Skip to content
Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices

Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices

Written By Anoop C Nair
Last Updated November 28, 2025
Posted In Entra
SHARE

Let’s discuss Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices. At Ignite 2025, Microsoft announced that Entra ID now supports Synced Passkeys across multiple credential providers.

This new feature is currently in preview and it represent the next step in passwordless authentication, balancing strong security with user convenience. This new feature making Entra one of the first enterprise identity platforms to embrace them.

With Setup Synced Passkeys users can authenticate with passkeys stored in cloud providers like Apple iCloud Keychain, Google Password Manager, 1Password, and Bitwarden. As you know that, Before this, Entra only supported device‑bound passkeys (stored locally on a TPM or hardware security key).

Synced passkeys expand usability by letting credentials follow the user across devices. The rollout is part of Microsoft’s broader passwordless strategy and Zero Trust alignment, aiming to make secure sign‑in easier and more scalable for enterprises.

Patch My PC
Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices - Fig.1
Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices – Fig.1

Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices

With this new capability, credentials to be phishing‑resistant and portable across devices, solving usability and recovery challenges. While they improve convenience, organizations must evaluate trust in the provider and enforce Conditional Access policies to ensure compliance.

Advantages
For End users it easies passwordless sign‑in across devices without re‑enrollment.
For Admins, it Simplifies rollout of passwordless authentication at scale.
For security Teams, it maintains phishing resistance while reducing reliance on device‑bound credentials.
Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices – Table.1

How to Setup Synced Passkeys in Entra ID

Here I am going to shows the demo which is showned on Ignite 2025 event by Nichole Peterson Senior Product Marketing Manager at Microsoft. Sign in to Microsoft Entra admin center > Go to Authentication Methods > Policies > Passkeys (FIDO2).

Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices - Fig.2 – Cred to Nichole Peterson MS
Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices – Fig.2 – Cred to Nichole Peterson MS

Enable and Target

On this window you can see the option to Enable and Target Passkeys. Here 2 options are provided which are included and excluded. And here the passkey profile is FIDO2 which is the default profile, Click on that.

Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices - Fig.3 – Cred to Nichole Peterson MS
Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices – Fig.3 – Cred to Nichole Peterson MS

Configure Passkeys

On the Configure Passkey tab, you can add profile for passkeys. Click on the Add profile button and enter the Name and Target type for Passkeys. Here the Name is Synced Passkeys and Target types are device-bound, synced(preview). Then click on the Save button.

Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices - Fig.4 – Cred to Nichole Peterson MS
Setup Synced Passkeys in Entra ID for Credentials to be Phishing‑Resistant and Portable Across Devices – Fig.4 – Cred to Nichole Peterson MS

Complete Sync Passkeys

After clicking on the Save button, you will get the notification on the portal as saved authentication method. The screenshot below shows the notification and Authentication methods changed.

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read