Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys

Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys

Microsoft is adding passkey support to Microsoft Entra on Windows, bringing phishing-resistant, passwordless sign-in via Windows Hello to both managed and unmanaged devices in a public preview. The opt-in rollout runs mid-March through late April 2026 for worldwide tenants (with GCC, GCC High, and DoD following mid-April to mid-May), and IT admins must enable Passkeys (FIDO2) and create a Windows Hello AAGUID passkey profile to enroll. #MicrosoftEntra #WindowsHello

Keypoints

  • Passkeys provide phishing-resistant, device-bound authentication stored in the Windows Hello container.
  • Public preview is opt-in worldwide from mid-March to late April 2026, with GCC, GCC High, and DoD rolling out mid-April to mid-May.
  • Passwordless sign-in is extended to unmanaged Windows devices, closing a gap for personal and shared machines.
  • Each Entra account registers a separate passkey per device; passkeys cannot be synced across devices.
  • IT admins must enable Passkeys (FIDO2), create a passkey profile with required Windows Hello AAGUIDs, and assign it to groups to enroll in the preview.

Read More: https://www.bleepingcomputer.com/news/microsoft/microsoft-entra-brings-phishing-resistant-sign-in-to-windows/