Microsoft Entra ID

Register a synced passkey (FIDO2)

In brief

Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.

Documentation change

Register a passkey (FIDO2)

Register a synced passkey (FIDO2)

This article shows how users can register a synced passkey (FIDO2) by using the Passkey flow. A synced passkey is stored in a passkey provider (such as iCloud Keychain or Google Password Manager) and syncs across the user's devices. For an overview of synced passkeys, see Synced passkeys in Microsoft Entra ID.

Prerequisites

You need to configure a password manager on your mobile device to save a synced passkey.

  • On your iOS device, you need to set Set Up Codes In to Passwords to manage synced passkeys. Open Settings > General > AutoFill & Passwords. For Set Up Codes In, select Passwords.
  • On your Android device, open Settings > Security and privacy > More security settings > Passwords, passkeys, and autofill, and then select a provider.

Register a passkey

To register a passkey on your device, follow these steps:

  1. Open a web browser and sign in to Security info.

  2. Sign in with multifactor authentication (MFA).

  3. Tap + Add sign-in method.

    :::image type="content" source="media/how-to-register-passkey/add-sign-in-method-ios.png" alt-text="Screenshot of the Security info page on iOS showing the Add sign-in method option." border="true" lightbox="media/how-to-register-passkey/add-sign-in-method-ios.png":::

  4. Tap Passkey.

    :::image type="content" source="media/how-to-register-passkey/choose-passkey-ios.png" alt-text="Screenshot of the Add a sign-in method page on iOS showing the Passkey option." border="true" lightbox="media/how-to-register-passkey/choose-passkey-ios.png":::

  5. Tap Next.

    :::image type="content" source="media/how-to-register-passkey/sign-in-faster-ios.png" alt-text="Screenshot of the Sign in faster with your face, fingerprint, or PIN page on iOS showing the Next option." border="true" lightbox="media/how-to-register-passkey/sign-in-faster-ios.png":::

  6. On iOS, tap Next.

    :::image type="content" source="media/how-to-register-passkey/setting-up-passkey-ios.png" alt-text="Screenshot of the Setting up your passkey page on iOS showing the Next option." border="true" lightbox="media/how-to-register-passkey/setting-up-passkey-ios.png":::

This article shows how users can register a passkey (FIDO2) by using the Passkey flow. For registration on a mobile device, see Register a passkey using a mobile device.

On Android, tap **Continue**.

For more information about enabling passkeys in Microsoft Authenticator, see How to enable passkeys in Microsoft Authenticator.

:::image type="content" source="media/how-to-register-passkey/android-complete.png" alt-text="Screenshot of the Create a passkey page on Android showing the account name and Continue option." border="true" lightbox="media/how-to-register-passkey/android-complete.png":::

Manual registration

  1. Name your passkey and tap Next.
  1. Users can register a passkey (FIDO2) as an authentication method by navigating and completing the process from a browser at Security info.

  2. Tap Add sign-in method > Choose a method > Passkey > Add.

  3. Sign in with multifactor authentication (MFA) before adding a passkey, then tap Next.

    1. If you don't have at least one MFA method registered, you must add one.
    2. An Authentication Policy Administrator can also issue a Temporary Access Pass to allow a user to strongly authenticate and register a passkey.

    :::image type="content" border="true" source="media/how-to-register-passkey-android-or-ios/add-passkey.png" alt-text="Screenshot of the Add a passkey on your iOS or Android device option.":::

:::image type="content" source="media/how-to-register-passkey/name-passkey.png" alt-text="Screenshot of the Let's name your passkey page showing the passkey name field and Next option." border="true" lightbox="media/how-to-register-passkey/name-passkey.png":::
  1. A security dialog opens on your device and asks where to save your passkey.
  1. After the passkey is created, tap Done.
:::image type="content" source="media/how-to-register-passkey/passkey-created-ios.png" alt-text="Screenshot of the Passkey created page showing the Done option." border="true" lightbox="media/how-to-register-passkey/passkey-created-ios.png":::
  1. You can see your passkey in Security info.
  1. If your organization allows saving a passkey to a security key:
    1. Choose Security Key.
    2. Follow the guidance and insert or connect your security key when requested.
    3. You're prompted to create or enter a PIN for your security key, then perform the required gesture for the key.
    4. Upon completion, review any additional information from the security dialog, then tap Ok or Continue.
:::image type="content" source="media/how-to-register-passkey/passkey-added-ios.png" alt-text="Screenshot of the Security info page showing the registered passkey." border="true" lightbox="media/how-to-register-passkey/passkey-added-ios.png":::
  1. After you're redirected to Security info, you can change the default name for the new sign-in method.
  2. Tap Done to finish registering the new method.

Related content

Next steps

To register a passkey on a different type of authenticator, see: