What is a passkey in Microsoft Authenticator?

Tags Passkey

Question

What is a passkey in Microsoft Authenticator?

Answer

A passkey in Microsoft Authenticator is a phishing-resistant credential stored in the MS Authenticator app on your smartphone or tablet. It lets you use your smartphone as a secure, phishing-resistant sign-in method instead of relying on passwords, text messages, or approval prompts. When you sign in, Microsoft Authenticator verifies your identity using your phone's built-in security features, such as fingerprint, facial recognition, or device PIN, and securely confirms the sign-in without exposing credentials that could be intercepted by attackers. Because the passkey is stored on your phone and is cryptographically tied to the legitimate sign-in service, it provides stronger protection against phishing attacks while making sign-in faster and easier.

NOTE: Passkeys became the default Microsoft Entra authentication on September 1, 2026.

How it works:

  • Uses device-bound cryptographic keys
  • You authenticate using Face ID / fingerprint / device PIN

Key benefits:

Best for:

  • Users with access to sensitive data

Learn how to set up a passkey in Microsoft Authenticator.

100% helpful - 1 review
Print Article

Related Articles (1)

A device‑bound passkey stored locally in Microsoft Authenticator app on your mobile device is tied to a single device or authenticator instance and does not sync, meaning it must be re‑registered on each new device. It uses biometrics or a PIN to prove your identity and is resistant to phishing while providing tighter control than synced passkey by keeping the credential confined to one device.