Microsoft Entra ID · Passkeys as the default sign-in method

Accelerate Passkey Adoption for Microsoft Entra ID.

FEITIAN is a member of the Microsoft Intelligent Security Association (MISA), working alongside Microsoft to help organizations move to phishing-resistant authentication for Entra ID.

Microsoft is making passkeys the default for Entra ID, and FEITIAN's hardware-bound passkeys are built for the shift. Every credential lives on the device and never leaves it, so there are no shared secrets, no codes to intercept, and no central database to break into.

Request up to two hardware-bound passkeys and see how they work in your own Entra ID environment.
FIDO2 certified · FIPS 140 certified · Microsoft Intelligent Security Association (MISA) member

YOUR EVALUATION KIT

Up to 2 Hardware-bound Passkeys

Free for qualified testing

Works natively with Microsoft Entra ID
Select the form factor that fits your use case
Register with your own tenant in minutes
Get Your Keys
WHAT CHANGED

Passkeys are the direction. Where your credential lives decides how strong it is.

Microsoft will make passkeys the default sign-in method for Entra ID, moving toward phishing-resistant credentials. Passkeys come in two forms, and the difference matters most for your highest-risk accounts.
SYNCED PASSKEYS
Stored on a phone or laptop and synced through a personal Apple, Google, or Microsoft account. Convenient for most people and a genuine step up from typed codes.
OTP TOKENS
Still ask a person to read a code and type it in. On a lookalike page that code can be relayed in real time, and the shared seed behind every token is stored on a server to verify it.
59%
of successfully compromised accounts already had MFA enabled at the time of the attack.
54% vs 12%
Click rate of AI-crafted phishing compared with the older, typo-filled kind.
21 sec
Median time from phishing email open to link click

OTP token vs. hardware-bound passkey

Both work with Entra ID. Only one removes what attackers target.

Property OTP token Hardware-bound passkey
Resists real-time relay (adversary-in-the-middle) phishing
No code for a person to read, type, or mistype
No shared secret stored on a verification server
Credential cannot be copied or exported from the device
Recognized as phishing-resistant by CISA and NIST
Meets NIST's highest assurance level (AAL3)
Works natively with Microsoft Entra ID
MIGRATION TO HARDWARE-BOUND PASSKEYS

If you already issue OTP tokens, you are most of the way there.

Your users already carry an authenticator and have the routine of using it. Switching to security keys keeps the habit and removes the phishable code. A small team can roll it out in phases.

01

Sample and test

Request two keys, register them in your own Entra ID tenant, and confirm the sign-in experience with your policies.
02

Provision

Use KeyProvision to pre-enroll keys to Entra ID accounts for users who can't self-register. Teach the rest how to do it themselves.
03

Roll out by risk

Start with admins, finance, and other privileged accounts. Issue two keys per user, a primary and a backup.
04

Retire the fallback

Once a group is enrolled, turn off legacy OTP and SMS on a schedule so attackers can't downgrade to the weaker method.

The Provisioning Tool

KeyProvision for Entra ID: enroll the users who can't enroll themselves

Self-registration works for technical staff. It leaves gaps for shared-workstation, deskless, and less-technical users. KeyProvision lets your admins pre-provision security keys directly to Entra ID accounts, so a key reaches each person ready to use.

Pre-register keys to accounts from one console

Enforce phishing-resistant MFA with hardware-bound passkeys

Built for Microsoft Entra ID using Microsoft provisioning APIs

KeyProvision · Entra ID

Why teams choose FEITIAN

FIDO2 and FIPS 140 certified hardware, and a Microsoft Intelligent Security Association (MISA) partnership behind every deployment.
3,000+
customers worldwide
60M+
devices shipped per year
150+
countries served
1,000+
patents held
FIDO2 certified
FIPS 140 certified
Microsoft MISA member

Get Up to Two Complimentary Hardware-Bound Passkeys

Tell us a little about your environment and we'll ship up to two keys to evaluate with Entra ID. No cost, no obligation.

  • Evaluate on your own tenant and policies
  • Planning 100+ keys? We'll include volume and deployment guidance.
  • FIPS 140 certified hardware

Thank you! We'll be reaching out shortly.

This field is required
Please enter a valid email
This field is required
Optional Advanced Evaluation
Interested in biometric authentication?
Biometric evaluation kits are available upon consultation.

Note: Complimentary samples and shipping are available within the 48 contiguous U.S. states. Shipping fees may apply elsewhere.