Synced passkeys and passkey profiles are now GA in Entra ID
Entra ID now supports passkeys stored in password managers and phone platforms, and lets you set different passkey rules for different groups. Here's how to use both sensibly.
On this page
Two passkey features reached general availability together, and they're designed to be used as a pair.
Device-bound passkey
security key, Authenticator, Windows Hello
- The key never leaves that device
- Attestation can confirm the exact model
- Losing the device means registering again
Synced passkey
stored by a passkey provider
- Available across the user's devices
- Survives a lost or replaced phone
- Less control over where the key lives
Synced passkeys
Until now, Entra passkeys were device-bound: tied to one security key or one phone's authenticator. Synced passkeys live in a passkey provider, such as the built-in platform provider on a phone or a third-party password manager, and are available across all of a user's devices.
The trade-off is simple. Synced passkeys are far easier for users: lose a phone, and the passkey is still there on the next device. Device-bound passkeys give you stronger guarantees about exactly where the key lives.
Passkey profiles
Passkey profiles let you define several sets of passkey rules in the authentication methods policy and target each at different groups. Each profile controls:
- which passkey types are allowed (device-bound, synced, or both)
- whether attestation is enforced
- which authenticators are allowed or blocked
If you already had passkeys configured, those settings moved into a default profile automatically. Later updates raised the limit to 10 profiles per tenant and gave the passkey policy its own storage allowance.
A sensible starting design
| Profile | Who | Rules |
|---|---|---|
| Admins | Privileged role holders | Device-bound only, attestation enforced, approved security keys or Authenticator |
| Standard | Everyone else | Device-bound or synced, no attestation |
This gets most users onto phishing-resistant sign-in with very little friction, while keeping a tighter grip on the accounts attackers want most.
How Entra decides which rules apply
Each passkey profile is targeted at groups. When a user registers or uses a passkey, Entra applies the profile assigned to them. Keep the targeting simple: one restrictive profile for privileged users, one relaxed profile for everyone else, and a clear rule for who goes where. Profiles that overlap in unclear ways become hard to support.
Rolling it out
- Check what your existing passkey settings migrated into. Tenants that already had passkeys configured get a default profile with those settings.
- Create the admin profile first and test it with two or three admins, including registration on a new device.
- Widen the standard profile to allow synced passkeys, then run a registration campaign.
- Once most users have a passkey, require the phishing-resistant MFA authentication strength for sensitive apps.
Checklist
- Decide which groups may use synced passkeys
- Create an admin profile with device-bound keys and attestation
- Test registration and sign-in on Windows, iOS and Android
- Brief the service desk on lost-device recovery with a Temporary Access Pass
- Add Conditional Access authentication strengths once adoption is high
This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.
Next in Passwordless rollout · part 3 of 6System-preferred authentication now picks the first factor too →