What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Entra ID passkey profiles let administrators apply different FIDO2 passkey rules to different user groups. A profile can specify whether attestation is required, whether synced passkeys are allowed, and which authenticator models are accepted or blocked. The feature is documented for configuration now; it is not merely a planned addition.

What passkey profiles change

Without profiles, an administrator configures one set of FIDO2 passkey rules for the tenant. Profiles add group-based policy: for example, an organization could use stricter authenticator requirements for administrators and a different passkey-type policy for frontline staff. Microsoft documents up to three profiles total, including the Default profile. Microsoft’s passkey setup guidance describes the available controls and configuration.

The main policy choices cover four practical questions:

  • Credential portability: Allow only device-bound passkeys, or also allow synced passkeys.
  • Authenticator assurance: Require attestation when a passkey is registered, or leave attestation off.
  • Approved authenticators: Use AAGUID allow or block lists to identify authenticator models.
  • Scope: Assign profiles to the groups whose users should follow those rules.

Device-bound passkeys can be stored on FIDO2 security keys and Microsoft Authenticator. Synced passkeys are a separate option and must be enabled in a profile. A physical security key is not required to use profiles; if you plan to use one, confirm that its model and AAGUID are compatible with your tenant policy. Microsoft explains security-key sign-in and AAGUIDs in its FIDO2 security-key guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What to know before enabling profiles

Enabling profiles changes the configuration model, so plan group assignments and settings before opting in. Microsoft says existing global FIDO2 settings transfer to the Default profile. It also states: “After you opt in to enable passkey profiles, you can’t opt out.” The setting is therefore a one-way configuration change, not a temporary preview switch.

The limit is three profiles in total, counting Default—not three additional profiles. Decide which groups genuinely need different rules before creating profiles, and avoid treating profiles as a substitute for access controls elsewhere in Entra.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Enable and configure passkey profiles

You need at least the Authentication Policy Administrator role to configure the passkey policy. Microsoft’s documented navigation and configuration sequence is:

  1. Open the Microsoft Entra admin center and go to Entra ID > Security > Authentication methods > Policies > Passkey (FIDO2).
  2. Opt in to enable passkey profiles. Review the current global FIDO2 settings, which Microsoft says are transferred to the Default profile.
  3. Configure the Default profile, then add profiles for groups that need different passkey rules. Set the attestation requirement, passkey types, and authenticator AAGUID rules for each profile.
  4. Target the appropriate groups with each profile and review whether users belong to more than one targeted group.
  5. Save the policy and verify that the overall Passkeys authentication-method policy includes the intended users rather than excluding them.

“Allow self-service set up” remains a global setting rather than a per-profile control. Configuring synced-passkey settings also requires the Authentication Policy Administrator role.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How overlapping assignments and exclusions work

A user can be in scope for multiple profiles. Microsoft says there is no fixed order in which those profiles are checked: registration or authentication is allowed if the passkey fully meets at least one applicable profile. Consequently, overlapping assignments are permissive across matching profiles. Review memberships carefully if the intended rule is that every applicable profile must be satisfied.

The overall Passkeys authentication-method policy’s exclusion takes precedence. A user excluded there is not made eligible merely by being targeted through a profile. Check that policy separately when troubleshooting a user who cannot register or use a passkey.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How attestation and AAGUID rules affect existing credentials

Attestation and AAGUID controls are not interchangeable. Attestation is checked at registration: enabling enforced attestation later does not prevent sign-in with credentials that were registered earlier without it. AAGUID restrictions affect both registration and authentication, so removing an AAGUID from the allowed set can make existing keys unusable for sign-in.

Microsoft also cautions that when attestation is off, AAGUID lists serve as a policy guide rather than a strict security control. Before changing either setting, consider whether the change affects only future registrations or can also disrupt existing users’ sign-ins.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Use profiles alongside Conditional Access

Profiles govern passkey registration and authenticator policy; they do not by themselves guarantee that every sensitive resource requires a phishing-resistant sign-in. For sensitive resources, Microsoft documents using the built-in phishing-resistant authentication strength or creating a custom Conditional Access authentication strength that permits passkeys and can optionally restrict AAGUIDs. See the Microsoft passkey configuration guidance for the related Conditional Access options.

Microsoft describes passkeys as phishing-resistant in its July 13, 2026 security guidance. That guidance is a reason to consider passkeys in an authentication strategy, not evidence that profiles alone prevent every attack.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.