Entra ID Synced Passkeys: First Look
Microsoft Entra
Jan 13, 2026 8:51 PM

Entra ID Synced Passkeys: First Look

by HubSite 365 about Andy Malone [MVP]

Microsoft 365 Expert, Author, YouTuber, Speaker & Senior Technology Instructor (MCT)

Microsoft expert: Entra ID Synced Passkeys enable seamless cross device sign in and admin control in Microsoft cloud

Key insights

  • Video summary: The video features Jeremy Chapman from Microsoft Mechanics explaining the new Synced Passkeys feature in Microsoft Entra ID. It demonstrates how users and admins set up and manage synced passkeys across multiple devices.
  • What synced passkeys are: Synced passkeys are FIDO2-based, phishing-resistant credentials that sync across a user’s devices via platform keychains or passkey managers, removing the single-device lock-in of traditional passkeys.
  • Key benefits and metrics: Sign-ins are much faster (reported as 14× faster, about 3 seconds vs 69 seconds) and user adoption is high (99% registration and ~95% sign-in success), making synced passkeys a simpler, lower-cost alternative to SMS or authenticator apps for MFA.
  • How they work and register: Synced passkeys use local biometrics plus device possession for strong authentication. Users add a passkey from the My Account > Security Info page and can create a passkey on the current device or another device like a phone.
  • Admin controls and hybrid deployment: Entra ID supports both device-bound and synced passkeys at the same time and enables group-based policies, so admins can enforce different passkey types for administrators and regular users during phased rollouts.
  • Current status and recovery options: Synced passkeys reached public preview (announced at Ignite 2025). Microsoft also introduced Entra Verified ID Face Check for account recovery, using selfie-to-ID matching and liveness checks to restore access securely.

Overview

In a recent YouTube episode, Andy Malone [MVP] presented a first look at a new sign-in option in Entra ID called Synced Passkeys, joined by Microsoft presenter Jeremy Chapman. The video demonstrates how the feature allows a single passkey to work across devices, for example an iPhone and a Mac, simplifying cross-device access. Importantly, Malone shows both user and admin experiences, giving viewers a clear picture of how the technology functions in practice.


The segment frames Synced Passkeys as part of a larger shift toward passwordless authentication, and it explains the basics without heavy technical jargon. As a result, the video is accessible to IT teams and to everyday users who want to understand what will change. Therefore, the episode serves as both a demo and a primer for organizations evaluating the technology.


How Synced Passkeys Work

The video explains that Synced Passkeys are built on FIDO2 standards, which means they use public-key cryptography and biometric checks to create strong, phishing-resistant credentials. Malone walks through registration steps where users add a passkey via the My Account Security Info page, and then choose whether to create it on the current device or on another device. In this approach, credentials can synchronize across a user’s device ecosystem, reducing the risk of lockout after device loss or change.


Additionally, the demonstration shows support for both device-bound and synced passkey types at the same time within an organization. This hybrid model enables administrators to assign stricter controls to high-privilege accounts while offering convenient synced passkeys to general staff. Thus, organizations can balance security and usability without forcing a single one-size-fits-all approach.


Malone also covers the new recovery and verification features tied into the experience, including an optional face check powered by Azure AI for account recovery workflows. This adds a biometric verification layer that can help legitimate users regain access without relying on less secure methods. However, the video notes that these recovery flows must be configured carefully to avoid introducing privacy or security risks.


Why Organizations Should Care

The episode highlights compelling metrics that make a practical case for adoption: sign-ins with synced passkeys can be far faster than legacy methods, and user success rates appear much higher. For example, Malone cites a dramatic improvement in sign-in time and success when compared to combinations of passwords and traditional multi-factor tools. Therefore, organizations seeking to improve productivity and reduce help desk overhead will find the data persuasive.


Moreover, synced passkeys can lower ongoing costs by replacing SMS or app-based MFA for many users, while also offering a simpler customer and employee experience. Because the solution syncs across devices, it can reduce account recovery incidents that typically require support intervention. Consequently, the balance between reduced operational expense and improved user experience is a strong benefit highlighted in the video.


Tradeoffs and Challenges

Despite the benefits, Malone clearly discusses tradeoffs. One tension involves convenience versus control: syncing passkeys across platforms relies on platform providers or third-party managers, which can expand the attack surface and introduce varied security models. Thus, organizations must weigh the ease of cross-device access against reliance on external sync services and their differing security guarantees.


Another challenge relates to cross-platform consistency, because passkey behavior may differ between ecosystems such as Apple, Google, and third-party managers. This inconsistency can complicate user guidance and increase support complexity during rollout. Therefore, IT teams should prepare documentation and test scenarios across device types to minimize user friction.


Finally, privacy and recovery controls require careful configuration to avoid unintended data exposure or weak account recovery paths. While features like Entra Verified ID Face Check can streamline recovery, they also introduce biometric handling that demands strict policy and compliance review. Consequently, administrators must balance the benefits of smooth recovery against regulatory and privacy responsibilities.


Deployment Advice for Admins

Malone’s walkthrough emphasizes staged rollouts and group-based policies as effective strategies for measured adoption. By piloting synced passkeys with a subset of users and maintaining device-bound keys for sensitive roles, organizations can learn and adjust before broad deployment. This phased approach reduces risk and gathers real-world feedback to refine policy settings.


In addition, the video suggests combining technical safeguards with clear user education to increase adoption and reduce support tickets. Training should cover registration, recovery options, and what to do if a device is lost, while admins should monitor adoption metrics and sign-in success rates. Ultimately, this balanced approach helps organizations adopt modern authentication while managing security, usability, and compliance tradeoffs.


Microsoft Entra - Entra ID Synced Passkeys: First Look

Keywords

Entra ID synced passkeys, Microsoft Entra passkeys, Entra ID passkey setup, Entra passkeys first look, Entra ID passwordless authentication, sync passkeys across devices Entra, Azure AD passkeys sync, Entra ID passkeys walkthrough