IAMinerva
HomeBlogAbout
m3M365 NewscoMicrosoft CopilotteMicrosoft TeamsshSharePoint & OneDriveinIntune & SecurityexExchange & OutlookpoPower PlatformazAzure & Entra IDtuTutorials & GuidesevEvents & ConferencesseSecuritywiWindows
IAMinerva

Professional blog dedicated to the Microsoft 365 ecosystem.

Quick links

HomeBlogAboutNewsletter

Stay informed

Get the latest Microsoft 365 news delivered straight to your inbox.

© 2026 IAMinerva. All rights reserved.

Built withNext.js&Tailwind
Microsoft Entra Passkeys : Une nouvelle étape pour Windows Hello
BlogAzure & Entra IDMicrosoft Entra Passkeys: A New Step for Windows Hello
Azure & Entra ID#Azure#Microsoft Entra#Windows Hello

Microsoft Entra Passkeys: A New Step for Windows Hello

Discover the introduction of Microsoft Entra Passkeys with Windows Hello for phishing-resistant authentication. Implement them now!

Houssem MAKHLOUF
March 11, 2026
3 min read

TL;DR par Minerva

généré par IA

Discover the introduction of Microsoft Entra Passkeys with Windows Hello for phishing-resistant authentication. Implement them now!

Introduction

Microsoft continues to strengthen passwordless authentication at scale with the introduction of Microsoft Entra Passkeys. Starting in March 2026, this update will allow users to use the Windows Hello container for phishing-resistant authentication on resources protected by Entra, including even personal and unmanaged devices.

[IMAGE:index:url:alt]

Enhanced Security with Windows Hello

With this update, device-bound passkeys are integrated into the Windows Hello container. This allows users to authenticate using biometric methods such as facial recognition, fingerprint, or secure PINs.

i

Good to know

This feature is particularly beneficial for enterprises adopting BYOD (Bring Your Own Device) strategies or managing shared and unmanaged PCs.

Key Features of Entra Passkeys

  • Device-bound security: Passkeys are stored locally and do not sync across devices.
  • Multi-account support: Ability to connect multiple Entra accounts on the same Windows device.
  • Complement to Windows Hello for Business: While remaining recommended for managed devices, passkeys add additional security for unmanaged scenarios.
  • Coexistence with WHfB: A passkey cannot be registered on a device if WHfB credentials exist for the same account, unless 50 credentials are exceeded among FIDO2, WHfB, and Mac Platform Credentials.

Enable Entra Passkeys in Your Tenant

Since this feature is available in public preview, it requires manual configuration from the Microsoft Entra Admin Center.

1

Enable FIDO2 Authentication

Verify that the Passkey (FIDO2) method is enabled in your authentication policies.

2

Configure AAGUIDs

Explicitly add the following AAGUIDs to your allowlist:

📄YAML
1# Windows Hello AAGUID identifiers
208987058-cadc-4b81-b6e1-30de50dcbe96
39ddd1817-af5a-4672-a2b9-3e3dd95000a9
46028b017-b1d4-4c02-b4b3-afcdafc96bb2
3

Review Conditional Access Policies

Ensure that your required security level policies support passkey authentication.

Detailed Configuration of Passkeys in Microsoft Entra

  1. Sign in to the Microsoft Entra Admin Center, navigate to Authentication methods, then select Policies.
  2. Enable Passkey (FIDO2): Add the method and target the groups of your choice.
  3. Under the Configure tab, add a profile and set the following parameters:
    • Enforce attestation: No
    • Target types: Device-bound
    • Behavior: Allow
    • Add the AAGUIDs.
  4. Under Enable and target, assign this new configuration to your targeted users.
✦

Tip

While the technical structure is ready, monitor Microsoft updates for information on the final user experience.

Useful Links

  • Official Microsoft Entra Documentation
  • Authentication Methods Overview
  • Windows Hello Security

Glossary

  • Passkey: Passwordless identifier based on FIDO2, bound to the device.
  • Windows Hello: Windows technology for biometric or PIN authentication.
  • WHfB (Windows Hello for Business): Enterprise version of Windows Hello for managed devices.
  • AAGUID: Unique identifier for a specific type of hardware or software authenticator.
Share:
HM

Houssem MAKHLOUF

Microsoft 365 enthusiast & IT professional.

Previous article

Secure BYOD Access with Microsoft Entra Private Access

Mar 10, 2026
Next article

Microsoft Entra Authentication Contexts: Understanding and Mastering

Mar 11, 2026

Related articles

Réseau de données avec une loupe et graphiques informatiques.azure

Azure Copilot Observability Agent: Diagnosing Your Applications

Discover Azure Copilot Observability Agent: automatically diagnose application problems and reduce resolution time with Azure AI.

Jun 29, 20267 min
Cadenas stylisé avec des éléments graphiques abstraits et du texte sur la sécurité.securite

New Microsoft 365 Security Adoption Model

Discover the Microsoft 365 security adoption guide based on Zero Trust principles: modular approaches and modern strategies.

Jun 29, 20264 min
Arbre stylisé en doré sur fond noir avec des éléments circulaires.azure

Choosing the Right Extension Type in Microsoft Entra

Discover Microsoft Entra extension types and choose the optimal configuration for your directory objects based on their usage.

Jun 27, 20264 min