Skip to main content
Security Products

Microsoft to roll out Entra passkeys on Windows starting late April

Microsoft to roll out Entra passkeys on Windows starting late April Image: Primary
Microsoft will begin rolling out passkey support for phishing-resistant passwordless authentication to Microsoft Entra-protected resources from Windows devices in late April. The feature is expected to reach general availability by mid-June 2026 and will also extend passwordless sign-in to unmanaged Windows devices. Microsoft said Entra passkeys on Windows will support corporate, personal, and shared devices, with admin controls via Conditional Access and Authentication Methods policies. Users can create device-bound passkeys stored in the Windows Hello container and authenticate using facial recognition, fingerprint, or PIN. Passkeys are cryptographically bound to each device and never transmitted over the network, meaning attackers cannot steal them during phishing or malware attacks. Microsoft Entra passkeys on Windows close a security gap that previously left personal and shared devices reliant on password-based Entra ID authentication. In recent months, attackers have targeted Microsoft Entra single sign-on accounts using stolen credentials. In May 2025, Microsoft announced that all new Microsoft accounts will be passwordless by default to protect against brute-force, credential stuffing, and phishing attacks.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Products
Security Products

Liquid sidechain pauses after reported 4,000 BTC withdrawal

Liquid says purported white-hat hackers withdrew about 4,000 BTC, valued in its statement at roughly $320 million, from the Liquid Federation wallet. The company says the funds left through the SideSwap Peg-out Authorization Key, ...

Security
Security

PaperCut flaws exploited in credential-theft attacks on schools

Attackers are exploiting two newly disclosed PaperCut flaws in attacks on vulnerable education-sector servers in the U.S. and Europe, according to Arctic Wolf. The security firm described the flaws as an authentication-bypass and ...

Security AI
Security AI

Microsoft reports ASCII-smuggling use in email spam

Microsoft said email spammers are adopting ASCII smuggling, a technique used to conceal malicious instructions in AI-agent prompt-injection attacks, to evade email-platform filters. The reported shift applies the obfuscation techn...

AI Products
AI Products

OpenRouter lists GPT-6 Astra with million-token context

OpenRouter listed GPT-6 Astra on September 4, offering an OpenAI-compatible API route to the model. The listing describes a 1,050,000-token context window, support for files and function calling, and prices of $10 per million inpu...