's local Windows Hello container. Users can then use these passkeys to sign in to Microsoft Entra ID. Microsoft Entra passkey on Windows enables phishing-resistant sign-in by using a Windows Hello biometric or PIN without requiring the device to be Microsoft Entra joined or registered. By using Microsoft Entra passkey on Windows: @@ -37,33 +40,12 @@ Windows Hello acts as a secure local credential container on Windows devices. Th Microsoft Entra passkey on Windows allows passkeys (FIDO2) to be created and stored inside this Windows Hello container and used for authentication to Microsoft Entra ID. -This behavior also applies when the device is governed by Windows Hello for Business policies configured through Microsoft Intune. However, passkeys (FIDO2) are distinct from the Windows Hello for Business credentials that may be automatically registered during device registration to Microsoft Entra ID. +This behavior also applies when the device is governed by Windows Hello for Business policies configured through Microsoft Intune. However, passkeys (FIDO2) are distinct from the Windows Hello for Business credentials that might be automatically registered during device registration to Microsoft Entra ID. ## How Microsoft Entra passkey on Windows compares with Windows Hello for Business Although both features use Windows Hello, Microsoft Entra passkey on Windows and Windows Hello for Business have different purposes and behavior. -### Windows Hello for Business - -- Windows Hello for Business credentials are automatically provisioned on some Microsoft Entra joined or registered devices during device registration. -- The credential is tied only to the Microsoft Entra account used to register the device. -- Windows Hello for Business credentials are passkeys using a first-party (1P) protocol, but not FIDO2 passkeys. -- Windows Hello for Business enables device sign-in using facial recognition, fingerprint, or PIN protected by Windows Hello. -- Windows Hello for Business provides single sign-on (SSO) to Microsoft Entra-integrated resources after device sign-in. -- Windows Hello for Business is primarily a device-bound sign-in method linked to device trust. -- Registration and authentication aren't controlled by the Microsoft Entra Authentication Methods Passkey (FIDO2) policy. - -### Microsoft Entra passkey on Windows - -- Microsoft Entra passkey on Windows is a FIDO2 passkey. -- They can be registered without device join or registration. -- Users can register multiple passkeys for multiple Microsoft Entra accounts on the same device. -- Registration and authentication are managed by the **Passkey (FIDO2)** policy in Microsoft Entra ID Authentication methods. -- They can't be used for device sign-in. - -> [!NOTE] -> If you're on a Microsoft Entra joined or Microsoft Entra registered device, setting up Windows Hello might automatically register a Windows Hello for Business credential for the device's linked account. If you then attempt to register a passkey on Windows for that same account, registration fails because the Windows Hello for Business credential already exists. On retry, you'll see an error indicating the passkey is already registered. - | Feature | Microsoft Entra passkey on Windows | Windows Hello for Business | |---|---|---| | Standard base | FIDO2 | FIDO2 for authentication, first-party (1P) protocol for device sign-in | @@ -73,37 +55,46 @@ Although both features use Windows Hello, Microsoft Entra passkey on Windows and | Credential binding | Bound to the device and stored in the local Windows Hello container. Users can register multiple passkeys for multiple work or school accounts on the same device. | Primarily a device-bound sign-in method linked to device trust. The credential is tied only to the work or school account used to register the device. | | Management | Microsoft Entra ID Authentication methods policy | Microsoft Intune<br>Group Policy | -## Attestation support +> [!NOTE] +> If you're on a Microsoft Entra joined or Microsoft Entra registered device, setting up Windows Hello might automatically register a Windows Hello for Business credential for the device's linked account. If you then attempt to register a passkey on Windows for that same account, registration fails because the Windows Hello for Business credential already exists. On retry, you see an error indicating the passkey is already registered. + +## Prerequisites for Microsoft Entra passkey on Windows -Attestation isn't supported for Microsoft Entra passkey on Windows. As a result, if **Enforce attestation** is selected in a passkey profile, passkey registration attempts to Windows Hello will fail. +- An account with at least [Authentication Policy Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-policy-administrator) permissions to configure authentication methods. +- You need to [enable passkey sign-in](how-to-authentication-passkeys-fido2.md#enable-passkey-profiles) in the **Passkey (FIDO2)** policy in **Authentication methods** in the Microsoft Entra admin center. +- Windows 10 or Windows 11 +- Device must support Windows Hello -## Supported Windows Hello passkey Authenticator Attestation GUIDs (AAGUIDs) +## Supported Windows Hello passkey AAGUIDs -During public preview, Windows Hello passkeys are identified and controlled by using the following AAGUIDs. These AAGUIDs must be explicitly allowed in a passkey profile to enable registration. +Windows Hello passkeys are identified and controlled by using the following AAGUIDs. These AAGUIDs must be explicitly allowed in a passkey profile to enable registration. | Windows Hello authenticator | AAGUID | Description | |----|----|----| -| Windows Hello Hardware Authenticator | 08987058-cadc-4b81-b6e1-30de50dcbe96 | Private key stored in a hardware-based Trusted Platform Module (TPM). | +| Windows Hello Hardware Authenticator | 08987058-cadc-4b81-b6e1-30de50dcbe96 | Private key stored in a hardware-based TPM. | | Windows Hello VBS Hardware Authenticator | 9ddd1817-af5a-4672-a2b9-3e3dd95000a9 | Virtualization-based Security (VBS) uses hardware virtualization and the Windows hypervisor to store private keys in the host machine's TPM. | | Windows Hello Software Authenticator | 6028b017-b1d4-4c02-b4b3-afcdafc96bb2 | Private key stored in a software-based TPM. | -These AAGUIDs represent Windows Hello passkey providers and are used in passkey profiles to allow or block registration. - -## How to configure passkeys on Windows +## Configure a profile for Microsoft Entra passkey on Windows -To enable registration, you need to meet all of the following prerequisites and configuration requirements. +Microsoft Entra passkey on Windows requires an Authentication Policy Administrator to configure a passkey profile with the following settings: -### Prerequisites +- The profile must target the specific Windows Hello AAGUIDs. +- The profile can't **Enforce attestation**. -- Windows 10 or Windows 11 -- Device must support Windows Hello +1. Sign in to the Microsoft Entra admin center as at least an [Authentication Policy Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-policy-administrator). +1. Browse to **Entra ID** > **Authentication methods**. +1. On the **Authentication methods | Policies** page, select **Passkey (FIDO2)** > **Configure**. +1. Select **+ Add profile**. -### Required configuration + :::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-passkey-profile.png" alt-text="Screenshot that shows how to add a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/add-passkey-profile.png"::: -- **Enforce attestation** can't be selected. -- **Passkey types** must include **Device-bound**. +1. Enter a **Name** for the profile, such as **Entra passkey on Windows**. +1. For **Passkey types**, select **Device-bound**. +1. Select **Target specific AAGUIDS** and set **Behavior** to **Allow**. +1. Select **+ Add AAGUID** > **Windows Hello** and **Save**. -:::image type="content" border="true" source="media/how-to-authentication-entra-passkeys-on-windows/passkey-on-windows-profile.png" alt-text="Screenshot of the Add passkey profile settings showing Enforce attestation cleared and Passkey types set to Device-bound."::: + :::image type="content" source="media/how-to-authentication-passkey-profiles/select-windows-hello.png" alt-text="Screenshot of the passkey profile configuration settings showing Windows Hello AAGUIDs configuration options." lightbox="media/how-to-authentication-passkey-profiles/select-windows-hello.png"::: ### Example: Allow Microsoft Authenticator and Windows Hello passkeys @@ -113,19 +104,11 @@ To configure this profile: 1. Select **Target specific AAGUIDs**. 1. Set **Behavior** to **Allow**. -1. Under **Model/Provider AAGUIDs**, add the AAGUIDs for both Microsoft Authenticator and Windows Hello: - - | Authenticator | AAGUID | - |----|----| - | Microsoft Authenticator for Android | de1e552d-db1d-4423-a619-566b625cdc84 | - | Microsoft Authenticator for iOS | 90a3ccdf-635c-4729-a248-9b709135078f | - | Windows Hello Hardware Authenticator | 08987058-cadc-4b81-b6e1-30de50dcbe96 | - | Windows Hello VBS Hardware Authenticator | 9ddd1817-af5a-4672-a2b9-3e3dd95000a9 | - | Windows Hello Software Authenticator | 6028b017-b1d4-4c02-b4b3-afcdafc96bb2 | +1. Select **+ Add AAGUID** > **Windows Hello** and **Save**. Select **+ Add AAGUID** > **Microsoft Authenticator** and **Save**. With this configuration, users can register passkeys with Microsoft Authenticator or with Windows Hello on Windows because both sets of AAGUIDs are in the allowed list. -:::image type="content" border="true" source="media/how-to-authentication-entra-passkeys-on-windows/authenticator-windows-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Microsoft Authenticator and Windows Hello AAGUIDs added."::: +:::image type="content" source="media/how-to-authentication-entra-passkeys-on-windows/authenticator-windows-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Microsoft Authenticator and Windows Hello AAGUIDs added." lightbox="media/how-to-authentication-entra-passkeys-on-windows/authenticator-windows-passkey-profile.png"::: ### Example: Allow only Windows Hello Hardware Authenticators @@ -135,11 +118,25 @@ To configure this restriction: 1. Select **Target specific AAGUIDs**. 1. Set **Behavior** to **Allow**. -1. Under **Model/Provider AAGUIDs**, add the AAGUIDs for **Windows Hello Hardware Authenticator** and **Windows Hello VBS Hardware Authenticator**. +1. Under **Model/Provider AAGUIDs**, add the AAGUIDs for **Windows Hello Hardware Authenticator** and **Windows Hello VBS Hardware Authenticator**, and **Save**. With this configuration, users can register passkeys on Windows only when their device supports hardware-backed Windows Hello. Because the Windows Hello Software Authenticator AAGUID isn't in the allowed list, software-only registrations are blocked. -:::image type="content" border="true" source="media/how-to-authentication-entra-passkeys-on-windows/high-assurance-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator AAGUIDs added."::: +:::image type="content" source="media/how-to-authentication-entra-passkeys-on-windows/high-assurance-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator AAGUIDs added." lightbox="media/how-to-authentication-entra-passkeys-on-windows/high-assurance-passkey-profile.png"::: + +## Enable and target groups for a profile for Microsoft Entra passkeys on Windows + +1. Sign in to the Microsoft Entra admin center as at least an [Authentication Policy Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-policy-administrator). +1. Browse to **Entra ID** > **Authentication methods**. +1. On the **Authentication methods | Policies** page, select **Passkey (FIDO2)** > **Enable and target**. +1. On the **Enable and Target** tab, make sure **Enable** is **On**. +1. Select **Add target**, and choose **All users** or **Select targets** to choose specific groups. + + :::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-target.png" alt-text="Screenshot that shows how to add a target for a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/add-target.png"::: + +1. Select the profile for Microsoft Entra passkey on Windows, and select **Save**. + + :::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/enable-target-windows.png" alt-text="Screenshot that shows how to enable and target a profile for Microsoft Entra passkey on Windows." lightbox="media/how-to-authentication-passkey-profiles/enable-target-windows.png"::: ## FAQ @@ -156,13 +153,27 @@ With this configuration, users can register passkeys on Windows only when their **Answer**: No. Microsoft Entra passkey on Windows doesn't replace Windows Hello for Business. Windows Hello for Business remains the recommended solution for signing into corporate managed, Microsoft Entra joined or registered devices. Microsoft Entra passkey on Windows complements Windows Hello for Business by enabling passkeys (FIDO2) on Windows in scenarios where devices aren't joined or registered. Microsoft Entra passkey on Windows doesn't support device sign-in. > [!NOTE] -> Users can't register a passkey on Windows if a Windows Hello for Business credential already exists for the same account and container. This block may not apply once the user exceeds 50 total platform credentials. +> Users can't register a passkey on Windows if a Windows Hello for Business credential already exists for the same account and container. This block might not apply once the user exceeds 50 total platform credentials. **Question**: Are Microsoft Entra passkeys synced? **Answer**: No. Microsoft Entra passkey on Windows is device-bound and stored in the local Windows Hello container. It isn't synced across devices. Each device requires a separate passkey registration for each Microsoft Entra account. +## Register a Microsoft Entra passkey on Windows + +After an admin creates the Windows passkey profile, users can register a passkey directly into the local Windows Hello container on their device. + +For registration steps, see [Register a Microsoft Entra passkey on Windows](how-to-register-entra-passkey-windows.md). + +## Sign in with a Microsoft Entra passkey on Windows + +After registration, users can sign in to Microsoft Entra ID by using the passkey stored in Windows Hello on their device. + +For sign-in steps, see [Sign in with a Microsoft Entra passkey on Windows](how-to-sign-in-entra-passkey-windows.md). + ## Related content -- [Enable passkeys (FIDO2) for your organization](how-to-authentication-passkeys-fido2.md) +- [Enable passkeys (FIDO2) in Microsoft Entra ID](how-to-authentication-passkeys-fido2.md) +- [Passkeys (FIDO2) authentication method in Microsoft Entra ID](concept-authentication-passkeys-fido2.md) +- [Support for FIDO2 authentication with Microsoft Entra ID](concept-fido2-compatibility.md) - [Microsoft Entra ID attestation for FIDO2 authenticators](concept-fido2-hardware-vendor.md)