Entra Admins: Passkeys, CA, Hard-match
Microsoft Entra
Mar 7, 2026 10:09 PM

Entra Admins: Passkeys, CA, Hard-match

by HubSite 365 about Merill Fernando

Product Manager @ Microsoft 👉 Sign up to Entra.News my weekly newsletter on all things Microsoft Entra | Creator of cmd.ms & idPowerToys.com

Microsoft security expert on Entra passkeys, Conditional Access changes, Graph API, GSA BYOD and Authenticator updates

Key insights

  • Syncable Passkeys: Tenants now get policy-driven passkey profiles and support for passkeys that sync across devices through authenticators.
    These passkeys are phishing-resistant and can be enforced by group-based profiles to separate hardware-bound keys from cloud-synced ones.
  • Conditional Access changes: Microsoft tightened enforcement for policies that use resource exclusions, which can cause some apps to be blocked unexpectedly.
    Admins should review exclusions, test policies in report-only mode, and update legacy or minimal-scope app settings to avoid surprises.
  • Hard-match updates & privileged roles: New hard-match behavior can affect privileged role authentication and cause access issues for accounts still tied to on-prem AD.
    Move privileged accounts to cloud-only or use dedicated admin accounts and Privileged Identity Management to reduce risk.
  • GSA BYOD preview: Global Secure Access (GSA) BYOD features let organizations register and secure personal devices with clearer policy controls.
    Pilot these features, align device compliance rules, and update enrollment flows to keep BYOD user experience smooth and secure.
  • External Authentication Methods GA & admin UX: External auth methods reached general availability, and Microsoft updated the My Account portal and Authenticator flows for easier self-service.
    Use lifecycle workflows and admin units to delegate registration, automate enrollments, and target policies by group.
  • AI & Graph API automation: AI tools now speed up Graph API scripting and identity automation, helping automate lifecycle, reporting, and remediation tasks.
    Validate generated scripts, test in non-production tenants, and monitor changes before applying tenant-wide to avoid configuration drift.

Overview


The YouTube video by Merill Fernando brings together identity experts to unpack a wave of Entra updates that matter to administrators. He is joined by Nathan McNulty and Daniel Bradley, who explain the practical effects of the changes on tenant security and daily operations. The discussion centers on passkeys, updated Conditional Access behavior, a tightening called Hard-match, and a preview of GSA BYOD. Together they highlight both immediate actions and strategic tradeoffs for IT teams.


Throughout the episode, the speakers emphasize how small configuration shifts can cause large outcomes for access controls and user experience. They note that some changes will roll out automatically, making proactive review essential. As a result, organizations should not assume default settings will always match their risk posture. Instead, teams should prepare to test and adjust policies to fit their environment.


Syncable Passkeys and Registration


One major theme is the move toward syncable passkeys that can synchronize across devices via supported managers. The panel explains that this change reduces friction because users no longer need to re-register on every new device, which improves adoption. However, they also warn about tradeoffs: synced keys increase convenience but can slightly broaden the attack surface compared with strictly hardware-bound credentials.


Administrators therefore face a clear choice between usability and maximal protection, and the guests recommend group-based policies to strike a balance. In practice, admins can enforce device-bound keys for high-risk or privileged accounts while allowing synced keys for everyday users. This hybrid approach helps preserve security for critical roles while improving overall user experience.


Conditional Access and Hard-match Changes


The video highlights important changes to Conditional Access that close previous loopholes when policies target "All resources" but exclude specific apps. Nathan and Daniel show how enforcement can now behave more consistently, which reduces unexpected bypasses but may also lead to apps being blocked suddenly. Consequently, organizations should review exclusions and test policies in audit mode before full enforcement.


Relatedly, the discussion covers the so-called Hard-match updates, which affect how privileged role authentication binds to specific on-premises attributes or cloud identifiers. The hosts argue that hard-match tightening is necessary to prevent account misuse in hybrid estates, but they caution that misconfiguration can inadvertently lock out administrators. Therefore, migration planning and staged rollouts are critical to avoid operational disruption.


In addition, the speakers describe mitigation steps such as separating privileged accounts from on-premises Active Directory and adopting cloud-only break-glass accounts. They recommend lifecycle workflows and admin units to control scope and provide rapid recovery options. By taking these steps, teams can reduce the risk of losing access while meeting stronger security requirements.


GSA BYOD and Managing Personal Devices


Merill and his guests also examine the GSA BYOD preview, which aims to let users bring personal devices into secure access models with fewer corporate controls. They praise the potential for increased flexibility, but they also point out privacy and policy challenges that come with BYOD. For instance, admins must balance device telemetry needs with user privacy expectations and legal constraints.


The practical tradeoffs include deciding how much device-level control to require versus relying on session-based controls and conditional signals. Organizations that opt for BYOD pilots should implement clear consent models and targeted policies for high-risk applications. Moreover, cross-team coordination between security, legal, and HR becomes essential when personal devices access sensitive systems.


AI, Graph API, and Operational Impacts


Finally, the video explores how AI and automation reshape identity operations, especially when paired with the Graph API. The guests describe automation examples that speed up tasks like bulk passkey migration and policy analysis, improving efficiency. Yet they also flag risks such as automation errors that could apply policies too broadly if not properly scoped and tested.


To manage these risks, teams should adopt staged automation, include manual approvals for high-impact operations, and maintain detailed change logs for audits. In addition, training for engineers on the new APIs and the implications of AI-driven scripts will reduce mistakes and speed recovery. In short, automation offers big gains but requires sound controls to prevent large-scale misconfigurations.


Overall, the video provides a pragmatic roadmap for Entra administrators: pilot passkeys, validate revised Conditional Access behaviors, plan migrations for privileged accounts, and treat BYOD and automation as controlled experiments. By weighing usability against security and testing changes in stages, teams can adopt these advances without compromising availability or compliance.


Microsoft Entra - Entra Admins: Passkeys, CA, Hard-match

Keywords

Entra Passkeys, Conditional Access policies, hard-match updates, GSA BYOD compliance, passwordless authentication, Azure AD Entra, Entra admin best practices, BYOD security guidance