Microsoft is adding passkey support to Microsoft Entra on Windows, bringing phishing-resistant, passwordless sign-in via Windows Hello to both managed and unmanaged devices in a public preview. The opt-in rollout runs mid-March through late April 2026 for worldwide tenants (with GCC, GCC High, and DoD following mid-April to mid-May), and IT admins must enable Passkeys (FIDO2) and create a Windows Hello AAGUID passkey profile to enroll. #MicrosoftEntra #WindowsHello
Keypoints
- Passkeys provide phishing-resistant, device-bound authentication stored in the Windows Hello container.
- Public preview is opt-in worldwide from mid-March to late April 2026, with GCC, GCC High, and DoD rolling out mid-April to mid-May.
- Passwordless sign-in is extended to unmanaged Windows devices, closing a gap for personal and shared machines.
- Each Entra account registers a separate passkey per device; passkeys cannot be synced across devices.
- IT admins must enable Passkeys (FIDO2), create a passkey profile with required Windows Hello AAGUIDs, and assign it to groups to enroll in the preview.