Microsoft Entra External ID
Authentication

Sign in with passkeys in Microsoft Entra External ID

In brief

The page now describes administrator-controlled passkey provisioning with the FIDO2 provisioning APIs and identifies the sample as testing-only with high-privilege permissions.

What Entra admins need to know

Review passkey implementations and permission usage against the updated guidance; the sample should not be treated as a production implementation.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Sign in with passkeys in Microsoft Entra External ID

[!INCLUDE applies-to-external-only]

Step 3: Build a passkey management experience for your application

Your application needs a credential management experience so signed-in customers can register and manage their own passkeys. Use the credential management APIFIDO2 provisioning APIs to build this experience with low-privilege delegated permissions.into your app.

The credential management experience should enable customers to:

  • View their registered passkeys.
  • Delete a passkey.

To support passkey management in your app, use theThe Microsoft Graph passkey sample. demonstrates administrator-controlled provisioning with high-privilege application permissions. The sample demonstrates how signed-in customers can listis intended for testing only and register their own passkeys by using theisn't an implementation model for customer self-service.

User experience

Are there low-privilege APIs for building a credential management API with delegated permissions. Followexperience?

No. Use the sample's READMEFIDO2 provisioning APIs to configure and run the app.

User experience

Are there low-privilege APIs for building a credential management experience?

Yes. Use the credential management API to let signed-in customers list and register their own passkeys with delegated permissions.build your credential management experience.

Can I use the same passkey across multiple domains (related origins)?

Is there an out-of-box passkey registration experience?

No. Microsoft doesn't currently provide a built-in passkey registration experience for external tenants. Build a credential management experience in your application by using the credential management APIFIDO2 provisioning APIs.

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…