๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐ง๐ญ๐ซ๐ ๐ฉ๐๐ฌ๐ฌ๐ค๐๐ฒ ๐จ๐ง ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐ฃ๐ฎ๐ฌ๐ญ ๐ก๐ข๐ญ ๐ฉ๐ฎ๐๐ฅ๐ข๐ ๐ฉ๐ซ๐๐ฏ๐ข๐๐ฐ
And it’s solving a problem many of us didn’t realize we had.
You can nowย ๐ซ๐๐ ๐ข๐ฌ๐ญ๐๐ซ ๐ ๐๐๐2 ๐ฉ๐๐ฌ๐ฌ๐ค๐๐ฒ๐ฌ ๐๐ข๐ซ๐๐๐ญ๐ฅ๐ฒ ๐ข๐ง๐ญ๐จ ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐๐๐ฅ๐ฅ๐จ without joining or registering the device to Microsoft Entra ID. Windows Hello becomes a local FIDO2 passkey container.
This means:
โข No device join required
โข Multiple passkeys for multiple Entra accounts on the same PC
โข Standards-based phishing-resistant auth
โข Governed by Entra passkey (FIDO2) policies, not Intune WHfB policies
Finally: passwordless that works on devices you don’t own.
โ ๏ธ Note: Requires explicit opt-in via passkey profiles with Windows Hello AAGUIDs during preview.
Details: https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-entra-passkeys-on-windows