
Microsoft 365 Expert, Author, YouTuber, Speaker & Senior Technology Instructor (MCT)
In a recent YouTube episode, Andy Malone [MVP] presented a first look at a new sign-in option in Entra ID called Synced Passkeys, joined by Microsoft presenter Jeremy Chapman. The video demonstrates how the feature allows a single passkey to work across devices, for example an iPhone and a Mac, simplifying cross-device access. Importantly, Malone shows both user and admin experiences, giving viewers a clear picture of how the technology functions in practice.
The segment frames Synced Passkeys as part of a larger shift toward passwordless authentication, and it explains the basics without heavy technical jargon. As a result, the video is accessible to IT teams and to everyday users who want to understand what will change. Therefore, the episode serves as both a demo and a primer for organizations evaluating the technology.
The video explains that Synced Passkeys are built on FIDO2 standards, which means they use public-key cryptography and biometric checks to create strong, phishing-resistant credentials. Malone walks through registration steps where users add a passkey via the My Account Security Info page, and then choose whether to create it on the current device or on another device. In this approach, credentials can synchronize across a user’s device ecosystem, reducing the risk of lockout after device loss or change.
Additionally, the demonstration shows support for both device-bound and synced passkey types at the same time within an organization. This hybrid model enables administrators to assign stricter controls to high-privilege accounts while offering convenient synced passkeys to general staff. Thus, organizations can balance security and usability without forcing a single one-size-fits-all approach.
Malone also covers the new recovery and verification features tied into the experience, including an optional face check powered by Azure AI for account recovery workflows. This adds a biometric verification layer that can help legitimate users regain access without relying on less secure methods. However, the video notes that these recovery flows must be configured carefully to avoid introducing privacy or security risks.
The episode highlights compelling metrics that make a practical case for adoption: sign-ins with synced passkeys can be far faster than legacy methods, and user success rates appear much higher. For example, Malone cites a dramatic improvement in sign-in time and success when compared to combinations of passwords and traditional multi-factor tools. Therefore, organizations seeking to improve productivity and reduce help desk overhead will find the data persuasive.
Moreover, synced passkeys can lower ongoing costs by replacing SMS or app-based MFA for many users, while also offering a simpler customer and employee experience. Because the solution syncs across devices, it can reduce account recovery incidents that typically require support intervention. Consequently, the balance between reduced operational expense and improved user experience is a strong benefit highlighted in the video.
Despite the benefits, Malone clearly discusses tradeoffs. One tension involves convenience versus control: syncing passkeys across platforms relies on platform providers or third-party managers, which can expand the attack surface and introduce varied security models. Thus, organizations must weigh the ease of cross-device access against reliance on external sync services and their differing security guarantees.
Another challenge relates to cross-platform consistency, because passkey behavior may differ between ecosystems such as Apple, Google, and third-party managers. This inconsistency can complicate user guidance and increase support complexity during rollout. Therefore, IT teams should prepare documentation and test scenarios across device types to minimize user friction.
Finally, privacy and recovery controls require careful configuration to avoid unintended data exposure or weak account recovery paths. While features like Entra Verified ID Face Check can streamline recovery, they also introduce biometric handling that demands strict policy and compliance review. Consequently, administrators must balance the benefits of smooth recovery against regulatory and privacy responsibilities.
Malone’s walkthrough emphasizes staged rollouts and group-based policies as effective strategies for measured adoption. By piloting synced passkeys with a subset of users and maintaining device-bound keys for sensitive roles, organizations can learn and adjust before broad deployment. This phased approach reduces risk and gathers real-world feedback to refine policy settings.
In addition, the video suggests combining technical safeguards with clear user education to increase adoption and reduce support tickets. Training should cover registration, recovery options, and what to do if a device is lost, while admins should monitor adoption metrics and sign-in success rates. Ultimately, this balanced approach helps organizations adopt modern authentication while managing security, usability, and compliance tradeoffs.
Entra ID synced passkeys, Microsoft Entra passkeys, Entra ID passkey setup, Entra passkeys first look, Entra ID passwordless authentication, sync passkeys across devices Entra, Azure AD passkeys sync, Entra ID passkeys walkthrough