
Entra ID Synced Passkeys How to Enable and Use Them with Password Managers
Microsoft Entra ID now supports synced passkeys in public preview. This allows users to store their passkeys inside a password manager and use them across multiple devices without re-registering on every new device.
Prerequisites
Before you start, make sure:
- Entra ID tenant is enabled for preview features
Users have:
-
A supported password manager (for example iCloud Keychain, Google Password Manager, 1Password, etc.)
-
A device that supports WebAuthn / passkeys
-
FIDO2 / Passkey authentication is not blocked globally
What Changes Compared to Device-Bound Passkeys
With synced passkeys:
-
✅ Passkeys roam across devices
-
✅ Easy recovery if a device is lost
-
✅ No physical security key needed
-
❌ No strong hardware attestation
-
❌ The security level depends on the password manager protection
This is a convenience vs control trade-off.
Recommended Deployment Strategy
Use synced passkeys for:
-
Standard end users
-
Remote workers
-
Multi-device users
Keep device-bound passkeys only for:
-
Global admins
-
Privileged roles
-
Break-glass accounts
-
Security-sensitive users
You can enforce this using multiple passkey profiles with different group assignments.
Enable Synced Passkeys in Entra ID
-
Go to Entra ID
-
Open Protection > Authentication methods
-
Select Passkey (FIDO2)
-
Enable the Preview banner for passkey profiles (if not already shown)
-
Open the Default passkey profile or create a new profile
-
Set Passkey storage type to Synced passkeys

This enables synced passkey for all users (Default Profile). You can also enable it ust for a subset with a custom profile which can be assigned to a specific usergroup.

User Registration with a Password Manager
After assignment, the user registers like this:
-
User signs in to aka.ms/setupmfa
-
Opens Security info
-
Selects Add sign-in method
-
Chooses Passkey
-
The browser prompts for a password manager
-
The passkey is stored inside the manager and automatically synced to other devices linked to the same vault
From now on, the user can sign in on any new device where the same password manager is already signed in.
No re-enrollment required.



Sign-in Experience

Important Security Notes
- Do not allow synced passkeys for global admin roles
Ensure:
-
Strong MFA is required for password manager access
-
Device compliance is still enforced via Conditional Access
-
Users storing corp credentials in personal vaults is a new risk you must consciously accept
Operational note: Entra ID Synced Passkeys How to Enable and Use Them with Password Managers
For Microsoft admins, the practical point in Entra ID Synced Passkeys How to Enable and Use Them is to treat the change as something that should be validated before it becomes tenant-wide behavior. Check the affected users, devices, assignments and support process so the Nugget turns into a controlled operational improvement instead of another undocumented setting.
Entra ID Synced Passkeys How to Enable and Use Them with Password Managers explains how passkeys can improve sign-in security while still supporting practical device and password manager workflows. The Entra ID passkey rollout should include user communication, supported platforms and recovery planning.
Runbook notes for Entra ID Synced Passkeys How to Enable and Use Them with Password Managers
Entra ID Synced Passkeys How to Enable and Use Them with Password Managers deserves a little more operational context because the decision usually affects passkey enablement. The related items are Entra ID synced passkeys, password managers, phishing-resistant MFA, rollout training. Treat this Nugget as a starting point for a concrete tenant decision: who is in scope, which Microsoft portal or policy is touched, and what visible result should confirm that the configuration worked.
When validating Entra ID Synced Passkeys How to Enable and Use Them with Password Managers, keep the test narrow enough to understand the result. Select one representative user, device, workload or subscription, capture the current state, then apply the change and compare the outcome. This avoids guessing later when support sees a different enrollment state, access result, model response, update status or admin center signal.
The most useful documentation for Entra ID Synced Passkeys How to Enable and Use Them with Password Managers is practical rather than theoretical. Record the assignment logic, the owner, the expected monitoring view and the exception path. If the change affects users, include the wording support teams should use when they explain the behavior. If it affects devices or services, include the exact place where administrators can verify health.
For search consistency, keep the phrase Entra ID Synced Passkeys How to Enable and Use Them with Password Managers connected to the body text, the internal links and the category context. That helps readers understand why this Microsoft admin topic belongs with the surrounding Intune, Entra, Azure, Copilot, Security or automation Nuggets, and it gives AI search systems clearer signals about the real subject of the page.