passkey enrollment for entra id: helpdesk guide
Helpdesk guide to passkey enrollment for Entra ID: policy check, the self-service enrollment flow, and verification. Use when rolling out phishing-resistant MFA. Not for SMS or app-based MFA issues.
TL;DR
Entra ID supports passkeys, including FIDO2 security keys and device-bound passkeys, as phishing-resistant MFA. Enrollment is self-service once the Authentication methods policy allows passkeys for the user. Helpdesk work is mostly confirming the policy targets the user and walking them through the browser prompts.
The query
passkey enrollment for entra id: helpdesk guideUse this when
- rolling out passkeys as the primary MFA method
- user asks how to set up a passkey for their work account
- verifying a passkey registration completed correctly
Not for
- Authenticator app or SMS code problems (different methods)
- users on browsers that do not support WebAuthn
- shared devices where a personal passkey makes no sense
Steps
- Check the Authentication methods policy: Passkey (FIDO2) is enabled and the user is in a targeted group. Expected output: the user is in scope
- The user signs in and opens the security info page, then chooses Add method and Passkey. Expected output: the add-method wizard opens
- The browser prompts for the security key or device biometrics; the user follows the prompts. Expected output: the ceremony completes without errors
- Confirm the new passkey appears in the user's methods list. Expected output: registration visible to the admin as well
- Have the user sign out and sign back in using the passkey. Expected output: sign-in succeeds with the passkey
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_sUq-hE86VkjKUtCP7IKR9Q
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.