Microsoft Entra Adds Windows Passkey Support via Windows Hello
Microsoft is rolling out passkey support for Microsoft Entra on Windows devices, enabling phishing-resistant, passwordless sign-in using Windows Hello (face, fingerprint, or PIN). The capability is opt-in and is scheduled to enter public preview from mid-March through late April 2026 for worldwide tenants, with government cloud environments (GCC, GCC High, DoD) following in a later window. A key security impact is that Entra passkeys extend passwordless authentication to unmanaged Windows devices (e.g., personal/shared endpoints) that previously often fell back to passwords.
Microsoft states the passkeys are device-bound and stored in the Windows Hello container; they are cryptographically bound to the device and not transmitted over the network, reducing exposure to credential phishing and certain malware-based theft scenarios used to bypass MFA. Each Entra account registers its own passkey per device (multiple accounts can coexist on one machine), but passkeys do not sync across devices, requiring separate registration per device. For preview enrollment, administrators must enable the Passkeys (FIDO2) authentication method in Entra Authentication Methods policies, create a passkey profile with the required Windows Hello AAGUIDs, and assign it to the appropriate groups.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
Government cloud rollout scheduled for Entra Windows passkeys
Microsoft scheduled rollout of the feature to government cloud environments, including GCC, GCC High, and DoD, from mid-April through mid-May 2026. This extends the phishing-resistant Windows sign-in capability beyond worldwide tenants.
Entra passkey support begins public preview for worldwide tenants
Microsoft said the new Entra passkey support for Windows would enter public preview for worldwide tenants starting in mid-March 2026. The feature uses device-bound passkeys stored in the Windows Hello container and supports authentication by face, fingerprint, or PIN.
Microsoft announces Entra passkey support for Windows devices
Microsoft announced an opt-in capability to use Microsoft Entra passkeys on Windows devices with Windows Hello, enabling phishing-resistant, passwordless sign-ins. The update extends passwordless authentication to unmanaged Windows devices that are not Entra-joined or registered.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


