Microsoft Entra ID

Enable Microsoft Entra passkey on Windows (preview)

In brief

Learn how Microsoft Entra passkey on Windows enables phishing-resistant authentication with work or school accounts by using Windows Hello as a FIDO2 passkey provider.

Documentation change

Enable Microsoft Entra passkey on Windows

Enable Microsoft Entra passkey on Windows (preview)

This article describes Microsoft Entra passkey on Windows. It covers how they work, how they differ from Windows Hello for Business, and how to configure passkey profiles to allow Windows Hello as a passkey provider.

This article describes Microsoft Entra passkey on Windows, how it works, and how it differs from Windows Hello for Business.

To configure passkey profiles that allow Windows Hello as a FIDO2 passkey provider, see Configure a profile for Microsoft Entra passkey on Windows.

Overview

Microsoft Entra passkey on Windows allows users to register passkeys (FIDO2) directly into their device's local Windows Hello container and use them to sign in to Microsoft Entra ID. Microsoft Entra passkey on Windows enables phishing-resistant sign-in by using a Windows Hello biometric or PIN without requiring the device to be Microsoft Entra joined or registered.

Microsoft Entra passkey on Windows allows users to register passkeys (FIDO2) directly into their device's local Windows Hello container. Users can then use these passkeys to sign in to Microsoft Entra ID. Microsoft Entra passkey on Windows enables phishing-resistant sign-in by using a Windows Hello biometric or PIN without requiring the device to be Microsoft Entra joined or registered.

By using Microsoft Entra passkey on Windows:

Microsoft Entra passkey on Windows allows passkeys (FIDO2) to be created and stored inside this Windows Hello container and used for authentication to Microsoft Entra ID.

This behavior also applies when the device is governed by Windows Hello for Business policies configured through Microsoft Intune. However, passkeys (FIDO2) are distinct from the Windows Hello for Business credentials that may be automatically registered during device registration to Microsoft Entra ID.

This behavior also applies when the device is governed by Windows Hello for Business policies configured through Microsoft Intune. However, passkeys (FIDO2) are distinct from the Windows Hello for Business credentials that might be automatically registered during device registration to Microsoft Entra ID.

How Microsoft Entra passkey on Windows compares with Windows Hello for Business

Although both features use Windows Hello, Microsoft Entra passkey on Windows and Windows Hello for Business have different purposes and behavior.

Windows Hello for Business

  • Windows Hello for Business credentials are automatically provisioned on some Microsoft Entra joined or registered devices during device registration.
  • The credential is tied only to the Microsoft Entra account used to register the device.
  • Windows Hello for Business credentials are passkeys using a first-party (1P) protocol, but not FIDO2 passkeys.
  • Windows Hello for Business enables device sign-in using facial recognition, fingerprint, or PIN protected by Windows Hello.
  • Windows Hello for Business provides single sign-on (SSO) to Microsoft Entra-integrated resources after device sign-in.
  • Windows Hello for Business is primarily a device-bound sign-in method linked to device trust.
  • Registration and authentication aren't controlled by the Microsoft Entra Authentication Methods Passkey (FIDO2) policy.

Microsoft Entra passkey on Windows

  • Microsoft Entra passkey on Windows is a FIDO2 passkey.
  • They can be registered without device join or registration.
  • Users can register multiple passkeys for multiple Microsoft Entra accounts on the same device.
  • Registration and authentication are managed by the Passkey (FIDO2) policy in Microsoft Entra ID Authentication methods.
  • They can't be used for device sign-in.
Feature Microsoft Entra passkey on Windows Windows Hello for Business
Standard base FIDO2 FIDO2 for authentication, first-party (1P) protocol for device sign-in
Credential binding Bound to the device and stored in the local Windows Hello container. Users can register multiple passkeys for multiple work or school accounts on the same device. Primarily a device-bound sign-in method linked to device trust. The credential is tied only to the work or school account used to register the device.
Management Microsoft Entra ID Authentication methods policy Microsoft Intune
Group Policy

Attestation support

Prerequisites for Microsoft Entra passkey on Windows

Attestation isn't supported for Microsoft Entra passkey on Windows. As a result, if Enforce attestation is selected in a passkey profile, passkey registration attempts to Windows Hello will fail.

  • An account with at least Authentication Policy Administrator permissions to configure authentication methods.
  • You need to enable passkey sign-in in the Passkey (FIDO2) policy in Authentication methods in the Microsoft Entra admin center.
  • Windows 10 or Windows 11
  • Device must support Windows Hello

Supported Windows Hello passkey Authenticator Attestation GUIDs (AAGUIDs)

Supported Windows Hello passkey AAGUIDs

During public preview, Windows Hello passkeys are identified and controlled by using the following AAGUIDs. These AAGUIDs must be explicitly allowed in a passkey profile to enable registration.

Windows Hello passkeys are identified and controlled by using the following AAGUIDs. These AAGUIDs must be explicitly allowed in a passkey profile to enable registration.

Windows Hello authenticator AAGUID Description
Windows Hello Hardware Authenticator 08987058-cadc-4b81-b6e1-30de50dcbe96 Private key stored in a hardware-based Trusted Platform Module (TPM).
Windows Hello Hardware Authenticator 08987058-cadc-4b81-b6e1-30de50dcbe96 Private key stored in a hardware-based TPM.
Windows Hello VBS Hardware Authenticator 9ddd1817-af5a-4672-a2b9-3e3dd95000a9 Virtualization-based Security (VBS) uses hardware virtualization and the Windows hypervisor to store private keys in the host machine's TPM.
Windows Hello Software Authenticator 6028b017-b1d4-4c02-b4b3-afcdafc96bb2 Private key stored in a software-based TPM.

These AAGUIDs represent Windows Hello passkey providers and are used in passkey profiles to allow or block registration.

How to configure passkeys on Windows

Configure a profile for Microsoft Entra passkey on Windows

To enable registration, you need to meet all of the following prerequisites and configuration requirements.

Microsoft Entra passkey on Windows requires an Authentication Policy Administrator to configure a passkey profile with the following settings:

Prerequisites

  • The profile must target the specific Windows Hello AAGUIDs.
  • The profile can't Enforce attestation.
  • Windows 10 or Windows 11
  • Device must support Windows Hello
  1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.
  2. Browse to Entra ID > Authentication methods.
  3. On the Authentication methods | Policies page, select Passkey (FIDO2) > Configure.
  4. Select + Add profile.

Required configuration

:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-passkey-profile.png" alt-text="Screenshot that shows how to add a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/add-passkey-profile.png":::

  • Enforce attestation can't be selected.
  • Passkey types must include Device-bound.
  1. Enter a Name for the profile, such as Entra passkey on Windows.
  2. For Passkey types, select Device-bound.
  3. Select Target specific AAGUIDS and set Behavior to Allow.
  4. Select + Add AAGUID > Windows Hello and Save.

:::image type="content" border="true" source="media/how-to-authentication-entra-passkeys-on-windows/passkey-on-windows-profile.png" alt-text="Screenshot of the Add passkey profile settings showing Enforce attestation cleared and Passkey types set to Device-bound.":::

:::image type="content" source="media/how-to-authentication-passkey-profiles/select-windows-hello.png" alt-text="Screenshot of the passkey profile configuration settings showing Windows Hello AAGUIDs configuration options." lightbox="media/how-to-authentication-passkey-profiles/select-windows-hello.png":::

Example: Allow Microsoft Authenticator and Windows Hello passkeys

  1. Select Target specific AAGUIDs.
  2. Set Behavior to Allow.
  1. Under Model/Provider AAGUIDs, add the AAGUIDs for both Microsoft Authenticator and Windows Hello:
| Authenticator | AAGUID |
|----|----|
| Microsoft Authenticator for Android | de1e552d-db1d-4423-a619-566b625cdc84 |
| Microsoft Authenticator for iOS | 90a3ccdf-635c-4729-a248-9b709135078f |
| Windows Hello Hardware Authenticator | 08987058-cadc-4b81-b6e1-30de50dcbe96 |
| Windows Hello VBS Hardware Authenticator | 9ddd1817-af5a-4672-a2b9-3e3dd95000a9 |
| Windows Hello Software Authenticator | 6028b017-b1d4-4c02-b4b3-afcdafc96bb2 |
  1. Select + Add AAGUID > Windows Hello and Save. Select + Add AAGUID > Microsoft Authenticator and Save.

With this configuration, users can register passkeys with Microsoft Authenticator or with Windows Hello on Windows because both sets of AAGUIDs are in the allowed list.

:::image type="content" border="true" source="media/how-to-authentication-entra-passkeys-on-windows/authenticator-windows-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Microsoft Authenticator and Windows Hello AAGUIDs added.":::

:::image type="content" source="media/how-to-authentication-entra-passkeys-on-windows/authenticator-windows-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Microsoft Authenticator and Windows Hello AAGUIDs added." lightbox="media/how-to-authentication-entra-passkeys-on-windows/authenticator-windows-passkey-profile.png":::

Example: Allow only Windows Hello Hardware Authenticators

  1. Select Target specific AAGUIDs.
  2. Set Behavior to Allow.
  1. Under Model/Provider AAGUIDs, add the AAGUIDs for Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator.
  1. Under Model/Provider AAGUIDs, add the AAGUIDs for Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator, and Save.

With this configuration, users can register passkeys on Windows only when their device supports hardware-backed Windows Hello. Because the Windows Hello Software Authenticator AAGUID isn't in the allowed list, software-only registrations are blocked.

:::image type="content" border="true" source="media/how-to-authentication-entra-passkeys-on-windows/high-assurance-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator AAGUIDs added.":::

:::image type="content" source="media/how-to-authentication-entra-passkeys-on-windows/high-assurance-passkey-profile.png" alt-text="Screenshot of the Add passkey profile settings with Target specific AAGUIDs selected, Behavior set to Allow, and the Windows Hello Hardware Authenticator and Windows Hello VBS Hardware Authenticator AAGUIDs added." lightbox="media/how-to-authentication-entra-passkeys-on-windows/high-assurance-passkey-profile.png":::

Enable and target groups for a profile for Microsoft Entra passkeys on Windows

  1. Sign in to the Microsoft Entra admin center as at least an Authentication Policy Administrator.

  2. Browse to Entra ID > Authentication methods.

  3. On the Authentication methods | Policies page, select Passkey (FIDO2) > Enable and target.

  4. On the Enable and Target tab, make sure Enable is On.

  5. Select Add target, and choose All users or Select targets to choose specific groups.

    :::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/add-target.png" alt-text="Screenshot that shows how to add a target for a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/add-target.png":::

  6. Select the profile for Microsoft Entra passkey on Windows, and select Save.

    :::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/enable-target-windows.png" alt-text="Screenshot that shows how to enable and target a profile for Microsoft Entra passkey on Windows." lightbox="media/how-to-authentication-passkey-profiles/enable-target-windows.png":::

FAQ

Answer: No. Microsoft Entra passkey on Windows doesn't replace Windows Hello for Business. Windows Hello for Business remains the recommended solution for signing into corporate managed, Microsoft Entra joined or registered devices. Microsoft Entra passkey on Windows complements Windows Hello for Business by enabling passkeys (FIDO2) on Windows in scenarios where devices aren't joined or registered. Microsoft Entra passkey on Windows doesn't support device sign-in.

Question: Are Microsoft Entra passkeys synced?

Answer: No. Microsoft Entra passkey on Windows is device-bound and stored in the local Windows Hello container. It isn't synced across devices. Each device requires a separate passkey registration for each Microsoft Entra account.

Register a Microsoft Entra passkey on Windows

After an admin creates the Windows passkey profile, users can register a passkey directly into the local Windows Hello container on their device.

For registration steps, see Register a Microsoft Entra passkey on Windows.

Sign in with a Microsoft Entra passkey on Windows

After registration, users can sign in to Microsoft Entra ID by using the passkey stored in Windows Hello on their device.

For sign-in steps, see Sign in with a Microsoft Entra passkey on Windows.

Related content