Microsoft 365 Adopts Passkeys to Replace Passwords
Microsoft 365 is rolling out passwordless authentication with passkeys based on public-private key pairs. Admins configure passkey profiles in the Microsoft Entra Admin Center, including device attestation via AAIDs and phased rollouts.
- Passkeys come in device-bound and cloud-synced variants
- Configuration is done in Microsoft Entra Admin Center with AAID device attestation
- The method resists phishing and adversary-in-the-middle (AITM) attacks
- Temporary Access Pass (TAP) is used for account recovery
Read next
Security