Microsoft Entra Deployment Guide

One Approved Authenticator.
No Substitutes.

Lock Microsoft Entra to hardware-bound biometric authentication

Enabling FIDO2 is not the same as controlling who gets in. A standard passkey rollout still accepts synced credentials, general purpose device authenticators, and whatever the help desk approves under pressure.

This guide closes that gap. Thirteen sections, written for identity teams, showing exactly how to configure Microsoft Entra so it refuses every authenticator except attested TokenCore™ hardware. Registration, sign-in, enrollment, and recovery are all governed by the same rule.

Trust stops being a judgment call. It becomes policy.

  • Build a Token-only passkey profile. Device bound allowed, synced passkeys refused, attestation enforced, AAGUID allow list applied to registration and sign-in.
  • Create a Token-specific authentication strength and require it through Conditional Access, with a report-only validation stage before enforcement.
  • Protect security information registration, so an attacker cannot talk an employee or a technician into enrolling their hardware.
  • Inventory and remove legacy passkeys, unattested credentials, and weak recovery paths for the protected population.
  • Lock down recovery and administrative override, including a stage-by-stage replacement workflow for a lost authenticator.
  • Run the validation plan. Ten tests with expected results, production acceptance criteria, and a go-live checklist.

Every step includes the admin center path, the recommended value, and the reason it exists. Microsoft technical references are listed at the end. The guide reflects Microsoft documentation reviewed in August 2026.

standing-book-mockup 1