Entra ID now supports multi-device Passkeys for password managers like 1Password

Until now, it was not possible to save a passkey from an Entra ID organization account in a password manager like 1Password. The Entra ID passkey was limited as a device-bound passkey, meaning you could store it on your Windows device, the Microsoft Authenticator app, or other supported devices. If you tried to store such a passkey in 1Password, you would receive an error.

A password manager like 1Password requires multi-device passkeys.

Multi device passkeys
Multi device passkeys (MDC) are credentials that can be moved and synced between devices. This means that if a user has multiple devices, they can use the built in authenticator to validate a credential regardless if they are using the device that was used to create the credential.

This offers a higher degree of usability as users will be able to utilize any of their devices to authenticate into services without having to individually enroll each one. MDC’s may also be shared between different users; for example you can AirDrop your passkey to another person in the case of shared accounts.

MDC’s are commonly embedded into other devices like a mobile phone, or laptop. Platforms that will support MDC are Windows Hello, Apple Face/Touch ID, and Android Biometrics.

Entra ID now supports synced passkeys in Public Preview (rolling out, should be available by December 2025). A synced passkey is a multi-device passkey that you can store in a password manager like 1Password. 🎉

Passkeys (FIDO2) are a strong, phishing resistant alternative to passwords. With this preview, Microsoft Entra ID supports synced passkeys. Synced passkeys are stored in platform or with other passkey providers such as Apple iCloud Keychain, Google Password Manager, 1Password, or Bitwarden, and made available across a user’s devices. Synced passkeys simplify user onboarding and account recovery, which accelerates passwordless adoption for most organizations.

  1. You must configure a new passkey profile in Entra ID, as synced passkeys are part of it.
    Open Entra ID > Authentication Methods, select Passkey (FIDO2), then opt-in to the Public Preview for synced passkeys.
Opt-in to the public preview of synced passkeys
Opt-in to the public preview of synced passkeys
  1. Entra ID requires a default passkey profile, which you need to configure first. You can create up to three profiles during the preview. A passkey profile defines which passkey policy applies to which group of users; for example, you may allow synced passkeys for standard users but not for privileged accounts, and specific accounts require a defined FIDO2 key.
  • Enable the target type “Synced (preview)” for the passkey profile. Enforce attestation is not supported for synced passkeys.
  • The provider GUID for 1Password is bada5566-a7aa-401f-bd96-45619a55120d, as posted in the 1Password community two years ago when passkeys were first introduced in Entra ID.
Define your default passkey profile
Define your default passkey profile
  1. Assign the passkey profile to your passkey authentication method.
Assign your passkey profile to a group of users or all users
Assign your passkey profile to a group of users or all users
  1. You’re now ready to configure a new passkey for your account.
    Open mysignins.microsoft.com/security-info and add a new sign-in method. You will now see the updated Passkey method. Previously, this was Security Key.
Select Passkey (previously Security Key)
Select Passkey (previously Security Key)
  1. Follow the steps to configure and store your passkey in 1Password. Both the Microsoft system and 1Password will guide you through the process. It takes less than a minute.
Name your passkey
Name your passkey
  1. Your synced passkey has been created and is now listed in your sign-in methods.
Delete your passkey if necessary
Delete your passkey if necessary

The provider GUID is also confirmed in the authentication methods of my Entra ID account.

Authentication methods from my account
Authentication methods from my account

To test it, open a private browser session and sign-in at m365.cloud.microsoft.
Select the passkey sign-in option and then choose the 1Password login offered by 1Password. You’re in, without entering your username, password, or MFA code. This is truly seamless authentication.

Select the Passkey option to sign-in
Select the Passkey option to sign-in

A synced passkey works seamlessly across your other devices, such as your mobile phone.

Synced passkey on a mobile phone
Synced passkey on a mobile phone

The Entra ID sign-in log lists the passkey-based sign-in.

Share
Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with more than 10 years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Reply

Your email address will not be published. Required fields are marked *