Microsoft Entra ID supports passkeys stored on FIDO2 security keys, alongside other supported passkey options. For IT teams planning the move from SMS or voice authentication, the key decision is which approved method fits each employee’s devices, work environment, and recovery needs. Compatibility depends on the authenticator, browser, operating system, and tenant policy. Microsoft’s passkey deployment documentation

Microsoft announced its passkey transition in July. Its newer implementation guidance, updated September 23, 2026, provides a more detailed schedule. That distinction matters when planning a rollout: an early announcement is a starting point, while current deployment documentation should guide decisions. Microsoft’s announcement

What is changing in Microsoft Entra’s passkey rollout?

According to Microsoft’s current guidance, automatic passkey enablement and registration prompts began rolling out from September 1 for users enabled for SMS or voice authentication.

Microsoft-provided SMS and voice delivery is scheduled to retire on February 1, 2027 for most users. Global Administrators and external users follow a July 1, 2027 date; internal guest users remain in the February group. Organizations with a continuing need for telephony can evaluate supported third-party providers. Microsoft also documents a temporary opt-out from automatic enablement, distinct from the later enforcement deadlines. Current migration guidance

These changes concern Entra ID, rather than every Microsoft consumer account. The announcement specifies the public cloud; other cloud environments have separate schedules. A registration campaign should also not be confused with proof that every employee has already switched methods. Announcement scope

How do passkeys and FIDO2 security keys work together?

Passkey describes a credential, while a FIDO2 security key is a physical authenticator that can hold and use that credential. Passkeys can also be available through phones, computers, and credential managers. The FIDO Alliance distinguishes synced passkeys from device-bound passkeys, including those stored on security keys. FIDO Alliance passkey overview

This gives deployment teams a choice. An employee who uses a managed laptop all day may have different needs from a worker moving among shared terminals. Someone who cannot use a personal phone at work needs an authentication path that fits that constraint. The deployment should start with these situations, then select an approved method for each.

A physical security key can be a useful option when an organization wants a portable authenticator that employees carry separately from their workstation. That is a reason to evaluate hardware—not a reason to assume every hardware model will work in every environment.

How should IT teams test FIDO2 security key compatibility?

Before buying a large batch, test the exact combination of key, operating system, browser, identity policy, and application. Microsoft documents controls for enabling passkeys and restricting which authenticators can be registered. Tenant configuration therefore matters alongside the key’s capabilities. Enable passkeys in Entra ID

Our deployment recommendation is to define a small pilot with a clear acceptance test:

  • Can the employee register the intended key under the organization’s policy?
  • Can they sign in to their actual applications from the devices they use?
  • Do USB or NFC connections work in those specific environments?
  • Can support restore access after a lost key without improvising a weaker process?
  • Can administrators revoke the lost authenticator and confirm that access is restored?

Document the results by user group. A successful demonstration on one administrator’s laptop is useful evidence, but it does not answer every frontline or remote-work scenario.

Plan backup authenticators and account recovery

A rollout is unfinished if it explains the first login but leaves the second key, a lost device, or employee departure to chance. Our recommendation is to register an approved backup authenticator where supported, store it separately, and rehearse recovery before expanding the pilot.

The same discipline should apply to help-desk instructions. Tell employees where to begin registration using a known company portal, what prompts to expect, and how to report an unexpected request. Measure successful use and support friction, rather than only counting shipped keys.

Choosing a Thetis FIDO2 security key for a pilot

For organizations evaluating physical authenticators, Thetis’s FIDO2 security key collection is a place to compare available options. Confirm the selected model’s specifications and your tenant’s requirements before deployment; this article does not certify a particular Thetis model for a particular Entra configuration.

Microsoft’s transition is an opportunity to improve the entire authentication experience. Choose the credential, test the workflow, prepare recovery, and give employees a clear path to use it.

Information checked September 29, 2026. Deployment schedules and platform policies may change.