msnugget
Entra ID Synced Passkeys How to Enable and Use Them with Password Managers
9 By Jannik Reinhard & Florian Salzmann · Published · Updated

Entra ID Synced Passkeys How to Enable and Use Them with Password Managers

Microsoft Entra ID now supports synced passkeys in public preview. This allows users to store their passkeys inside a password manager and use them across multiple devices without re-registering on every new device.

Prerequisites

Before you start, make sure:

  • Entra ID tenant is enabled for preview features

Users have:

  • A supported password manager (for example iCloud Keychain, Google Password Manager, 1Password, etc.)

  • A device that supports WebAuthn / passkeys

  • FIDO2 / Passkey authentication is not blocked globally

What Changes Compared to Device-Bound Passkeys

With synced passkeys:

  • ✅ Passkeys roam across devices

  • ✅ Easy recovery if a device is lost

  • ✅ No physical security key needed

  • ❌ No strong hardware attestation

  • ❌ The security level depends on the password manager protection

This is a convenience vs control trade-off.

Use synced passkeys for:

  • Standard end users

  • Remote workers

  • Multi-device users

Keep device-bound passkeys only for:

  • Global admins

  • Privileged roles

  • Break-glass accounts

  • Security-sensitive users

You can enforce this using multiple passkey profiles with different group assignments.

Enable Synced Passkeys in Entra ID

  • Go to Entra ID

  • Open Protection > Authentication methods

  • Select Passkey (FIDO2)

  • Enable the Preview banner for passkey profiles (if not already shown)

  • Open the Default passkey profile or create a new profile

  • Set Passkey storage type to Synced passkeys

Entra ID Synced Passkeys How to Enable and Use Them with Password Managers

This enables synced passkey for all users (Default Profile). You can also enable it ust for a subset with a custom profile which can be assigned to a specific usergroup.

assign specific group to synced passkeys

User Registration with a Password Manager

After assignment, the user registers like this:

  • User signs in to aka.ms/setupmfa

  • Opens Security info

  • Selects Add sign-in method

  • Chooses Passkey

  • The browser prompts for a password manager

  • The passkey is stored inside the manager and automatically synced to other devices linked to the same vault

From now on, the user can sign in on any new device where the same password manager is already signed in.

No re-enrollment required.

Entra ID Synced Passkeys How to Enable and Use Them with Password Managers

Entra ID Synced Passkeys How to Enable and Use Them with Password Managers

Entra ID Synced Passkeys How to Enable and Use Them with Password Managers

Sign-in Experience

Entra ID Synced Passkeys How to Enable and Use Them with Password Managers

Important Security Notes

  • Do not allow synced passkeys for global admin roles

Ensure:

  • Strong MFA is required for password manager access

  • Device compliance is still enforced via Conditional Access

  • Users storing corp credentials in personal vaults is a new risk you must consciously accept

Operational note: Entra ID Synced Passkeys How to Enable and Use Them with Password Managers

For Microsoft admins, the practical point in Entra ID Synced Passkeys How to Enable and Use Them is to treat the change as something that should be validated before it becomes tenant-wide behavior. Check the affected users, devices, assignments and support process so the Nugget turns into a controlled operational improvement instead of another undocumented setting.

Entra ID Synced Passkeys How to Enable and Use Them with Password Managers explains how passkeys can improve sign-in security while still supporting practical device and password manager workflows. The Entra ID passkey rollout should include user communication, supported platforms and recovery planning.

Runbook notes for Entra ID Synced Passkeys How to Enable and Use Them with Password Managers

Entra ID Synced Passkeys How to Enable and Use Them with Password Managers deserves a little more operational context because the decision usually affects passkey enablement. The related items are Entra ID synced passkeys, password managers, phishing-resistant MFA, rollout training. Treat this Nugget as a starting point for a concrete tenant decision: who is in scope, which Microsoft portal or policy is touched, and what visible result should confirm that the configuration worked.

When validating Entra ID Synced Passkeys How to Enable and Use Them with Password Managers, keep the test narrow enough to understand the result. Select one representative user, device, workload or subscription, capture the current state, then apply the change and compare the outcome. This avoids guessing later when support sees a different enrollment state, access result, model response, update status or admin center signal.

The most useful documentation for Entra ID Synced Passkeys How to Enable and Use Them with Password Managers is practical rather than theoretical. Record the assignment logic, the owner, the expected monitoring view and the exception path. If the change affects users, include the wording support teams should use when they explain the behavior. If it affects devices or services, include the exact place where administrators can verify health.

For search consistency, keep the phrase Entra ID Synced Passkeys How to Enable and Use Them with Password Managers connected to the body text, the internal links and the category context. That helps readers understand why this Microsoft admin topic belongs with the surrounding Intune, Entra, Azure, Copilot, Security or automation Nuggets, and it gives AI search systems clearer signals about the real subject of the page.