Microsoft Entra passkeys on Windows enable phishing-resistant, passwordless sign-in using Windows Hello on Entra-protected resources, including unmanaged devices. Public preview starts mid-March 2026. Organizations must opt in and configure policies to enable this feature; no impact occurs without activation.
Introduction
We’re introducing Microsoft Entra passkeys on Windows to enable phishing-resistant sign-in to Entra-protected resources. This update allows users to create device‑bound passkeys stored in the Windows Hello container and authenticate using Windows Hello methods (face, fingerprint, or PIN). It also expands passwordless authentication to Windows devices that aren’t Entra‑joined or registered, helping organizations strengthen security and reduce reliance on passwords.
When this will happen
How this affects your organization
Who is affected
What will happen
What you can do to prepare
If you want to enable Entra passkeys on Windows during public preview:
08987058-cadc-4b81-b6e1-30de50dcbe969ddd1817-af5a-4672-a2b9-3e3dd95000a96028b017-b1d4-4c02-b4b3-afcdafc96bb2If you do not plan to participate in the public preview, no action is required.
Compliance considerations
No compliance considerations identified, review as appropriate for your organization.