Microsoft Entra Passwordless Authentication โ€” Complete Field Guide

ENTRA ID ยท Modern Endpoint Guides

๐Ÿ”‘ Microsoft Entra Passwordless Authentication

Eliminate passwords entirely with FIDO2 security keys, Windows Hello for Business, and Microsoft Authenticator phone sign-in. Step-by-step deployment guide โ€” from policy enablement to end-user rollout.

FIDO2 Windows Hello for Business Phishing-Resistant MFA Zero Trust

๐Ÿ“‹ Why Passwordless?

Passwords are the root cause of over 80% of identity breaches โ€” phishing, credential stuffing, and spray attacks all exploit them. Microsoft Entra Passwordless replaces the password with cryptographic credentials tied to the device and the user, making phishing structurally impossible.

entra.microsoft.com โ€บ Identity โ€บ Overview โ€บ Security Score
๐Ÿ  Home
๐Ÿ” Identity
๐Ÿ”’ Protection
โš™๏ธ Authentication
Home โ€บ Identity Secure Score
Secure Score โ€” Identity
Improvement ActionScore ImpactStatus
Require MFA for all users +10 pts Complete
Enable passwordless sign-in for users +9 pts In Progress
Block legacy authentication +7 pts Not Started
Register FIDO2 security keys +6 pts In Progress
๐Ÿ’ก Passwordless contributes up to +15 points to your Microsoft Secure Score โ€” the highest single-action identity improvement available.
๐Ÿ“ธ Microsoft Entra admin center โ€” Identity Secure Score. Enabling passwordless is one of the highest-impact security improvements available.
Traditional PasswordPasswordless (Entra)
Phishable via fake login pagesCryptographically bound to origin โ€” phishing-resistant
Reused across sitesUnique key pair per service
Stolen in breach databasesPrivate key never leaves device
Spray / brute-force attacksNo password to brute-force
Requires complex password policyBiometric or PIN โ€” simpler UX, stronger security

๐Ÿ›ก๏ธ Passwordless Authentication Methods

Entra supports three passwordless methods. Choose based on user role, device type, and security requirements.

Phishing-Resistant Hardware

๐Ÿ” FIDO2 Security Keys

Hardware tokens (YubiKey, Feitian, etc.) containing a private key that never leaves the device. Authentication requires physical possession + PIN/biometric. Best for shared workstations, privileged admins, and high-security scenarios.

  • Platforms: Windows 10/11, macOS, Linux, iOS, Android
  • Works on: Entra-joined, Hybrid-joined, BYOD browsers
  • Best for: Admins, shared machines, SOC analysts
Phishing-Resistant Built-in

๐Ÿ’ป Windows Hello for Business (WHfB)

Asymmetric key pair provisioned on the TPM chip of a Windows device. Sign in with face, fingerprint, or PIN โ€” the PIN unlocks the TPM key, not a password. Works offline and on-premises.

  • Platforms: Windows 10/11 with TPM 2.0
  • Works on: Entra-joined, Hybrid-joined devices
  • Best for: Corporate laptop/desktop users
Phishing-Resistant (Passkey)

๐Ÿ“ฑ Microsoft Authenticator โ€” Phone Sign-in / Passkey

Two modes: (1) Phone sign-in โ€” approve a push notification with number matching; (2) Passkey (FIDO2) โ€” phone stores a FIDO2 passkey, sign in with biometric. Passkey mode is phishing-resistant; phone sign-in has number matching to mitigate MFA fatigue.

  • Platforms: iOS 17+, Android 9+
  • Works on: All Entra-joined and personal devices
  • Best for: Information workers, remote employees, BYOD
MethodPhishing-ResistantWorks OfflineHardware RequiredIdeal Scenario
FIDO2 Keyโœ… Yesโœ… Yesโœ… TokenAdmins, shared PCs
Windows Hello for Businessโœ… Yesโœ… YesTPM 2.0 (built-in)Corporate laptops
Authenticator Passkeyโœ… Yesโœ… YesPhoneMobile workers, BYOD
Authenticator Phone Sign-inโš ๏ธ Number matchingโŒ NoPhoneGeneral workforce

โš™๏ธ Step 1 โ€” Enable Authentication Methods Policy

All passwordless methods are controlled from the Authentication Methods Policy in Entra. This is the single control plane โ€” the legacy MFA settings in the Microsoft 365 admin center are deprecated.

1

Navigate to Authentication Methods

Entra admin center โ†’ Protection โ†’ Authentication methods โ†’ Policies

๐Ÿ“ entra.microsoft.com โ€บ Protection โ€บ Authentication methods โ€บ Policies
2

Select each method to configure

You'll see: FIDO2 security key, Microsoft Authenticator, Windows Hello for Business. Click each to enable and scope.

3

Scope to a pilot group first

Set Target โ†’ Select group โ†’ Passwordless-Pilot. Enable for all users only after pilot success.

โš ๏ธ Do NOT enable for all users immediately โ€” pilot with 20-50 users and resolve registration blockers first.
entra.microsoft.com โ€บ Protection โ€บ Authentication methods โ€บ Policies
๐Ÿ”’ Protection
๐Ÿ”‘ Authentication methods
๐Ÿ“‹ Policies
๐Ÿ“Š Activity
Protection โ€บ Authentication methods โ€บ Policies
Authentication methods โ€” Policies
MethodStateTarget
๐Ÿ” FIDO2 security key Enabled Passwordless-Pilot (42 users)
๐Ÿ“ฑ Microsoft Authenticator Enabled All users
๐Ÿ’ป Windows Hello for Business Enabled All users
๐Ÿ“ฒ SMS Enabled All users (reduce over time)
๐Ÿ”‘ Temporary Access Pass Enabled Helpdesk group
๐Ÿ’ก Enable Temporary Access Pass (TAP) for helpdesk. TAP is a time-limited passcode used to bootstrap passwordless registration without a password โ€” essential for new hires and key recovery.
๐Ÿ“ธ Entra โ€บ Authentication Methods โ€บ Policies โ€” FIDO2 enabled for pilot group, Authenticator and WHfB enabled for all, TAP enabled for helpdesk.
๐Ÿ’ก Temporary Access Pass (TAP) โ€” Enable TAP in Authentication Methods and assign it to Helpdesk admins. When a user loses their passwordless credential, helpdesk issues a TAP โ†’ user signs in โ†’ registers new credential โ†’ TAP expires. This is the passwordless break-glass recovery path.

๐Ÿ” Step 2 โ€” Configure FIDO2 Security Keys

FIDO2 keys are the strongest passwordless option โ€” hardware-bound, phishing-resistant, works on shared PCs without a user profile. Required for privileged accounts.

1

Enable FIDO2 in Authentication Methods Policy

Entra admin center โ†’ Protection โ†’ Authentication methods โ†’ FIDO2 security key โ†’ Enable โ†’ Select target group

2

Configure FIDO2 Settings

Allow self-service setup: Yes | Enforce attestation: Yes (for high-security) | Enforce key restrictions: Optional (to limit to specific vendors)

๐Ÿ“ FIDO2 Policy โ†’ Configure tab โ†’ Key restrictions: add AAGUIDs of approved keys (YubiKey, Feitian, etc.)
3

User Self-Registration โ€” Security Info

User navigates to: aka.ms/mysecurityinfo โ†’ + Add method โ†’ Security key โ†’ USB device or NFC โ†’ Insert key โ†’ Set PIN โ†’ Touch key to confirm

4

Sign in with FIDO2 Key

Windows sign-in โ†’ Sign-in options โ†’ Security key โ†’ Enter PIN โ†’ Touch key. Browser sign-in โ†’ use passkey/security key option in the Entra login page.

mysecurityinfo.microsoft.com โ€บ Security info โ€บ Add method
๐Ÿ” Security info
๐Ÿ“ฑ Devices
๐Ÿ”‘ Passkeys
Security info โ€บ Add sign-in method
Add a method โ€” Security key (FIDO2)
๐Ÿ”
Set up your security key
Insert your USB security key or hold your NFC key near your device
USB device
NFC device
Step 2 of 4: Create a PIN for your security key (min. 4 digits, max 63 characters)
Security key PIN
Confirm PIN
๐Ÿ’ก Touch the gold contact on your key when it blinks โ€” this is the user presence confirmation required by FIDO2 protocol.
๐Ÿ“ธ mysecurityinfo.microsoft.com โ€” FIDO2 security key registration flow. User inserts key, sets a PIN, and confirms with a physical touch.
โš ๏ธ Key Restriction Important Note: If you enforce key restrictions (AAGUID allowlist), users cannot register any key not on the list โ€” including keys they may already own. Coordinate with procurement before enabling restrictions in production.

๐Ÿ’ป Step 3 โ€” Windows Hello for Business (WHfB)

WHfB provisions a key pair on the device TPM at first sign-in. The user signs in with face, fingerprint, or a local PIN โ€” the PIN unlocks the TPM key, not an AD or Entra password. No password is sent over the network.

Prerequisites

RequirementDetail
Device join typeEntra-joined (cloud-only) or Hybrid Entra-joined
TPMTPM 2.0 required (most devices after 2016 have it)
Intune / GPOIntune policy OR Group Policy to configure WHfB
OSWindows 10 1903+ or Windows 11
LicenseEntra ID P1 or P2 (included in M365 E3/E5)
1

Create WHfB Intune Policy

Intune admin center โ†’ Endpoint security โ†’ Account protection โ†’ Create policy โ†’ Windows โ†’ Windows Hello for Business

๐Ÿ“ intune.microsoft.com โ€บ Endpoint security โ€บ Account protection
2

Configure Key Settings

Configure Windows Hello for Business: Enable | Use a Trusted Platform Module (TPM): Required | Minimum PIN length: 6 | Biometrics: Enable

3

Assign to Pilot Group

Assignments โ†’ Add groups โ†’ Passwordless-Pilot-Devices. Exclude helpdesk and shared kiosks until they have separate policies.

4

User Experience โ€” First Sign-in

After policy applies, Windows prompts: "Your organization requires Windows Hello." โ†’ User sets PIN โ†’ Camera scans face or fingerprint reader enrolls biometric โ†’ Done.

๐Ÿ“ Provisioning happens at first sign-in after policy applies โ€” typically within 15 minutes of device enrollment or next sync.
intune.microsoft.com โ€บ Endpoint security โ€บ Account protection โ€บ WHfB Policy
๐Ÿ  Home
๐Ÿ’ป Devices
๐Ÿ”’ Endpoint security
๐Ÿ“‹ Account protection
Endpoint security โ€บ Account protection โ€บ WHfB-Corp-Policy
Windows Hello for Business โ€” WHfB-Corp-Policy
Configuration settings
SettingValue
Configure Windows Hello for BusinessEnable
Use a Trusted Platform Module (TPM)Required
Minimum PIN length6 characters
Maximum PIN length127 characters
Lowercase letters in PINNot configured
Use biometricsEnable
Use enhanced anti-spoofingEnable
Certificate for on-premises resourcesNot configured (cloud-only)
โš ๏ธ Require TPM ensures keys are hardware-protected. Without this, keys may store in software โ€” acceptable for testing, not production.
๐Ÿ“ธ Intune โ€บ Endpoint Security โ€บ Account Protection โ€” WHfB policy with TPM Required, biometrics enabled, and anti-spoofing enforcement.

๐Ÿ“ฑ Step 4 โ€” Microsoft Authenticator Passwordless

For mobile workers and BYOD scenarios. Two levels: Phone sign-in (approve push notification with number matching) and Passkey (FIDO2 on phone โ€” phishing-resistant, works even offline).

1

Enable Microsoft Authenticator in Policy

Entra admin center โ†’ Protection โ†’ Authentication methods โ†’ Microsoft Authenticator โ†’ Enable โ†’ Configure

2

Enable Passkey (FIDO2) in Authenticator

In the Authenticator policy settings, enable: Allow use of Microsoft Authenticator OTP โ€” OFF | Passwordless sign-in โ€” ON | Show app name / location in notification โ€” ON | Number matching โ€” Enabled

๐Ÿ“ Number matching prevents MFA fatigue attacks โ€” user must type the number shown on login screen into the app.
3

User Registers Passkey โ€” Security Info

User โ†’ aka.ms/mysecurityinfo โ†’ Add method โ†’ Passkey (Microsoft Authenticator) โ†’ Scan QR code โ†’ Biometric confirmation on phone โ†’ Done

4

Sign In โ€” Passwordless Flow

Login page โ†’ enter username โ†’ "Approve a request on the Microsoft Authenticator app" โ†’ notification appears โ†’ user approves with biometric. For passkey: select "Sign in another way" โ†’ Passkey โ†’ biometric on phone.

entra.microsoft.com โ€บ Protection โ€บ Authentication methods โ€บ Microsoft Authenticator
๐Ÿ”’ Protection
๐Ÿ“ฑ Authenticator
โš™๏ธ Configure
Authentication methods โ€บ Microsoft Authenticator โ€บ Configure
Microsoft Authenticator โ€” Advanced settings
Passwordless & MFA Settings
Require number matching
Enabled โ€” Microsoft managed
Show app name in push notifications
Enabled
Show geographic location in push notifications
Enabled
Passwordless sign-in (phone sign-in)
Enabled
๐Ÿ’ก Passkey (FIDO2) in Authenticator is registered separately via Security Info (aka.ms/mysecurityinfo) โ€” it appears as a Passkey entry, not as an Authenticator entry.
๐Ÿ“ธ Entra โ€บ Authentication Methods โ€บ Microsoft Authenticator advanced settings. Number matching and location context must be enabled to mitigate MFA fatigue.

๐Ÿ”’ Step 5 โ€” Conditional Access for Passwordless

Create two CA policies: one requiring phishing-resistant MFA for privileged roles, and one to drive the general workforce toward passwordless over time.

1

Policy 1 โ€” Require Phishing-Resistant MFA for Admins

Users: All directory roles (Global Admin, etc.) | Conditions: All apps | Grant: Require authentication strength โ†’ Phishing-resistant MFA

๐Ÿ“ Phishing-resistant MFA strength = FIDO2 key OR WHfB OR Authenticator Passkey. Excludes phone sign-in and TOTP.
2

Policy 2 โ€” Nudge Workforce Toward Passwordless

Users: All users | Apps: Office 365 | Grant: Require MFA (allows any MFA) โ†’ Enable registration nudge in Authenticator settings to prompt users to set up passkeys.

3

Policy 3 โ€” Block Legacy Authentication

Users: All | Conditions: Client apps โ†’ Other clients (legacy auth) | Grant: Block. Legacy auth cannot satisfy modern MFA โ€” it must be blocked.

entra.microsoft.com โ€บ Protection โ€บ Conditional Access โ€บ Policies โ€บ New policy
๐Ÿ”’ Protection
๐Ÿ“‹ Conditional Access
+ New policy
Conditional Access โ€บ CA-ADMIN-PhishingResistant-MFA
CA-ADMIN-PhishingResistant-MFA
Assignments
SectionSetting
UsersDirectory roles: All privileged admin roles
Target resourcesAll cloud apps
Conditions โ†’ Sign-in riskNot configured (admin policy applies always)
Access controls โ€” Grant
SettingValue
Grant accessโœ… Selected
Require authentication strengthPhishing-resistant MFA
โš ๏ธ Enable in Report-only mode first. Monitor sign-in logs for 1-2 weeks before switching to Enabled โ€” look for any admin accounts without a passwordless credential registered.
๐Ÿ“ธ CA policy for admins requiring phishing-resistant MFA strength. Always start in Report-only and monitor the sign-in logs before enforcing.
โš ๏ธ Break-glass accounts: Exclude your break-glass emergency admin accounts from ALL CA policies. These accounts should have long random passwords stored in a sealed envelope โ€” not passwordless. They are your recovery path if CA policies lock everyone out.

โญ Step 7 โ€” Set Passwordless as Default for Specific Users

By default, Entra presents the sign-in method the user registered first โ€” often a password + SMS. Two mechanisms let you change this: System-preferred MFA (nudges Entra to offer the strongest method first) and a CA authentication strength policy (enforces it hard).

Option A โ€” System-preferred MFA (Recommended First Step)

Entra automatically evaluates which passwordless method the user has registered and presents it first. The priority order:

PriorityMethodCondition
1stFIDO2 security keyUser has registered a key
2ndWindows Hello for BusinessDevice is Entra/Hybrid joined with TPM
3rdAuthenticator PasskeyPasskey registered in Authenticator app
4thAuthenticator push notificationAuthenticator registered
5thTOTP / SMSFallback only
1

Navigate to Authentication Methods โ†’ Settings

Entra admin center โ†’ Protection โ†’ Authentication methods โ†’ Settings

๐Ÿ“ entra.microsoft.com โ€บ Protection โ€บ Authentication methods โ€บ Settings
2

Enable System-preferred MFA

Find "System-preferred multifactor authentication" โ†’ Set to Microsoft managed (on by default for new tenants) or explicitly Enabled.

3

Scope to target group

Include: Passwordless-Pilot group. Exclude: users still in onboarding who haven't registered a passwordless method yet.

โš ๏ธ If a user has no passwordless method registered, system-preferred MFA falls back to their strongest registered method โ€” it never blocks sign-in.
entra.microsoft.com โ€บ Protection โ€บ Authentication methods โ€บ Settings
๐Ÿ”’ Protection
๐Ÿ”‘ Authentication methods
โš™๏ธ Settings
Authentication methods โ€บ Settings
Authentication methods โ€” Settings
System-preferred multifactor authentication
State
When enabled, Entra ID presents the strongest available authentication method to the user.
Enabled
Target
Include
Passwordless-Pilot
Exclude
Onboarding-Users
๐Ÿ’ก System-preferred MFA is a nudge, not an enforcement. Users can still click "Use a different method". Use Option B to enforce hard.
๐Ÿ“ธ Entra โ€บ Authentication methods โ€บ Settings โ€” System-preferred MFA enabled for the Passwordless-Pilot group.

Option B โ€” Enforce with Conditional Access Authentication Strength

Hard enforcement: users in scope cannot sign in with password + SMS โ€” they must use a passwordless method. Use this after the pilot group has successfully registered.

1

Create a new CA Policy

Protection โ†’ Conditional Access โ†’ New policy โ†’ Name: CA-Passwordless-Enforce-Pilot

2

Assignments

Users: Include โ†’ Passwordless-Pilot group | Resources: All cloud apps (or Office 365)

3

Grant โ€” Authentication Strength

Grant access โ†’ Require authentication strength โ†’ Passwordless MFA (includes FIDO2, WHfB, Authenticator Passkey โ€” excludes password + push).

๐Ÿ“ "Passwordless MFA" is a built-in Entra preset. You can create a custom strength to restrict further (e.g. FIDO2 only).
4

Start in Report-only

Set policy state to Report-only. Monitor sign-in logs for "Report-only: Failure" entries. Switch to Enabled only after all group members have a passwordless credential registered.

entra.microsoft.com โ€บ Protection โ€บ Conditional Access โ€บ CA-Passwordless-Enforce-Pilot
๐Ÿ”’ Protection
๐Ÿ“‹ Conditional Access
Conditional Access โ€บ CA-Passwordless-Enforce-Pilot
CA-Passwordless-Enforce-Pilot
SectionSetting
Users โ€” IncludePasswordless-Pilot
Users โ€” ExcludeBreak-Glass-Accounts
Target resourcesAll cloud apps
Authentication strengthPasswordless MFA
Policy stateReport-only
โš ๏ธ Before enabling: Sign-in logs โ†’ filter by this policy โ†’ look for "Report-only: Failure". Each entry = a user who will be blocked.
๐Ÿ“ธ CA policy enforcing Passwordless MFA strength for the pilot group. Report-only first โ€” verify all users have registered before enabling.
โš ๏ธ Always verify registration before enforcing: Filter sign-in logs by group + CA policy + Report-only: Failure before switching to Enabled. Every user in that list will be locked out the moment you enable the policy.

๐Ÿ“Š Step 6 โ€” Monitor Passwordless Adoption

Track registration progress, sign-in method usage, and authentication failures from the Entra admin center.

entra.microsoft.com โ€บ Identity โ€บ Monitoring โ€บ Authentication methods activity
๐Ÿ“Š Monitoring
๐Ÿ”‘ Auth methods activity
๐Ÿ“ˆ Sign-in logs
Monitoring โ€บ Authentication methods activity
Authentication methods โ€” Usage & Insights
MethodRegistered usersSign-ins (30d)% of total
Windows Hello for Business 847 24,310 41%
Microsoft Authenticator (push) 1,203 18,640 31%
FIDO2 security key 67 3,880 6%
Password (password hash sync) 1,500 12,700 22%
๐Ÿ’ก Target: password sign-ins โ†’ <5% within 6 months. Use the "Registration and reset events" report to identify users still needing passwordless enrollment.
๐Ÿ“ธ Entra โ€บ Monitoring โ€บ Authentication methods activity. Use this dashboard weekly to track passwordless adoption and identify stragglers.

Key Metrics to Track

MetricTargetWhere to Find
% users with passwordless registered>80% in 90 daysAuth methods activity โ†’ Registration
% sign-ins using passwordless>70% in 180 daysAuth methods activity โ†’ Usage
SSPR registration rate>95%Auth methods activity
CA policy failures (block)<1% per daySign-in logs โ†’ filter by Failure
Legacy auth sign-in attempts0 after block policySign-in logs โ†’ Client app = Other clients

โœ… Deployment Checklist โ€” Entra Passwordless

    ๐Ÿ—๏ธ Foundation
  • Authentication Methods Policy โ€” migrated from legacy MFA settings
  • Temporary Access Pass (TAP) โ€” enabled and scoped to helpdesk
  • Break-glass accounts โ€” excluded from all CA policies
  • Pilot group created (20-50 users covering IT, HR, Finance)
  • ๐Ÿ” FIDO2 Security Keys
  • FIDO2 enabled in Authentication Methods for pilot group
  • Approved key vendors list configured (if key restrictions needed)
  • Users registered keys via aka.ms/mysecurityinfo
  • Windows sign-in via security key tested successfully
  • ๐Ÿ’ป Windows Hello for Business
  • TPM 2.0 confirmed on all target devices
  • WHfB Intune policy created and assigned to pilot group
  • Biometrics (face/fingerprint) enabled in policy
  • Users completed WHfB provisioning at first sign-in
  • Hybrid key trust configured (for hybrid-joined devices)
  • ๐Ÿ“ฑ Microsoft Authenticator
  • Authenticator passwordless enabled in policy
  • Number matching โ€” Enabled (Microsoft managed)
  • App name and location in notifications โ€” Enabled
  • Users registered phone sign-in via Security Info
  • ๐Ÿ”’ Conditional Access
  • CA policy: Admins โ†’ Phishing-resistant MFA (Report-only first)
  • CA policy: All users โ†’ Require MFA for Office 365
  • CA policy: Block legacy authentication
  • CA policies moved from Report-only โ†’ Enabled after monitoring period
  • ๐Ÿ“Š Monitoring
  • Auth methods activity dashboard reviewed weekly
  • Sign-in log alerts for legacy auth attempts
  • Passwordless adoption % tracked monthly
  • Rollout expanded from pilot โ†’ department โ†’ all users