## TL;DR
Entra ID supports passkeys, including FIDO2 security keys and device-bound passkeys, as phishing-resistant MFA. Enrollment is self-service once the Authentication methods policy allows passkeys for the user. Helpdesk work is mostly confirming the policy targets the user and walking them through the browser prompts.

## The query
```text
passkey enrollment for entra id: helpdesk guide
```

## Use this when
- rolling out passkeys as the primary MFA method
- user asks how to set up a passkey for their work account
- verifying a passkey registration completed correctly

## Not for
- Authenticator app or SMS code problems (different methods)
- users on browsers that do not support WebAuthn
- shared devices where a personal passkey makes no sense

## Steps
1. Check the Authentication methods policy: Passkey (FIDO2) is enabled and the user is in a targeted group. Expected output: the user is in scope
2. The user signs in and opens the security info page, then chooses Add method and Passkey. Expected output: the add-method wizard opens
3. The browser prompts for the security key or device biometrics; the user follows the prompts. Expected output: the ceremony completes without errors
4. Confirm the new passkey appears in the user's methods list. Expected output: registration visible to the admin as well
5. Have the user sign out and sign back in using the passkey. Expected output: sign-in succeeds with the passkey

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_sUq-hE86VkjKUtCP7IKR9Q
