MC1282568: Microsoft Entra Makes Passkeys on Windows Generally Available for Passwordless Sign-In

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
51
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSecurity TeamsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
The GA rollout for Entra passkeys on Windows is confirmed, with revised dates for GCC High and DoD tenants. Admin impact is high because authentication behaviour changes and Conditional Access and passkey profiles may require review to block or allow usage. No significant action is needed for most tenants, but unmanaged device usage and security governance decisions should be considered. User impact is moderate as sign-in workflows may change, especially with easier passkey registration on Windows devices.
65
🛡️ Admin Impact
30
👥 User Impact
45
Urgency
50
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Microsoft Entra passkeys on Windows are now generally available for most tenants, bringing passwordless sign-in without extra configuration if profiles allow device-bound passkeys.
👥

END USERS

Users may start registering and using Entra passkeys on Windows devices if policy settings allow.
🛡️

IT ADMINS

Review passkey profiles; update settings if you want to block Windows Hello AAGUIDs or control unmanaged device use.
📅

ROLLOUT TIMELINE

Rolling out:
In progress

📢 Official Microsoft Message Center Announcement


(Updated) General Availability: Microsoft Entra passkeys on Windows
Message ID: MC1282568 (Updated)

Updated July 20, 2026: We have updated the timeline. Thank you for your patience.

[Introduction]

Microsoft Entra passkeys on Windows will soon be Generally Available, enabling phishing‑resistant, passwordless sign‑in to Microsoft Entra‑protected resources from Windows devices.

The Public Preview of this capability was previously announced in MC1247893.

Users can create device‑bound passkeys stored in the Windows Hello container and authenticate using Windows Hello methods (face, fingerprint, or PIN). This expands passwordless authentication support to Windows devices that aren’t Microsoft Entra‑joined or registered, helping organizations strengthen security and reduce reliance on passwords across corporate‑managed, personal, and shared device scenarios.

[When this will happen:]

  1. General Availability (Worldwide, GCC): We will begin rolling out in late April 2026 and expect to complete by mid‑June 2026.
  2. General Availability (GCC High, DoD): We will begin rolling out in early October 2026 (previously early September 2026) and expect to complete by late October 2026 (previously late September).

How this affects your organization:

Who is affected:

Organizations using Microsoft Entra ID with passkeys enabled in the Authentication Methods policy whose users sign in from Windows devices, including:

  1. Corporate‑managed PCs
  2. Personal devices
  3. Shared devices

What will happen:

With this General Availability release:

  1. Microsoft Entra passkeys on Windows will no longer require explicit opt‑in through Windows Hello AAGUID allow‑listing in a passkey (FIDO2) profile.
  2. This represents a change from Public Preview behavior, where administrators were required to explicitly allow Windows Hello AAGUIDs in a passkey profile for Microsoft Entra passkeys on Windows to function.
  3. If your passkey profile allows device‑bound, non‑attested passkeys:
  4. Users scoped to that profile will now be able to register and use Microsoft Entra passkeys on Windows by default without additional administrator configuration.
  5. As a result:
  6. Users in scope of passkey profiles that allow device‑bound, non‑attested passkeys may begin registering and using passkeys on Windows devices.
  7. If Conditional Access policies allow:
  8. Passkeys can be created and used on Windows devices that are not Microsoft Entra‑joined or registered, including personal or shared PCs.
  9. Each Windows device requires separate passkey registration per Entra account.
  10. Windows Hello for Business remains recommended for managed, Microsoft Entra‑joined or registered devices.
  11. Passkeys on Windows supplement unmanaged or shared device scenarios and do not support device sign‑in.
  12. Attestation is not currently supported for Microsoft Entra passkeys on Windows but is planned for a future update.

What you can do to prepare:


No action is required for most organizations.

If you do not want users to register or use Microsoft Entra passkeys on Windows:

  1. Update the relevant passkey (FIDO2) profile to block Windows Hello AAGUIDs.
  2. Review existing passkey profiles that allow device‑bound, non‑attested passkeys.
  3. Add Windows Hello AAGUIDs to the block list in passkey profiles where passkey usage on Windows devices should not be permitted.

Learn more: Enable Microsoft Entra passkey on Windows | Microsoft Learn (will be updated before GA rollout)

[Compliance considerations:]

Compliance areaExplanation
Does the change modify, interrupt, or disable Conditional Access policies?Existing Conditional Access policies continue to govern whether passkeys can be created or used on unmanaged Windows devices.
Does the change include an admin control and can it be controlled through Entra ID group membership?Admins can control passkey availability through Authentication Methods policies and FIDO2 passkey profiles scoped to Microsoft Entra ID groups.
Does the change allow a user to enable and disable the feature themselves?Users may register Microsoft Entra passkeys on Windows devices if permitted by administrator policy configuration.

Source: Microsoft Message Center • Analysed by MWPro

<<< [MC1282568] Archive
Tooltip: View earlier revisions of this post

Share This Update